4 ms·
1Password integrates with all pass keys on my iPhone, my Mac, and my Linux box. By a far and away WORTH the subscription, for me!
by an_d_rew 1y ago
1Password integrates with all pass keys on my iPhone, my Mac, and my Linux box.
By a far and away WORTH the subscription, for me!
- drdrey 1y agodoesn't that mean your passkeys are now about as secure as a regular password?
- kbolino 1y agoA passkey is a public-private keypair strongly tied to a specific site. Sites never have access to the private key, and the key will never be presented for use on the wrong site. Those two advantages remain even if the passkey is stored in software or synced over the cloud.
- radlad 1y agoPasskeys are highly phishing resistant in a way that passwords are not and are not subject to credential reuse (though password managers somewhat solve the first problem and almost entirely solve the latter problem.) In effect, though, 1Password is both something you have (the device with 1P logged in, login requires a Security Key that you don't memorize) and something you know (the master password) or are (typically biometrics can be used to unlock for a period after entering the master password.)
- jcattle 1y agoHow do Password managers solve phishing issues? Even just somewhat?
- josephcsible 1y agoYour password manager will autofill your credentials on the real site but not on a phishing site.
- jcattle 1y agoAh true. Didn't think of that. Good point
- recursive 1y agoDon't know about you, but my passwords were already secure enough anyway.
- SchemaLoad 1y agoNo. The service you are logging in to does not hold the keys so they can't be leaked, passkeys do not get reused between services, it's effectively impossible to fall for phishing attacks with passkeys, and it's effectively impossible to fall for scammers trying to get your keys since there isn't any mechanism to directly dump the private keys out. Pretty much all the problems related to passwords are solved by passkeys, having them synced between your devices does not impact that.
- awesome_dude 1y agoThat's my impression as well, and the nature of computing today /encourages/ putting passkeys into some container that means that they can be accessed from other pieces of hardware at different locations.
- loeg 1y agoFrom a practical perspective, passkeys are mostly identical to passwords where (1) secret generation is guaranteed to be strong, random, and unique; (2) they're tied to a specific site, so they can't be phished; and (3) filling is standardized and therefore ergonomic. If your passwords have those properties, passkeys aren't really an improvement for you. The main benefit to savvy consumers is that websites can trust that your passkeys are actually high quality and treat them as a primary authentication mechanism, instead of only a weak factor in an MFA system. And of course the huge huge benefit to most (unsavvy) consumers is that, you know, they're actually secure/unique and phishing-resistant.
- udev4096 1y agoNormal passwords can be phished, no matter how strong it is. The weak link is always a careless human. Passkeys are definitely a huge improvement for everyone, apart from the vendor-lock in which can be avoided
- loeg 1y agoYou can get around it, of course, but password managers are aware of the correct domain for a password and will only auto fill it into a form on the right domain. This is phishing-resistant. I'm not saying it's perfect, and I'm a big passkeys advocate. But "randomly generated password auto-filled by 1password" already meets many of the same benefits as passkeys, kinda, so long as auto-fill works on that particular website. Passkeys, in addition to stronger versions of those properties, also provide (1) ergonomics/standardization ("fill" works everywhere) and (2) sites can trust them to be strong.
- udev4096 1y agoImagine using the worst password manager out there. 1Password was breached several times and even led to some people losing significant amount of money
- larsnystrom 1y agoPlease do share some links to these events, because this is the first I hear of it.