6 ms·
> Passkeys is the way to go No, at least not on its own. Let's not repeat the mistakes. Password managers are the way to go and ONLY FOR RARE EXCEPTIONS we sh
by valenterry 1y ago
> Passkeys is the way to go
No, at least not on its own. Let's not repeat the mistakes.
Password managers are the way to go and ONLY FOR RARE EXCEPTIONS we should use dedicated MFA, such as for email-accounts and financial stuff. And the MFA should ask you to set up at least 3 factors and ask you to use 2 or more. And if it doesn't support more or less all factors like printed codes, OS-independent authenticator apps and hardware keys like yubikey, then it should not be used.
- degamad 1y agoPasskey are more like password managers, and less like MFA tokens - despite the fact that many passkey implementations can function as MFA tokens as well. Bitwarden the password manager includes a full passkey implementation, which doesn't involve any MFA.
- valenterry 1y ago> Passkey are more like password managers, and less like MFA tokens No: - I can always export and import all my passwords from/into my password manager - My passwords always work independently of a password manager or any specific app/OS/hardware That is not true for passkeys and makes them much more like tokens. Of course they don't have to be used in MFA, just like passwords.
- jerf 1y agoI just exported my Bitwarden vault and the resulting .json file has my passkeys in it. I'm not going to try to test import, but if it doesn't work that would obviously be more "bug" than anything else. Clearly "export" is the high concern functionality and once exported, importing them is not a big deal. This is only about your first paragraph, it doesn't affect your second.
- geodel 1y agoIndeed. Credential Exchange Protocol (CXP) is already been worked on and all major vendors are planning to support it. There was talk also in Apple WWDC 2025 about Passkey related APIs including exporting them.
- valenterry 1y agoUnfortunately just because it's possible with Bitwarden doesn't mean it is always possible.
- palata 1y agoAre you saying that it's not always possible to import/export passkeys because you can manage them with some program that doesn't allow it, but the same is not true for passkeys? Counter-example: I can write a password manager that will not allow you to export/import passwords.
- valenterry 1y agoNo, that's not what I meant. There are cases where bitwarden doesn't work but chrome for example does. Easy to Google up. For passwords however, I never heard of a case where a website only accepts passwords from a specific password manager - and how could they even do that right?
- palata 1y agoI don't think your reasoning holds. You say "I know situations where one passkey client works with some websites and not others, but I don't know situations where a website works with some clients and not others". If the website accepts a password, then it can't prevent you from using the password manager you want. But if the website accepts FIDO2 passkeys, it's the same thing, isn't it?
- valenterry 1y ago> but I don't know situations where a website works with some clients and not others For example: https://www.w3.org/TR/webauthn-2/#dictdef-authenticatorselectioncriteria https://www.w3.org/TR/webauthn-2/#dictdef-authenticatorselec... > If the website accepts a password, then it can't prevent you from using the password manager you want. But if the website accepts FIDO2 passkeys, it's the same thing, isn't it? Unfortunately not...
- pyrale 1y agoWe need to go further. If a service doesn't include 197 factors including blood samples, showing up at a physical location 50 miles from your home, and sending a picture of yourself in a specific posture, and doesn't require you to use at least 53 of them (determined randomly) to login, then it's insecure and should not be used.
- doublerabbit 1y agoSounds like something the UK gov would love to implement, plus extra. Such as finding a dinosaur fossil of your families name clan.
- johncoltrane 1y agoThat's the French postal service's "identité numérique".
- dchest 1y agoIf you like password managers, you'll love passkeys! Passkeys is an interface between your password manager and a website without all the fluff with filling or copy-pasting passwords.
- dur-randir 1y agoLet me decide for myself what must I love.
- valenterry 1y agoNo need to write like that. I know, understand and use passkeys for quite a while now. I don't love them. I don't love passwords either. But while I don't fear passwords, I fear passkeys. The reason is that it makes the tech even more intransparent. My password manager stops working, completely dies or I can't use it anymore for other reason? No problem, I can fallback to a paper list of passwords if I really have to. This transparency and compatibility is more important than people think. Passkeys lack that. They can be an interface like you described, but only if everyone plays along and they can be exported. But since there is no guarantee (and in practice, they often cannot be exported either) they are not a replacement for passwords. They are a good addition though. Unfortunately, many people don't understand that and push for passwords to begone.
- Flimm 1y agoWhat about server-generated passwords, like API keys? That would solve the main problem with passwords, namely, that people reuse the same weak password everywhere. I doubt it would be as popular as user-selected passwords, but I still wonder why no website has tried it.
- dchest 1y agoHow is that different from a passkey's private key, apart from being less secure? It's literally something like hnkTKS7h2WCOBr3CxSKM51cSVKSkiKOSlQsMhtRZ0CU stored in the password manager.
- 1y ago
- codedokode 1y agoPassword managers are those proprietary programs that you need to install, give full access to your computer, register an account and trust their word that your passwords are uploaded to the cloud securely? No thanks. Also they are too complicated for an ordinary user. A physical key is much simpler and doesn't require any setup or thinking, and can be used on multiple devices without any configuration. And doesn't require a cloud account.
- blkhawk 1y agouh no - a password manager is an open source application you can compile and install yourself if you want. Its nothing more than a small specialised database with a excel like interface. Personally I think that the argument that things are "too complicated for the average user" eventually gets gets you users that find breathing and sphincter function too complicated.
- Hackbraten 1y agoI’ve been observing this space for two decades and haven’t come across a single open-source password manager that actually works, is properly maintained, has an acceptable security track record, and comes with a similarly well-maintained browser extension that protects both my clipboard and myself from phishing.
- rpdillon 1y agoI've been using Keepass for two decades and have never had a single issue. I would never recommend a browser plug in (too much attack surface area), and instead simply check the URL before having KeePass autotype. No clipboard. I think you're rejecting good solutions out of hand. Meanwhile...millions of users trusted LastPass. Twice.
- Hackbraten 1y ago> simply check the URL before having KeePass autotype. I’m not going to rely on myself never making a mistake. I want a solution that protects me even during stressful moments where I have a lapse of judgement and forget to check.