4 ms·
Passkeys are a private key stored on your device with the public key registered with the server. Servers should allow multiple passkeys per user (so you can re
by IcyWindows 11mo ago
Passkeys are a private key stored on your device with the public key registered with the server.
Servers should allow multiple passkeys per user (so you can register multiple devices), but many don't.
- sam_lowry_ 11mo agoThat's an implementation detail users should not care about. The bigger question is... why don't we replace the login/password combination with just a string of randomly generated characters and call it a day? Why protect these strings of random characters from users, call them passkeys and advertise them on all street corners? Feels like a devil's plot to strip us from all the rights to our devices.
- joshuamorton 11mo agopublic/private keypairs (and therefore passkeys) provide cryptographically secure anti-phishing properties that passwords cannot.
- zzo38computer 11mo agoX.509 already does that, and in a better way. It also makes it unnecessary to register multiple devices, if you allow certificate chains (the server would check the certificate chain; one of the was issued by the service and contains information about which account it is associated with; the other ones you can issue to yourself, optionally with more restricted permissions, and can be revoked or expire). That would also allow you to have passworded private keys, and/or to store one private key on a separate computer that is not connected to the internet to issue the other one to yourself in order to mitigate security issues (and you can revoke the certificate and make a new one if it is compromised or expires). X.509 also is not limited to only WWW, so it can be used with other protocols too.