4 ms·
Agree. This is why I do not use Passkeys, and I have 4 physical Yubikeys tied to every system I secure with them.
by SomeHacker44 6mo ago
Agree. This is why I do not use Passkeys, and I have 4 physical Yubikeys tied to every system I secure with them.
- deepsun 6mo agoCloud-based passkeys are okayish (1pass, bitwarden), as they are available on multiple devices. However not all devices play well with it, e.g. iOS and Android don't ask 1pass for the passkey. I also couldn't make it ask NFC for my hardware Yubikey with passkeys, but maybe I just did something wrong.
- sitting33 6mo agoPasskeys are supposed to cover two authentication factors at once (having your device + biometrics). Because your yubikey doesn't implement biometrics, it's only a single factor, and thus cannot be used as a passkey.
- palata 6mo agoWell a Yubikey can require a password/PIN. So having your device + knowing the password.
- deepsun 6mo agoYubikey can be used as passkey atorage, I do it on Linux desktop/laptop with passkeys. It requires touching it (but no biometrics). I just couldn't make Android ask my hardware device, it wants to handle passkeys by itself. It's false that passkeys cover biometrics. They cover password + OTP (aka 2FA aka MFA, although BestBuy requires OTP even after logging in with a passkey).
- qurren 6mo agoI still don't understand what the hell passkeys are. Weren't passwords and {hardware keys | authenticator apps} enough? I don't think average Joe is going to understand these passkeys either.
- palata 6mo agoA passkey is just a thing that authenticates with FIDO2 (or is it WebAuthn?), I believe. With a password, you open your password manager, copy the password in memory, paste it into the input field and trust that nobody could read it from your clipboard and that the program handling the password does it correctly. If your password leaks on the way, it's leaked. With FIDO2, the server sends a challenge and asks your HSM (or TPM, not sure what the right word is) to sign it with your private key. So the server can verify that you own the private key, but if the challenge or the response leaks, it's just this one time. Next time it will be a new challenge. Also for the average Joe, the result is that the "passkey" is the fingerprint or the face recognition and there is no password. It feels like they have only one password: the biometry/face recognition (or a master password, I guess?). So passkeys are superior to passwords in that sense. Fun fact 1: some people hate passkeys because they don't want to be forced to rely on TooBigTech for them. Currently I use my Yubikeys as passkeys everywhere and it works well, so I do NOT depend on TooBigTech. Fun fact 2: FIDO2 on current Yubikeys (and HSM in general, I think) tend to use classic cryptography which would be broken by quantum computers. A password used with symmetric encryption is not broken by quantum computers. So there may be a period of time where this becomes a tradeoff (you may have to decide whether the most likely attack is a quantum computer breaking your authentication or a malware stealing your password)?
- qurren 6mo ago> With a password, you open your password manager, copy the password in memory, paste it into the input field and trust that nobody could read it from your clipboard and that the program handling the password does it correctly. If your password leaks on the way, it's leaked. I don't do that. My password manager simulates keystrokes 2 seconds after I hit the button. I switch to the other window and my password gets punched in without going through the clipboard. Specifically to avoid this attack. > Currently I use my Yubikeys as passkeys I have Yubikeys but for 2FA. So we're back to 1FA now but just "something you have" and no "something you know" ?
- palata 6mo ago
- palata 6mo agoI don't get this. Why don't you use your Yubikeys as passkeys then?
- Ferret7446 6mo agoLikely because GP is misinformed about what passkeys are, which is understandable because they have not been marketed very clearly at all (though I do wish technically literate folks would actually do some research into "new" tech before parroting opinions based on their technopolitical alignment)