Passkeys.io – A Passkey Authentication Demo
11–20 of 121 posts
Re: Passkeys.io – A Passkey Authentication Demo
#12I guess I’m not understanding passkeys. On my iPhone it’s asking generating a QR code to scan with another device. Is this assuming another device already has credentials? What if this is my only device?
Re: Passkeys.io – A Passkey Authentication Demo
#13I guess I’m not understanding passkeys. On my iPhone it’s asking generating a QR code to scan with another device. Is this assuming another device already has credentials? What if this is my only device?
Without this kind of cloud sync, you need at least two devices, or you will be locked out if you lose or break one.
Re: Passkeys.io – A Passkey Authentication Demo
#14I guess I’m not understanding passkeys. On my iPhone it’s asking generating a QR code to scan with another device. Is this assuming another device already has credentials? What if this is my only device?
Re: Passkeys.io – A Passkey Authentication Demo
#15Very nice, a good step towards the future. Just tried on multi-device scenario with android and my mac and that worked fine. I'm wondering though, how the biometric data gets associated with my email address.
Don't take my word for it though!
Re: Passkeys.io – A Passkey Authentication Demo
#16To make it worse, when I'm trying to sign in, it prompts me for my Yubikey PIN, and not Windows Hello PIN. Basically, multiple token support is badly messed up.
Re: Passkeys.io – A Passkey Authentication Demo
#17I guess I’m not understanding passkeys. On my iPhone it’s asking generating a QR code to scan with another device. Is this assuming another device already has credentials? What if this is my only device?
You can also save it to your phone, you only need to scan another QR code if you want to save it on another device
Re: Passkeys.io – A Passkey Authentication Demo
#18> passkeys are way more secure and are easier to use than both passwords and all current 2-factor authentication methods Perhaps I'm naive, but how are passkeys "way more secure" than "all current 2-factor authentication methods"? Don't many security keys (e.g. Yubikey) also require that you are in possession of the physical yubikey? I'm using that as a 2-factor authentication method. Why is a passkey more secure? Up…
Re: Passkeys.io – A Passkey Authentication Demo
#19The demo is just using OTP sent to my email, which essentially makes my email a password manager, and now a much higher value target.
Re: Passkeys.io – A Passkey Authentication Demo
#20If I have a single hardware key/tpm/yubikey/iphone/etc - can you create multiple users on one site? And can they tell that you're the same user? Or are you now locked to just a single user for your phone/macbook/yubikey/whatnot?
Also if multiple services colluded (or integrated with say GA) - can they (or at least GA) all tell that you're using the same hardware key across services?
Unless I'm missing something this sounds like very bad news for user privacy