[flagged]
I'm pretty sure passkeys are just a rebranded version of virtual WebauthN tokens. So while passkey secrets can be synced (unlike U2F physical tokens) they can also be implemented as being backed by a physical token (think Yubikey) that never goes om the cloud.
Tailscale doesn't want your password
51–60 of 316 posts
Re: Tailscale doesn't want your password
#52My work uses Microsoft SSO for everything. Passkeys aren't enabled though. And management won't enable them on Azure AD. Instead, they enable the tried and tested and ultra secure method of SMS based 2FA with a password. (This is sarcasm.) The alternative is the Microsoft authenticator app with its associated risk of approval fatigue. I have already had several malicious login attempts. Fortunately I'm attuned enough…
I don't think they're actually available on AzureAD. That thing tends to lag like crazy in actual security features. FIDO support is relatively newish. IIRC it was generally available around the end of 2022. Only recently, you no longer have to register a phone number for password reset (which is different from login, mind (SSPR)).
> they enable the tried and tested and ultra secure method of SMS based 2FA with a password
This isn't actually that much worse than the MS recommended way of using their crappy authenticator. They even allow passwordless sign-in with that thing! The prompt doesn't tell you anything useful apart from "login with ?". Now, at least, they prompt you for a number you see on screen. It doesn't help with phishing, but at least you know the request comes from what you're doing, not someone else, since it also tended to drop any request if another one was pending.
Re: Tailscale doesn't want your password
#53My work uses Microsoft SSO for everything. Passkeys aren't enabled though. And management won't enable them on Azure AD. Instead, they enable the tried and tested and ultra secure method of SMS based 2FA with a password. (This is sarcasm.) The alternative is the Microsoft authenticator app with its associated risk of approval fatigue. I have already had several malicious login attempts. Fortunately I'm attuned enough…
> I have already had several malicious login attempts Doesn't that mean they know your username and password? How does that happen so easily.
> Fortunately I'm attuned enough to decline them.
There is only something to decline if they know your password.
Re: Tailscale doesn't want your password
#541Password does not support PassKeys.
They have announced the intention to, but outside of beta releases it's not there yet.
Re: Tailscale doesn't want your password
#55My work uses Microsoft SSO for everything. Passkeys aren't enabled though. And management won't enable them on Azure AD. Instead, they enable the tried and tested and ultra secure method of SMS based 2FA with a password. (This is sarcasm.) The alternative is the Microsoft authenticator app with its associated risk of approval fatigue. I have already had several malicious login attempts. Fortunately I'm attuned enough…
> I have already had several malicious login attempts Doesn't that mean they know your username and password? How does that happen so easily.
This became so tiresome that I disabled MFA. Here's a hot take: if your MFA solution fatigues people to the point they disable MFA, you have a problem.
Also, I'm wondering if the OP might be referring to passwordless "Approve this login request" notifications rather than plain old MFA, where someone just needs to enter your email address and hope you approve the login request. Not sure if MS does this, but I know other apps that do.
Re: Tailscale doesn't want your password
#56Earlier quoted context omitted.
> I have already had several malicious login attempts Doesn't that mean they know your username and password? How does that happen so easily.
They said login attempt, not successful login. So no.
Re: Tailscale doesn't want your password
#57I don’t understand why someone would want to store all their credentials with one of the large tech companies. It seems like this makes it really easy for law enforcement to grab access to all accounts easily.
Re: Tailscale doesn't want your password
#58I haven't yet looked into the inner mechanics of passkeys, and the link only talks about the first login. What is the experience like when a user wants to log in from a different system? They press the "Login with Passkey" button on Device 2, and then...?
It presents a qr code you can scan with the other device. You can try it on https://passkeys.io
Re: Tailscale doesn't want your password
#59My work uses Microsoft SSO for everything. Passkeys aren't enabled though. And management won't enable them on Azure AD. Instead, they enable the tried and tested and ultra secure method of SMS based 2FA with a password. (This is sarcasm.) The alternative is the Microsoft authenticator app with its associated risk of approval fatigue. I have already had several malicious login attempts. Fortunately I'm attuned enough…
> My work uses Microsoft SSO for everything. Passkeys aren't enabled though. And management won't enable them on Azure AD. I don't think they're actually available on AzureAD. That thing tends to lag like crazy in actual security features. FIDO support is relatively newish. IIRC it was generally available around the end of 2022. Only recently, you no longer have to register a phone number for password reset (which is…
Re: Tailscale doesn't want your password
#60Apple Slightly off topic: did Apple just make it super easy for law enforcement to unlock your phone & passkeys as part of iOS 17? > ”Apple ID. Securely sign in to your iPhone using a nearby device or any email address or phone number listed in your account.” https://www.apple.com/ios/ios-17-preview/