Earlier quoted context omitted.
Currently, none of the big players in the passkey space support exporting or importing of passkeys, because the spec for doing this securely has not been agreed upon, and nobody wants to allow plaintext export of passkeys. See a recent post in the 1Password passkey AMA about this subject: https://old.reddit.com/r/1Password/comments/16to6x7/hey_redd... Re. your point about 1Password going down: Your passwords and pass…
> nobody wants to allow plaintext export of passkeys. While noble, why? 1Password exports a plaintext file that has all of the credentials in plaintext already.
Passkeys are now enabled by default for Google users
311–320 of 684 posts
Re: Passkeys are now enabled by default for Google users
#3121Password enabled PassKey support recently and I was "surprised" to learn that there is no way of exporting them out of 1Password. They're not included in the 1PUX format export, nor in the CSV. That means that they're literally impossible to back up. If 1Password goes down, or the company stops operating, or anything else like that, your Passkeys are just... gone. Absolutely no way to recover them.
Is version 8 reasonably mac-like? On 7 it's still a mac application that acts like a true mac application (drag/drop works properly everywhere, expansion, properly keyboard-enabled, etc) which is well nigh impossible when running inside a chrome box. Agile Bits support kept insisting it was the same as the old native app and people kept complaining about bugs until I stopped following it.
Re: Passkeys are now enabled by default for Google users
#313Earlier quoted context omitted.
Disaster recovery. This is 100% my biggest worry with 2FA/MFA. I also think this is one of the reasons stuff like PGP never took off (don't @ me regarding perfect forward secrecy): the problem has always been managing some little, precious thing and the ramifications of what happens if it put beyond use or is used by some bad actor.
There are some Google Authenticator replacements that have an export function (eg. Authenticator+ on Android, although I'm not sure if it's still maintained). You give up a bit of [theoretical] security for a whole lot of DR insurance.
Re: Passkeys are now enabled by default for Google users
#314Earlier quoted context omitted.
Now there is a technically savvy solution that is a technical tour-de-force. Very very cool. But also completely unrealistic for the average person to use.
How? The usage was very easy. You select a contact and add them as your recovery contact (by selecting contact from your contact list) The system adds the key in the background. If they don't have the app, the app asks you to tell them to install the app (viral growth?). The users didn't need to know any thing technical. But install app, and click yes/no like they do with a 2FA app.
Re: Passkeys are now enabled by default for Google users
#315Earlier quoted context omitted.
Don't worry, if you lose your passkey all you need is access to your email to receive a password reset link.
That's literally the solution to "What if I lose all the passkeys associated with my account and I've also forgotten my password?"
Re: Passkeys are now enabled by default for Google users
#316Earlier quoted context omitted.
Disaster recovery. This is 100% my biggest worry with 2FA/MFA. I also think this is one of the reasons stuff like PGP never took off (don't @ me regarding perfect forward secrecy): the problem has always been managing some little, precious thing and the ramifications of what happens if it put beyond use or is used by some bad actor.
There are some Google Authenticator replacements that have an export function (eg. Authenticator+ on Android, although I'm not sure if it's still maintained). You give up a bit of [theoretical] security for a whole lot of DR insurance.
Re: Passkeys are now enabled by default for Google users
#317Lauren Weinstein is sounding the alarm on passkeys which is flawed and that it would make a huge headache for a lot of people especilly normal folks. https://mastodon.laurenweinstein.org/@lauren/111103819626952... https://mastodon.laurenweinstein.org/@lauren/111211366080459...
He says it's "easy to find" but apaprently he can't find it. https://mastodon.laurenweinstein.org/@lauren/111211489395997...
Why is "weak device password" a reason to avoid passkeys, when those users presumably have weak service passwords as well?
Re: Passkeys are now enabled by default for Google users
#318Lauren Weinstein is sounding the alarm on passkeys which is flawed and that it would make a huge headache for a lot of people especilly normal folks. https://mastodon.laurenweinstein.org/@lauren/111103819626952... https://mastodon.laurenweinstein.org/@lauren/111211366080459...
Re: Passkeys are now enabled by default for Google users
#319Earlier quoted context omitted.
Now there is a technically savvy solution that is a technical tour-de-force. Very very cool. But also completely unrealistic for the average person to use.
How? The usage was very easy. You select a contact and add them as your recovery contact (by selecting contact from your contact list) The system adds the key in the background. If they don't have the app, the app asks you to tell them to install the app (viral growth?). The users didn't need to know any thing technical. But install app, and click yes/no like they do with a 2FA app.
Re: Passkeys are now enabled by default for Google users
#320Earlier quoted context omitted.
> nobody wants to allow plaintext export of passkeys. While noble, why? 1Password exports a plaintext file that has all of the credentials in plaintext already.
Because passkeys are supposed to be a bit more secure than plaintext passwords.