Earlier quoted context omitted.
Edit: everything I say below is not just wrong, but confidently wrong... "Communicate over bluetooth" doesn't mean anything. What app or BT device would they be using? How would a PC communicate with a YubiKey over bluetooth? I have no idea where you got this strange concept from, but registering multiple passkeys from multiple devices on the same account on a site requires no communication between the devices - it o…
That's how it works. You open Google Chrome on Linux, press "Log in with PassKey", scan QR with iPhone, then iPhone contacts Google Chrome via bluetooth to do its crypto magic (which doesn't work 50% of times) and may be it'll work. No idea how Yubikey works, never used it.
Passkeys: A shattered dream
651–660 of 789 posts
Re: Passkeys: A shattered dream
#652Earlier quoted context omitted.
You can always use passkeys like Yubikey or others which are much more multi-platform.
This isn't a viable option in practice, because Passkeys use "Resident Keys". This means the credential needs to be stored on the Yubikey - which has a limited number of key slots. Need to log in to more than 25 (I believe) websites? Tough luck!
Re: Passkeys: A shattered dream
#653Earlier quoted context omitted.
This isn't a viable option in practice, because Passkeys use "Resident Keys". This means the credential needs to be stored on the Yubikey - which has a limited number of key slots. Need to log in to more than 25 (I believe) websites? Tough luck!
Use a better token. YubiKey is the most popular one, not the best one by a long shot. My (cheaper) alternative supports 300 resident keys per each hardware key.
Re: Passkeys: A shattered dream
#654Earlier quoted context omitted.
1Password is a closed-source, cloud-hosted service. At any time, for any reason, they can close and delete your account, leaving you high and dry. Self-hosted, multi-device password managers are the only real solution. Thankfully, Vaultwarden and KeePassXC fill this role perfectly. Now if we could just get the other providers that require insecure email/SMS 2FA to follow suit, that would be great...
I wonder if BitWarden doesn't support passkeys too. BitWarden is open source to a large degree and even provides an (open source) server for self-hosting.
Re: Passkeys: A shattered dream
#655Earlier quoted context omitted.
I'm curious as to why the number of slots is so small. Surely this is not some kind of fundamental limitation on what's possible (or cheap) with hardware?
Because yubikeys were designed long before passkeys become a thing. And hardware people love cutting cost to the bare bone to save one cent of $50 device.
Re: Passkeys: A shattered dream
#656I work in cybersecurity and need to think hard and draw diagrams to understand how modern authentication systems work (modern = something more than passwords). The implementation part is hidden from users but they only understand "password". Sometimes "fingerprint". Anything above that is really tough.
While Passkeys are an interesting development, it will take time before they are part of the authentication routine of standard users.
Re: Passkeys: A shattered dream
#657Earlier quoted context omitted.
Agreed. I self hosted the key 100 bitcoin in like 2010. Machine crashed. Oops.
That's a fundamental problem with cryptographic security: you cannot trust people to manage your keys for you (because due to lack of regulation preventing that companies have this bad habit of pulling the rug under their customers' feet) but you cannot trust yourself doing that either, because you can, and will, make mistakes.
Re: Passkeys: A shattered dream
#658Earlier quoted context omitted.
Agreed. I self hosted the key 100 bitcoin in like 2010. Machine crashed. Oops.
That's a fundamental problem with cryptographic security: you cannot trust people to manage your keys for you (because due to lack of regulation preventing that companies have this bad habit of pulling the rug under their customers' feet) but you cannot trust yourself doing that either, because you can, and will, make mistakes.
I don't trust many people to do that.
I have everything encrypted and self hosted and I sometimes wonder what I would do if I was suffering from amnesia after an accident for example. And having a note somewhere telling me I have a safe in bank X is the only solution I have found.
Re: Passkeys: A shattered dream
#659Earlier quoted context omitted.
Then don’t change phone OS, or put your passkeys in a third party password manager.
Or... use passwords and 2FA which we have been using forever and for years respectively.
Re: Passkeys: A shattered dream
#660Earlier quoted context omitted.
You are able to share an Apple passkey to any nearby Apple device at any time using AirDrop. Passkeys can also be used cross-platform during sign in via an NFC/Bluetooth handshake initiated by QR code. Additionally, passkeys are just a synced-via-cloud implementation of FIDO2, an open standard that has other implementations you may feel more comfortable using. For someone who requires being able to sign in to, say, G…
But what happens if I as an iPhone user want to switch to Android next year? Can I move my Apple passkeys?