Earlier quoted context omitted.
I agree that it's not more vulnerable than just using a password, I'm only saying that it's only slightly less vulnerable under the best circumstances and incredibly more vulnerable under the worst circumstances (ie. if somebody got ahold of your password manager). I also agree that passkey-based authentication provides a smaller attack surface than purely password-based authentication. But putting the passkey on a s…
> I agree that it's not more vulnerable than just using a password, I'm only saying that it's only slightly less vulnerable under the best circumstances and incredibly more vulnerable under the worst circumstances (ie. if somebody got ahold of your password manager). I feel like we might have a mismatch in understanding what a passkey is. You make a new keypair for each account to authenticate to. A leaked passkey is…
Passkeys: A shattered dream
751–760 of 789 posts
Re: Passkeys: A shattered dream
#752Here's my opposing view: I love Passkeys. I use Firefox as my browser and 1Password as my password manager. On my iPhone, I use 1Password + Firefox. I look at https://passkeys.directory/ every so often and switch my logins from passwords to passkeys. This has included a lot of my common logins like GitHub, Google, and Microsoft. There is a lot of confusing terminology. For some reason sites will say "login with Touch…
> It would be inconvenient if I needed to login to a shared computer Ok, I'll bite. Anyone knows how this would be done in that setup? "Can't" is a deal breaker, so is "use the password you had to generate and store in your manager anyway".
If you _had_ to you your passkey you'd probably have to install 1Password + the extension in your browser. This is definitely not a great workaround.
Re: Passkeys: A shattered dream
#753Earlier quoted context omitted.
I use 1Password which supports Passkeys, and don’t have an issue across mobile or desktop. I don’t get what the issues people have really are. I never experience them (fortunately!).
1Password is a closed-source, cloud-hosted service. At any time, for any reason, they can close and delete your account, leaving you high and dry. Self-hosted, multi-device password managers are the only real solution. Thankfully, Vaultwarden and KeePassXC fill this role perfectly. Now if we could just get the other providers that require insecure email/SMS 2FA to follow suit, that would be great...
Re: Passkeys: A shattered dream
#754Earlier quoted context omitted.
Wow. I just bought a couple of new YubiKeys for the OpenPGP Curve25519 support. I was looking forward to using the NFC feature with my Android phone. Is it just a Chrome problem? I downloaded some OpenPGP app from fdroid and it says it supports NFC keys.
I'm not sure about your exact situation, lot of the scenarios are OK, just the one without Google services which are dependent on Google account doesn't work. That is actually irrelevant for "normal" phone users that are logged to Google all the time anyway.
Re: Passkeys: A shattered dream
#755Earlier quoted context omitted.
This is why I’m not interested in passkeys unless I can use it with my password manager (which I probably can at this point). It would also be nice to see the spec for these specifically address lock-in and provide anti-lock-in measures.
The idea of a passkey is that it's bound to a device, and you can have more than one passkey. Think of a YubiKey, just that you can use your Phone or your PC instead. You basically have designated hardware that is always allowed to just login to your account...
Re: Passkeys: A shattered dream
#756Earlier quoted context omitted.
> there's no social-engineering technique someone can use to get you to copy and paste your passkey to an enemy This is a deep, fundamental flaw in passkeys. It's just another example of enshittification disguised as denying end-user control "for their own good." There is no for-profit organization anywhere that I trust more than I trust myself, and there's no threat model where it's more likely I'll be socially engi…
Good for you; I'm ashamed to say that I've hurt my data sanctity far more than any criminal has, with 2am tinkering with my systems. I have vaultwarden at home but I don't use it because I just know I'll fuck up my tunnel while I'm travelling or something. This is my threat model: "hi mum. I need you to drive to my house and fish a keyboard out of the cupboard. Plug it into the big black box and type exactly what I t…
Re: Passkeys: A shattered dream
#757Earlier quoted context omitted.
Are you using every single one of the 100+ accounts constantly? No? Then you can do the passkey flow on demand as needed. It can be comparably simple as an email login or 'we emailed you an OTP' login confirmation flow. If you never get around to using the account ever again in your life, I suppose you never needed it? If the website is momentarily down how are you going to access it with a password at that moment? Y…
I'm referring to the process of switching where my passkeys are stored to a different place. E.g. moving from them being stored by Apple to them being stored by Google or any other provider.
Re: Passkeys: A shattered dream
#758Earlier quoted context omitted.
> With passkeys it's literally impossible. I dunno about you. But I like being able to get my passwords out of the password manager. How is not being able to do so a feature?
Because that opens you up for being phished.
Re: Passkeys: A shattered dream
#759Earlier quoted context omitted.
> It would be inconvenient if I needed to login to a shared computer Ok, I'll bite. Anyone knows how this would be done in that setup? "Can't" is a deal breaker, so is "use the password you had to generate and store in your manager anyway".
Most if not all providers that I've used still allow you to use a password. If you _had_ to you your passkey you'd probably have to install 1Password + the extension in your browser. This is definitely not a great workaround.
Re: Passkeys: A shattered dream
#760Earlier quoted context omitted.
I said "more interop" is coming.. There is a significant amount of interop that already exists, that folks are looking past or just already taken for granted (which is actually fine too!). While on a Windows machine using Edge, you can save a passkey for your Google account to your 1Password vault, and use it to sign in to that Google account on Chrome on Mac (if you have signed in to the same 1Password account on th…
I'll believe you when every home in America has a fusion reactor.