Passkeys for Infrastructure
goteleport.com
Passkeys for Infrastructure
1–10 of 73 posts
Re: Passkeys for Infrastructure
#2Meanwhile I'm sure a decade from now we'll all look back and say "Remember when we had to type _secret characters_ into a little box to log in to an app/site?"
Re: Passkeys for Infrastructure
#3This is exciting, I love that we're moving toward passkeys. When I tell non-devs that passwords will be going away in the years to come they almost can't understand what I'm saying. Like we've all lived this life of passwords for as long as we can remember so the idea of not getting having to click "Forgot my password" once a day is foreign to us. It's sort of like we've been gaslighted into thinking this is how it h…
Re: Passkeys for Infrastructure
#4This is exciting, I love that we're moving toward passkeys. When I tell non-devs that passwords will be going away in the years to come they almost can't understand what I'm saying. Like we've all lived this life of passwords for as long as we can remember so the idea of not getting having to click "Forgot my password" once a day is foreign to us. It's sort of like we've been gaslighted into thinking this is how it h…
The problem with passkeys IMO is they typically aren't portable between devices, and if they are, they will have some of the same problems as passwords. A long passphrase will probably have the same threat profile as a portable passkey, but with an easier implementation.
Worst case scenario, you have multiple passkeys per service identity/web property, one in each sync ecosystem (if the relying party supports it). Still better than passwords! If your SSO provider does't support passwordless/passkeys, loudly complain to them :) Azure Active Directory supports it, I have worked with a team to implement it.
(great post btw to the Teleport folks, both content and visual appeal)
Re: Passkeys for Infrastructure
#5Earlier quoted context omitted.
The problem with passkeys IMO is they typically aren't portable between devices, and if they are, they will have some of the same problems as passwords. A long passphrase will probably have the same threat profile as a portable passkey, but with an easier implementation.
For the vast majority of your layman use cases, passkeys are perfect because the switch rate between ecosystems is low. My mid 90s grandmother is not able to use a password manager, she's just not capable. Same for my mid 60s in laws. Passkeys fix this for them. If your use case requires heterogenous ecosystem support, it might make sense to wait for your preferred password manager to have passkey support (to have an…
Re: Passkeys for Infrastructure
#6Re: Passkeys for Infrastructure
#7Earlier quoted context omitted.
For the vast majority of your layman use cases, passkeys are perfect because the switch rate between ecosystems is low. My mid 90s grandmother is not able to use a password manager, she's just not capable. Same for my mid 60s in laws. Passkeys fix this for them. If your use case requires heterogenous ecosystem support, it might make sense to wait for your preferred password manager to have passkey support (to have an…
Hopefully someday some smart person invents a standard, secure way of handling enrollment/forgot my pass(key|word), as that will always be the weakest link. As much as it freaks some people out, a cryptographic national ID would be really helpful for this, IMO.
Agreed about a cryptographic national ID. One day! Login.gov is already prototyping using USPS for in person identity verification, we'll get there.
Re: Passkeys for Infrastructure
#8I remain unconvinced that Regular Users will find passkeys as necessary/useful as the rest of the industry does, especially older users. Will be interesting to see how pervasive passkeys become.
Re: Passkeys for Infrastructure
#9This means that soon your logins will be tied to your ID.
Re: Passkeys for Infrastructure
#10You can't use Passkeys on iOS without iCloud, and you can't get an Apple ID without a phone number, which frequently maps to real-world ID. This means that soon your logins will be tied to your ID.
Or did Apple manage to helpfully extend this standard into something requiring iWhatever accounts?