I really don't want to use Passkeys until they can be stored in my password manager of choice on Linux, Android and Windows.
Toward a Passwordless Future
11–20 of 70 posts
Re: Toward a Passwordless Future
#12So... what happens with passkeys if you lose/break/someone_steals your phone? I'm talking about normal users, without backups.
All of the major implementations sync across all of your devices and use recovery codes as part of the setup process. Apple’s implementation is designed to cover loss of all devices, and I’d assume the others are similar: https://support.apple.com/guide/security/escrow-security-for... The key thing to understand is that passkeys are not intended to be as secure as hardware tokens but to be more secure than traditiona…
Re: Toward a Passwordless Future
#13Earlier quoted context omitted.
All of the major implementations sync across all of your devices and use recovery codes as part of the setup process. Apple’s implementation is designed to cover loss of all devices, and I’d assume the others are similar: https://support.apple.com/guide/security/escrow-security-for... The key thing to understand is that passkeys are not intended to be as secure as hardware tokens but to be more secure than traditiona…
What if the provider of the major implementation decides to shut you out of your account?
If you have two password managers then they can serve as backups for each other. Unfortunately that means you have to register each account twice.
Re: Toward a Passwordless Future
#14Earlier quoted context omitted.
All of the major implementations sync across all of your devices and use recovery codes as part of the setup process. Apple’s implementation is designed to cover loss of all devices, and I’d assume the others are similar: https://support.apple.com/guide/security/escrow-security-for... The key thing to understand is that passkeys are not intended to be as secure as hardware tokens but to be more secure than traditiona…
What if the provider of the major implementation decides to shut you out of your account?
The fallback path here is what you’d do with any other MFA loss. It’s not a federated login system so you’d be looking at some kind of account recovery process for each of the sites where you used your passkey, just like you would if you lost a Yubikey or changed phone numbers.
Re: Toward a Passwordless Future
#15Earlier quoted context omitted.
All of the major implementations sync across all of your devices and use recovery codes as part of the setup process. Apple’s implementation is designed to cover loss of all devices, and I’d assume the others are similar: https://support.apple.com/guide/security/escrow-security-for... The key thing to understand is that passkeys are not intended to be as secure as hardware tokens but to be more secure than traditiona…
We can’t trust users to not re use a password, why do we expect they will go through the effort of storing / understanding recovery codes?
The key here is thinking about relative risk: many people get compromised by reusing passwords or being phished every day compared to the number of people who simultaneously lose all of their devices and recovery codes.
Re: Toward a Passwordless Future
#16I really don't want to use Passkeys until they can be stored in my password manager of choice on Linux, Android and Windows.
Passkeys are supported by my password manager of choice, in the OSs that I care about.
Re: Toward a Passwordless Future
#17I really don't want to use Passkeys until they can be stored in my password manager of choice on Linux, Android and Windows.
Re: Toward a Passwordless Future
#18So... what happens with passkeys if you lose/break/someone_steals your phone? I'm talking about normal users, without backups.
Re: Toward a Passwordless Future
#19Earlier quoted context omitted.
But if that "buddy account" is 'passworded' by the same passkey device? Getting a new sim card with the same number is easy, you just go to your mobile provider with your ID card, and you're done in five minutes. I mean still... the article mentions a "single point of failure" as a bad thing with other methods, but forgets about it here.
Until the passkey workflow goes sideways for "tech" people I don't think the risks will be acknowledged (if then even). Those of us who don't want the let Google, Apple, or Microsoft manage our passkeys (i.e. pledging our fealty to our lords) will be seen as fringe lunatics. I'll keep my workflow of always visiting sites by typing the URL myself, using a password manager, and TOTP 2FA w/ the secrets saved offline on…
Re: Toward a Passwordless Future
#20Earlier quoted context omitted.
What if the provider of the major implementation decides to shut you out of your account?
That depends on whether you need to have an active account to use your existing devices. For example, an Apple user would need to migrate before things fall out of sync but they have a full copy on every device. The fallback path here is what you’d do with any other MFA loss. It’s not a federated login system so you’d be looking at some kind of account recovery process for each of the sites where you used your passke…
Which, in many cases, is avoid MFA because it's less secure. Yes, less secure because availability is part of security.
And I don't have a better plan to store all those recovery codes than to store all those passwords. So the attacker can still get in with the same effort, but I have to keep getting my phone. No thank you.