Earlier quoted context omitted.
Think of passkeys as being the same as a password database. The provider can offer whatever recovery mechanism they want, and sites that use passkeys can continue to offer account recovery methods completely independent of their use of passkeys. As for what Google does specifically with their implementation, I'm not sure. I personally plan to use KeepassXC's implementation, whenever that comes out, with my own custom…
This is an area with the specs contrast with the vendors. The WebAuthn specs recommends to register multiple passkeys/credentials per device and assume that once a credential is lost it might not be recoverable. Apple and other vendors using keychains/wallets are effectively offering the option to delegate the recovery of the passkey to the recovery of the account with them (eg: the iCloud account). In case it is of…
Passkeys now support external providers
111–120 of 185 posts
Re: Passkeys now support external providers
#112Earlier quoted context omitted.
Just chiming in to ask -- the immediate need for account recovery is in cases with lost or forgotten passwords. Am I right in assuming that account recovery becomes a much smaller attack surface when using passkeys? Or are there scenarios I'm overlooking?
So you're covered for "forgotten" - but "lost" is still an issue. What happens when a user loses their passkey? (stolen phone, no backups, house fire, etc).
Re: Passkeys now support external providers
#113Earlier quoted context omitted.
Passkeys were designed from the start to enable portability if desired. The rollout has been a mess though, so it’s been very effective in causing a lot more confusion than needed. From the page: > What’s new > Now people can share passwords and passkeys from iCloud Keychain with their trusted contacts. *Password manager apps can save and offer passkeys on iOS, iPadOS, and macOS*. Enterprises can take advantage of pa…
That emphasized sentence is key. Pessimistically, it could mean that password managers can ‘save’ only to the Apple OS passkey store, acting as an intermediary transport, without being able to provide cross-platform vendor-agnostic sharing.
I totally understand a pessimistic reading. In trying to roll out passkeys to everyone at once, and doing a poor job of UX and documentation clarity, all the major players bungled the 2022 launch. Not having some portability out of the gate absolutely caused unnecessary distrust about passkeys.
But I strongly believe this won’t become a vendor lock-in playground.
I have replied a lot about passkeys. I should disclose a former employer works in this space, but I’m not advocating for any particular company or product here, and I no longer have any inside knowledge relevant to the topic that isn’t already public.
Edit: grammatical typo; disclosure clarification
Re: Passkeys now support external providers
#114Of all the recent publications with regards to passkeys, FIDO2, WebAuthn, etc., finally there's one with a simple and concise summary of the benefits: > Strong credentials. Every passkey is strong. They’re never guessable, reused, or weak. > Safe from server leaks. Because servers only keep public keys, servers are less valuable targets for hackers. > Safe from phishing. Passkeys are intrinsically linked with the app…
> Safe from server leaks. Because servers only keep public keys, servers are less valuable targets for hackers. It's still an attack scenario to keep in mind. If a server can be tricked into storing the wrong public key, authentication is defeated.
Re: Passkeys now support external providers
#115That's a great development. Reducing vendor lock-in removes one of the bigger reservations some mentioned in regards to WebAuthn.
Re: Passkeys now support external providers
#116Earlier quoted context omitted.
> Whichever way you look at it, in every sense, password managers are a really bad, bad idea. Okay, how about, the actual problem they solved: Reusing a single, simple password on every site, shared behind an email login. That doesn’t sound like a really, really bad idea.
At what point did password managers invent the idea of using a different password for each account? That is computing basics from the beginning. They didn't solve a problem, they just increased the lottery prize if the master password gets compromised. Every body can continue down-voting, but that fact is not going to change.
They didn't invent the idea.
They just made it useable for people who have a lot of different accounts.
I've got nearly 500 accounts, and based on a comment thread a while back where someone asked here how many accounts people have in their password managers I'm on the low side.
Re: Passkeys now support external providers
#117One thing I don't understand about offering passkey login for your email is how you would go about recovering an account if you lost access to the device which holds your passkey? Google states: "When you create a passkey, you opt in to a passkey-first, password-less sign-in experience.". This seems to imply that you will not be able to use your old password if you ever lost your phone. Do Google still offer backup p…
Re: Passkeys now support external providers
#118My method for judging the quality of software: Read the latest release notes, negate every statement, and think to yourself: "They were fine with it being like this until now." Passkeys have been advertised as a superior replacement to passwords, but really fundamental issues remain unaddressed. I have one (1) Windows PC and one (1) iDevice. Can I get these to sync? Will both be able to log me in to a Google Account?…
Yes. In Chromium-based browsers, at least. Your browser will display a QR code which you scan with your phone. Your phone will display a list of accounts you can sign in with, you select one, authenticate, and you're logged in. Firefox support isn't here yet.
Re: Passkeys now support external providers
#119Earlier quoted context omitted.
That emphasized sentence is key. Pessimistically, it could mean that password managers can ‘save’ only to the Apple OS passkey store, acting as an intermediary transport, without being able to provide cross-platform vendor-agnostic sharing.
1Password previously announced that mobile support for passkeys stored in 1Password was on its way later. I assume they had advanced knowledge of this announcement. I totally understand a pessimistic reading. In trying to roll out passkeys to everyone at once, and doing a poor job of UX and documentation clarity, all the major players bungled the 2022 launch. Not having some portability out of the gate absolutely cau…
Re: Passkeys now support external providers
#120One thing I don't understand about offering passkey login for your email is how you would go about recovering an account if you lost access to the device which holds your passkey? Google states: "When you create a passkey, you opt in to a passkey-first, password-less sign-in experience.". This seems to imply that you will not be able to use your old password if you ever lost your phone. Do Google still offer backup p…