11 ms·
I do not know how to use a Passkey in a way that won’t impede how I log in to systems. I’ve been in tech for 26 years, and I understand the Public/private key b
by gortok 2mo ago
I do not know how to use a Passkey in a way that won’t impede how I log in to systems. I’ve been in tech for 26 years, and I understand the Public/private key behind what a Passkey is. Here’s what I don’t understand:
I access a website through at least four different devices (my iPad, iPhone, Windows Desktop computer, and MacBook Pro) and three different browsers on each device (Brave, Firefox, Safari) , and I use LastPass. If I accidentally set up a passkey on my phone (let’s say I use Safari one day instead of my go-to, Brave), can I still log in without that passkey on other devices? Is there a way to ensure that passkey can be used on other devices? Can I add another passkey on another device? How many passkeys can I set up for a particular site/app? I have at least 6 different combination of browser/devices in use.
I don’t want to use Passkeys because I don’t the answers to those questions, and I don’t know whether each website/app that has set up Passkeys has decided the answers to those questions in the same way as the others. For now, I’m going to stick with LastPass and use Passwords; because no matter whether I lose my device or not or whether I’m on my own devices or not, I can be sure I’ll be able to get into a site/app.
Edit: One final consideration, my spouse and I share user/name passwords for some things (notably Pandora and our Amazon Prime account) since they don’t handle things like family logins well; how do both my wife and I use amazon or Pandora with passkeys? Do we each set up passkeys? How do I get her Pass if that’s not an option?
- bombcar 2mo agoI’m 90% certain most of the push for passkeys is to prevent paid account sharing.
- cpburns2009 2mo agoThis is the main reason I've avoided passkeys. I have these exact questions and there's no a clear explanation given for these. I don't want to lose access to important accounts.
- dijit 2mo agoAgreed, it's the exact same as me, I haven't seen someone put it into such succint words before, so bravo. I think the reason is because I've anchored passkeys into my understanding of how 2FA works, and the pain of migrating 2FA from one phone to another. So, I don't want to bother with it.
- pas 2mo ago> there's no a clear explanation there's. it depends on how the site implemented passkeys. I'm using multiple devices and passkeys via keepassXC. I haven't lost access or even got locked out of any accounts. but it's like 2FA, and almost all sites have a clean fallback (backup codes) for 2FA.
- thyristan 2mo ago> there's. it depends on how the site implemented passkeys. so. no clear explanation.
- pas 2mo agothe same is true of passwords. some sites provide password reset some don't. how is that not clear?
- Telaneo 2mo ago> some sites provide password reset some don't I'm yet to see a site that doesn't provide a password reset (excluding websites without passwords). What inane webdev though that'd be a good idea?
- Melatonic 2mo agoHow do you sync the KeePassXC file?
- cpburns2009 2mo agoI use KeePassXC, just not for passkeys. I used to use Dropbox but now I use Syncthing. I use a strong password and a key file that IS NOT synced.
- jesseendahl 2mo agoThis is the #1 most common misconception I see about passkeys. They do not make it more likely that you will lose access to your accounts. They actually have nothing to do with account recovery. They are just a stronger primary factor than a password. Most providers continue to offer email-based recovery in the case that the end-user loses access to their primary factor, regardless of whether the primary factor is a password or a passkey. And email based account recovery does not make the security advantages of passkeys disappear, which are: - credential that's guaranteed to be unique - credential that's guaranteed to be strong - credential that cannot be phished (due to cryptographic binding to the domain at the time of credential creation) - changes the incentives for compromising servers (there's nothing worth stealing from the server -- only public keys) - if/when an app/website transitions to retiring password-based authN, then it will entirely eliminates credential stuffing attacks And if the account recovery scenario in question is your Gmail or Apple account, then you would need to go through their account recovery flows regardless of whether you were using a password or a passkey: https://support.google.com/accounts/answer/7682439?hl=en https://support.google.com/accounts/answer/7682439?hl=en https://support.apple.com/en-us/118574 https://support.apple.com/en-us/118574
- brentm 2mo agoIf you use something like 1Password it's very easy. It stores your Passkey and it syncs cross device. It's another thing but once it's set up it's less of a pain than using authenticator apps or having to find some random iPad that Google popped up an approval prompt on.
- sylens 2mo agoThis is how I use them but you have to admit that this assumes 3-4 things about a user just to save them the hassle of supplying two factors at login time. It's also unclear to users if passkeys can be migrated from one password manager to another
- wadim 2mo agoI'm using bitwarden, but it's possible to use passkeys from multiple devices and if it's not available for whatever reason, you can just login with username/password/token/biological probe/whatever you used before. As an example: GitLab gives you both options right from the start, so you can use whatever you fancy in that particular moment.
- FireBeyond 2mo agoDid [someone from the Working Group] ever back down from their implied threat to blacklist Bitwarden for allowing for the sharing/export of passkeys? That really rubbed me the wrong way, and smacked very heavily of "the big players (MSFT, AAPL, GOOG) can do this - you can't".
- cpburns2009 2mo agoI know KeePassXC faced the same threat. I don't know whatever became of it.
- mingus88 2mo agoIt’s really not that hard. Most of your devices are in the Apple ecosystem and when you are prompted to create a passphrase it will ask you to put it in your iCloud Keychain. Boom, now it is available across all of those This is how it will work for most people who don’t care about security and just casually use their devices. My boomer mom does this. It’s better than the notebook full of handwritten passwords she was using. You have chosen lastpass and a multi-ecosystem environment with windows and multiple browsers on each. You have chosen complexity and this is not a limitation of passsphrases as they have been designed for a more common use case. I use Linux and apple. I have chosen protonpass for my vault. I just tell my OS to save the passkey there and everything works pretty well. If not, my password is right there as fallback. It’s really not that hard.
- juancn 2mo agoWhat if I lose all my apple devices? House break-in and they steal my mac and my phone? You're basically fucked even if you buy a new one because you need one of the other two to log in.
- gretch 2mo agoNo technology in the world can protect you against every threat model and unlikely scenario. What if the robber hits you in the head and you get brain damage and forget your password?
- deejaaymac 2mo agoMaster password to password vault stored on metal, buried in my backyard and I tell a family member where it is in case I ever get brain damage
- gretch 2mo agoFamily member gossips "that crazy [deejaaymac] always burying secrets in the backyard..." Or straight up betrays you (you slighted them at some family event)
- juancn 2mo agoSame here, also what if I lose the device? I can safely write down a password on a piece of paper and keep it somewhere phyisically safe. Passkeys and 2FA are a usability nightmare if you need to recover, or all the security vanishes if you put usable recovery mechanisms for the passkey or the second factor.
- varispeed 2mo agoSounds like something security services would love people to use. Instead of using wrench to extract the password - and distressed person may lose memory, they can just locate the passkey.
- msandford 2mo agoNobody is safe from a nation-state "attack" they'll just go threaten your providers to give up your data. Passwords written on paper are probably safer than a centralized password manager for almost every circumstance other than a government coming after you.
- odux 2mo agoPapers: Safe - yes. Easy to lose/misplace: also yes.
- TeMPOraL 2mo agoHumanity having millennia of experience securing them: also yes.
- NetMageSCW 2mo agoI’d like to see them threaten Apple or Bank of America.
- izacus 2mo agoYou do the same as you do when you lose your SSH key. Restore from backup and move on with your life. Why is there so much misinformation nonsense around passkeys?
- darknavi 2mo agoWhy not use passkeys in LastPass? Then the passkey travels with you to your devices/apps.
- microflash 2mo agoYou can store your passkeys in Bitwarden or Keepass vault. Then you can use them through Bitwarden or Keepass apps on any other device. Been using passkeys like this for several years, and it works pretty seamlessly. With Keepass vault, I even have an offline copy as backup.
- RHSeeger 2mo agoIf you store the key in Bitwarden or Keepass, what makes it different from a password?
- kodt 2mo agoThe difference is you can't just copy and paste the private key into a phishing website. The login process validates your private key and logs you in. Also since the service does not store your private key, it is more resistant to data-breaches as that is one less potential breach source.
- RHSeeger 2mo agoBut most password programs do this too, if you install the plugin (which you pretty much need if you want those same programs to do the passkey thing, anyways)
- BadBadJellyBean 2mo agoThey are bigger. Not as easy to guess. More like pretty impossible. It's like not letting the user choose the password. That way they can't have a bad password.
- owaislone 2mo agoAnswer to almost all of your questions is that it entirely depends on the service what kind of auth implementation they offer. I personally have completely adopted passkeys and use them with every service that allows it. I use ProtonPass and have made it the default password store on every device and browser. This way all passkeys get stored in proton and I can login from any other personal device with proton setup.
- summermusic 2mo ago> ...it entirely depends on the service what kind of auth implementation they offer. I think that's exactly the problem. These are all answerable questions, but getting those answers is confusing for most people.
- TeMPOraL 2mo agoAlso from experience, most sites will implement it in every wrong way possible. For example, all the major sites that allow the total of 1 active TotP authenticator app - trying to add one forces to delete the other. Which is fine while you have only one phone and aren't in the process of switching to another one.
- deltoidmaximus 2mo agoWith foresight you can get around this since you can reuse the TOTP seed values. The annoying thing is so many services don't even support TOTP. They either want their own proprietary app, still insist on SMS, some of them even try to get you to use voice prints!
- mhurron 2mo ago> These are all answerable questions, but getting those answers is confusing for most people. It's the same answer when someone asks 'how am I supposed to have a different password for every site' and 'how am I supposed to remember a password of X+ characters.' Use a password manager. Pretty sure every major one supports passkeys by now.
- bflesch 2mo agoPasskeys basically MITM the 2FA process so that they can track and deplatform you with a single click across all your accounts. The biometric verification also allows to confirm that a certain person is holding the device, and they can easily be matched to existing passport/travel databases. Great system if the good guys have it, a bit problematic if it's abused by nepo kids to hide their crimes.
- vel0city 2mo ago> Passkeys basically MITM the 2FA process so that they can track and deplatform you with a single click across all your accounts. I use passkeys with a physical authenticator. How do "they" track and deplatform me with a single click? Can you explain?
- deltoidmaximus 2mo agoThe service can use the use the attestation feature to block passkey providers that are deemed undesirable for whatever reason. Hard not to see eventually only major providers being accepted, even things like Microsoft services requiring Microsoft Passkeys using the Microsoft Passkey App which you're now required to have on your phone. Or worse you now need Symantec Passkeys to login to Symantec services (using that example since I believe Symantec had a ToTP App you needed to reverse engineer to extract the ToTP seed from if you wanted to use a different Authenticator)
- vel0city 2mo agoIf a service wanted to do that they could already do that, you even point to an example with a platform requiring their specific app to use the account. I've had banks which required me to have their own time-based code physical security tokens to log in, isn't that in the end the same? This thing you're talking about isn't inherently a thing about passkeys. If a service wants to remove your ability to log in to their service they can do it in a million different ways. Also, the above poster said: > deplatform you with a single click across all your accounts "They" could do it across all your accounts with a single click. If service A decides to require attestation, how is that now affecting all my accounts?
- notatoad 2mo agothese questions all have easy answers that could be quite easily discovered by simply trying to use passkeys, instead of trying to find reasons not to use them.
- cpburns2009 2mo agoYou shouldn't be forced to discover what capabilities exist by brute force. Just freaking explain it.
- pjc50 2mo agoBut since there's a potential nonzero risk of permanent account loss, I don't want to experiment, and since I can still log in with email/password I'm going to keep doing that.
- giancarlostoro 2mo agoIf you save it via Passwords app, it'll be iOS / macOS mainly, but you can unlock with any Apple device that supports Passkey / Passwords app (so likely modern + reasonably updated) the easiest. If you want it to work "everywhere" then you CAN use your iOS / MacOS Passkey, it will show you a QR code, some places poorly support this, I believe both devices need bluetooth, and then it will authenticate it. Linux is the only oddball here, I had issues getting this flow to work. If the UX for Passkey improves, I will go all-in on it, I'm at the point I'd love to just completely block passwords from accessing my account, unless I explicitly enable it temporarily by logging on via passkey, I wish some sites would let me lock my account to this level, it would be better. Passwords feel like they just wind up all over the web. Weirdly enough you can store multiple passkeys for a given domain, which can get confusing in some cases if they dont have normal names tied to them. Edit: Originally I thought Passwords from Apple was iOS / macOS only, but its not! So I have been editing my original message, sorry for the confusion, I had forgotten that I can login on Windows with my Passkeys from Apple's ecosystem. As another poster noted, you can transfer them out of Apple's ecosystem too!
- reddalo 2mo ago> Linux is the only oddball here, I had issues getting this flow to work. Take a guess why. Passkeys are just a trick for vendor lock-in disguised as a security practice.
- giancarlostoro 2mo agoFirefox just didn't support it cleanly, I think Chrome did, I don't remember. Apparently it's just due to Linux not having a native passkey implementation. Dang. Edit: Apparently BitWarden should work, but my particular passkey was not on there.
- PaulDavisThe1st 2mo ago> Apparently it's just due to Linux not having a native passkey implementation. Excuse me? The infrastructure for "an apps is trying to login with a private/public key pair, and right now it needs the private key to encrypt some part of the transaction" has existed on Linux since it began. The problem, as best as I can understand it, is that some/all browsers are not treating passkeys as an extension of the key system that began with ssh(1), even though technically speaking, they are.
- helix90 2mo agoListening to Yubikey and OnePassword talk about this, they actually say "One Person, One Device". Which really speaks to their failure to understand their users.
- gortok 2mo agoI would love to see what you’re referencing, can you provide a link or citation to that quote?
- helix90 2mo agothe video requires signing up for Yubikey spam. https://app.livestorm.co/yubico-y/securing-trusted-actions-and-ai-workflows-with-passkeys/ https://app.livestorm.co/yubico-y/securing-trusted-actions-a...
- thewebguyd 2mo agoBecause the original FIDO/WebAuthn standard was built for device bound credentials. They imagined unique keypairs tied strictly to a specific piece of hardware. Synced passkeys were a compromise, mostly driven by Apple and Google, because per-device credentials are too much friction for general use. It's not that they failed to understand users, it's that they incorrectly assumed the level of inconvenience people are willing to tolerate to be textbook secure (the answer is almost zero inconvenience). The device bound model also completely falls apart in the enterprise, fails to address shared devices and shift workers where employees share the same PC under the same OS profile, now you're back to needing good old fashioned SSO w/ physical MFA (Yubikey) to attest who the user is in addition to attesting the device itself. Before synced passkeys, the actual standard is a unique key pair per device. The key pair on my phone shouldn't be synced to my laptop, my laptop should generate it's own key pair.
- astrospective 2mo agoThat is odd, I regularly use my Yubikey on multiple devices, that was the biggest draw.
- 2mo ago
- dfabulich 2mo agoThis is much, much simpler than you think it is. Passkeys are just passwords that require a password manager. If you lose your passkey, you'll reset your passkey the same way you reset your password, probably with a "forgot my password" email. (But you're not going to lose it, because you use a password manager, and the passkey will be stored there and synchronized to all of your other devices.) The weird part is that password managers provide no way for you to copy and paste your passkeys. To present a passkey, you have to use a password manager. This makes it impossible to copy and paste your passkey to the wrong person (someone trying to trick you). Major password managers don’t even allow you to export your passkeys to a file that you can read/backup yourself. Instead, the password managers each have their own finicky app-to-app mechanism for transferring passkeys from one password manager to another. (I think all the password managers kinda like that lock in.) Finally, note that for logging into your password manager itself, you'll always require something outside your password manager to login, probably a password, but possibly a YubiKey; your choice. (It's your one "last password," as they call it.) https://danfabulich.medium.com/passkeys-are-just-passwords-that-require-a-password-manager-ebb7f2fdcadf https://danfabulich.medium.com/passkeys-are-just-passwords-t... P.S. It's past time to move off of LastPass. LastPass lost all of your passwords again last month, just like they did in 2022. The most similar service is 1Password. If you like LastPass, you'll like 1Password about the same, but 1Password hasn't had multiple terrible security breaches.
- xboxnolifes 2mo agoSo to login using a public PC, you need either USB access (and carry around your password manager) or you need to install the password manager on the PC to log into a website?
- realityking 2mo agoThere’s a process to scan a QR code with your phone and your phone then authenticates with the passkey.
- archargelod 2mo ago
- 1-more 2mo ago> If I accidentally set up a passkey on my phone (let’s say I use Safari one day instead of my go-to, Brave), can I still log in without that passkey on other devices? N=1 and I'm sure I'm holding it wrong, but I can only log in to ADP to request PTO from my personal laptop because I set up an iCloud passkey, work laptop does not allow access to iCloud keychain, and you can't request PTO from mobile.
- nozzlegear 2mo agoAlthough that's more a failure of your workplace's security policy than of the Passkey itself. It makes sense that the passkey doesn't work if you can't access the place the passkey is stored.
- 1-more 2mo agoyeah but my problem is that I can't fall back to logging in to ADP with a password. Maybe there's some way to fix this? IDK.
- throwawayffffas 2mo agoI think the intended workflow is you login with your phone and that device is now the authority that allows other devices to issue their own passkeys. In my opinion it's a bad plan, because it elevates certain devices to privileged status, if you lose your phone you are hosed. Passkeys should be allowed to be synced between devices and stored on password managers in the cloud. I am making my own password manager for my personal use, but have not delved into passkeys.
- qlte 2mo ago> Passkeys should be allowed to be synced between devices and stored on password managers in the cloud. I am making my own password manager for my personal use, but have not delved into passkeys. They are, that’s exactly how I use all my passkeys with Bitwarden. They sync to any device I have Bitwarden installed on when added on one device.
- throwawayffffas 2mo agoYeah that's all hackery I think, if you read at the specs there is always a device involved, bitwarden and company just pretend to be a device or have an extension that just ignores the spec.
- teekert 2mo agoI use ProtonPass and afaiu it just syncs the passkeys private part everywhere you need it. So it “just works”. This is better than just old fashioned credentials because the passkey only “triggers” on the correct domain, so they can’t be phished by other domains… Right?
- rufo 2mo agoI recognize the point of your post is more about the lack of clarity and details around passkeys. That's real, and I don't really have an answer for that - other than, I think maybe the quest for making them simple and "just work" has maybe made them nebulous enough that we've wound up in the current situation where a lot of even technically savvy people don't really understand them. But I feel like answering your questions might sort of help explain why that's the case, so I'm going to take a stab at it: > If I accidentally set up a passkey on my phone (let’s say I use Safari one day instead of my go-to, Brave), can I still log in without that passkey on other devices? Assuming you have LastPass set up to be an iOS password manager, and it fully supports iOS' passkey implementation: when you create a passkey in Safari, it will ask you if you want to store it in LastPass or in the iOS Passwords app (previously known as iCloud Keychain). If you say LastPass, then it's up to them, but I assume it'll sync to all your devices - it's how 1Password works. If you were to accidentally say Apple Passwords, it'll sync to all your Apple devices automatically, and you can either use Apple's password browser extension on Windows, or you can use the "another device flow" I'm about to detail. > Is there a way to ensure that passkey can be used on other devices? As mentioned above, passkeys are intended to sync via your password manager of choice as the primary use case. If for any reason you don't have that passkey synced to that device, _and that passkey is on a mobile device with a camera_, most browsers will give you the option to scan a QR code with your phone. This kicks off a flow that will authenticate you via your phone's biometrics or passkey, then use Bluetooth to first ensure device proximity and then handle the authentication exchange. In the case of iOS, this includes any passkey-supporting password manager, so the passkey itself can be in 1Password; it doesn't have to be in the iOS password system for this to work. When I first read the above, my hackles were raised given how well Bluetooth operates at times; but every time I've used it so far, it's been fast and flawless. Still, I can see a lot of scenarios where this might not work - e.g., the first one I thought of was a public computer at a library where Bluetooth might be locked down; corporate computers or remote servers could also be troublesome. As far as I know, passkeys don't yet have answers to those scenarios; other than to just use your password + 2FA as you would without a passkey. As far as I know, both of the above apply to every passkey-consuming site. > Can I add another passkey on another device? How many passkeys can I set up for a particular site/app? This touches on your last paragraph, where it indeed could change based on the website. In my experience, every website where passkeys are fully supported - e.g., not ones that are using passkeys as a substitute for FIDO/U2F keys - has let me add multiple passkeys and have not _appeared_ to have a limit. I typically will create a passkey in both 1Password and Apple Passwords just to have a backup, and I can't recall any cases where that's been a problem. Still, I can't say for sure that isn't a problem on any website. I went all in on trying passkeys when they started to be an option, and I don't have any notable regrets. For me, passkeys have generally worked well when the site is designed to use them well; and at no point have they been a _major_ hindrance. That isn't to say there are _no_ annoyances, though: - Most websites that support passkeys tend to use them as a replacement for both the password _and_ 2FA, which makes them more convenient. However, a few - Amazon being the most notable I can recall - only use them as a second factor, which just makes them feel a little useless. - A passkey can _also_ be used as the proof of identity, meaning you can log in in one fell swoop and don't need to enter a username or email address, which is IMO the best showcase for passkeys. Like above, this makes websites that ask you to enter an email address before letting you use a passkey also feel annoying. - Most web browsers I've used support the QR + Bluetooth flow I mentioned above (otherwise known as Hybrid Transport or caBLE) without issue; Linux has been the odd duck out. Firefox doesn't seem to support it at all on Linux, and Chrome-based browsers do but sometimes are missing what they need and in that case don't show it as an option. Since I sync just about every passkey with 1Password this typically isn't a problem; the exception is the passkey for Apple Accounts, which Apple creates automatically, and (AFAIK) doesn't allow you to enroll your own. Apple Accounts are the only service I've found that does this, though. - Some websites seem to only offer passkeys as an option if you're on a mobile device, or at least did so at the time of enrolling. eBay and PayPal I think are the two that jump out at me as having done this. Why they did it this way instead of simply detecting if the browser supported passkeys, I have no idea. All of the above issues have gone down over time, so it's generally been a net decrease in friction over time. And, at least as far as I can recall, passwords themselves continue to be an option in every instance I've enrolled a passkey. So if you like your passwords, generally speaking, you can keep them :P
- 3RTB297 2mo agoMy issue is that they're touted to the consumer as secure, and they're not really doing much more than a complex password. How do you generate a new key if you need one? Same process as a password reset. Does it prevent session stealers? Not at all. Its "benefit" is grandma can't read it to an attacker. OK, well can grandma click a link and have a session stealer bork her life instead? Yeah, and attackers know that and just shift methods. Session stealing isn't a sophisticated attack, and so all that's being done is shaving a cost on PW resets in the interest of shareholder value, at the cost of security theater and locking up your keys in a single domain that holds control over our access to everything.
- zdp7 2mo agoThere is security value. A passkey will not work anywhere except the actual website. Fake look a like sites can't get the credentials. Evidently they can trick you into authorizing their device.
- thyristan 2mo agoSure? MitM isn't a new kind of attack, and I'd be surprised if the ball-of-wax-and-javascript that is WebAuthn isn't vulnerable to that...
- zdp7 2mo agoThis is one of the key security features of passkeys. I did a little searching and the work around is to do a standard fake website that prompts for your standard credentials. That should be a fairly simple fix. Require access from a new device to be authorized from another source with an explanation that they will never request this info.
- harshreality 2mo agoThat's also how any good password manager works. You'd have to manually copy-paste the password to get around the same-site fill restriction (whether it's autofill or manual fill).
- pkulak 2mo agoI think the point is that Passkeys are not supposed to be as precious as passwords. You're supposed to have a brand new one for every device/application combination. So they are just login cookies at this point, and haven't even come close to replacing passwords because you need to know your password to get a new passkey every time you log in. Now, is that the official stance? I don't know; but it's _absolutely_ what every current implementation suggests the companies deploying this stuff want. You can make passkeys better. Like me, you can install a well-funded password manager (well-funded, because it needs the engineering effort behind it to keep up with the ever-changing passkey apis on every platform in the world; screw up and oos, can't log in today!). Then you have one passkey per remote service, and just have to make sure 1password is _always_ installed and perfectly integrated. Easy!
- MattTheRealOne 2mo agoThere are a couple of problems I have with that. 1) Many websites limit the number of passkeys I can link to my account. Some only allow 2 or 3. I have more devices than that. 2) If I am supposed to create a new passkey for every device, how do I login in the first place? Most websites currently fallback to password login which defeats the security benefit of using passkeys in the first place. I currently only use passkeys for a few websites that have awkward password login workflows or do not autofill properly from my password manager. I just have a single passkey for each that is synced via Bitwarden. Currently, I see passkeys as using an electronic biometric lock on the front door while passwords are still regular locks on the backdoor. The biometric lock on the front door does not do much for security when the backdoor still exists and I have come across very few websites that support only allowing passkeys. And those that do still run into problem 2 listed above.
- pkulak 2mo agoYeah, I agree. My policy is much the same as yours: set a passkey only when a site makes logging in with a password such a PITA that the PITA of a passkey becomes the easier option. Google comes to mind. They seem to actively not want anyone to log in. At some point sites will start to 2FA you even with a passkey, but we don't seem to be there yet.
- skybrian 2mo agoCopying / syncing passkeys between password managers is still work in progress, but you can usually work around it by making multiple keys. For important websites, I recommend saving additional passkeys to Keychain, etc, as backup, assuming the website allows that. (It should, but some websites might not have a good implementation.) Also, nothing says you have to delete passwords (or alternate means of logging in) if you already have them set up. Having multiple ways in will help prevent lockout.
- zdp7 2mo agoUnfortunately probably implementation specific, but you don't always need to have multiple passkeys. There is cross device passkey login. I had this occur in the last couple weeks. Evidently I had created a passkey on my phone. Logging into that site on my PC, it identified that I had a passkey and allowed me to authenticate using my phone.
- hoppp 2mo agoYou can add as many passkeys as you want and you can still have password logins too.
- MattTheRealOne 2mo agoI have come across many websites that limit how many passkeys I can add. Some have only allowed one or two.
- hoppp 2mo agoYeah, it's bad implementation on the websites but the protocol doesn't have a limit.
- pseudalopex 2mo ago1 of gortok's points was I don’t know whether each website/app that has set up Passkeys has decided the answers to those questions in the same way as the others.
- mdavidn 2mo agoI can't speak to all of your browser combinations, but most desktop browsers can present a QR code when logging in with a passkey. I keep my passkeys in a password manager synced between my phone and personal computers. On my work computer, where the password manager is not installed, I can still use passkeys by scanning the QR code with my iPhone's camera app.
- shinryuu 2mo ago(small parenthesis, please consider to _not_ use lastpass given they have had so many security incidents https://en.wikipedia.org/wiki/LastPass#Security_incidents https://en.wikipedia.org/wiki/LastPass#Security_incidents )
- pjsg 2mo agoFor me, it is "how many passkeys can I have for the same site?", and "how do I revoke them?" Worse, I'm still using LastPass -- but migrating over to Chrome password storage as it syncs between phone and laptop. LastPass doesn't give you the option to not use it for passkeys. It might be the thing that causes me to finish the migration away from it.
- thecombjelly 2mo agoA potentially good idea got corrupted by vendors, password managers, browsers, etc trying to assert control. I'm also an engineer and I find the UI around passkeys entirely unclear, but it doesn't have to be that way. It seems like everyone wants to be _the_ password manager for all your passkeys. They don't want to make it easy to understand that is what they are doing though, they just happily offer to "handle it for you". My non-technical friends are extremely confused by passkeys and if they should use them and how to use them and I honestly don't have very good answers. It is a mess. I don't believe an inherit mess, but one created by the companies and projects trying to take advantage of the new system.
- thewebguyd 2mo ago> It seems like everyone wants to be _the_ password manager for all your passkeys. Which defeats part of the point of passkeys in the first place in that they are supposed to be device-bound, the private key held in the TPM or secure enclave or whatever other security chip, mathematically non-exportable. Storing all your private keys in a cloud vault still leaves you exposed to potential credential theft if your vault gets compromised. Every device is supposed to have its own unique private key, stored in TPM, released only when passing the user challenge (biometrics or pin, or a yubikey).
- Someone1234 2mo agoRight; but THAT idea is consumer hostile by design. So your account is now tied to a physical device; great, but the device is dead, or you own a dozen devices, now what? Each vendor has their own idea about what THIS means. Heck I have a couple that allow, max, a single Passkey at a time.
- thewebguyd 2mo ago> Right; but THAT idea is consumer hostile by design. No argument from me there, just stating what the design actually calls for. It was never meant to be consumer friendly in the first place, it's an enterprise standard. It was just shoehorned onto consumers with the synced credential compromise to make it easier, instead of coming up with something better, and then just calling it a "Passkey" which now has dual meaning. But the real solve is difficult. If a system requires a consumer user to manage, remember, or safely store something extra, it will fail.
- readread 2mo agoI’ve just been operating under the assumption passkeys are gonna lock me out unrecoverably in some way at some point, and have been avoiding them for anything important while allowing them for low-value accounts so they’ll stop nagging me. I hate that I can’t just put a value in a plain text file somewhere (encrypted, let’s say, to preempt the inevitable and low-value response) and rely on that to work when I need it on any device and interface that can accept keyboard input.
- deltoidmaximus 2mo agoI avoid using them altogether for the same reason. I won't use them for low value accounts because it signals that I think they might be acceptable to eventually require for high value ones. And of course low value accounts have no value so I don't even care about phishing on most of those.
- readread 2mo agoHaha, this thread has prompted me to follow some of the discussion about stupid bullshit like requiring "user is present" attestation and banning passkey programs (LOL wut?) if they lie about it, or resistance to allowing exports and portability. I'm now on team "I am outright anti-passkeys and hope they fail and everyone pushing them cries a whole lot about it and never gets over it".
- selicos 2mo agoIt makes sense for a work device that is off network/domain, but then it is your primary/only means of interfacing with services. Then you can consolidate under a Windows Hello passkey or something else. The second you have a second device to log in from they are useless. The second you want or need to share a credential (smart or not) they are more work than a password. The passkey trend seems lead by platforms that want to make it easier to get or stay logged in, Netflix type companies that want to prevent account sharing, and those that value convenience (if one device) over security.
- rpdillon 2mo agoTotally in the same boat, passkeys seem to massively increase the risk that I will lose access to my data.
- OkayPhysicist 2mo agoI've taken up the strategy of telling any less-technical person who asks me about passkeys that they are the mark of the beast, intrinsically evil, and should be avoided at all costs, and I encourage all y'all to do the same. Maybe, at some distant point in the past, there was a plan for a whole system of intercommunicating implementations of passkeys. That is no longer the case. The moment that they decided to include the information necessary to only allow the use of certain passkey vaults in the protocol, and then use that capability to threaten to lock out certain vaults that dared to let users actually be in control of THEIR OWN DAMN CREDENTIALS, it invalidated the entire project in my eyes. Passkeys cannot be trusted, they are designed to let entrenched powers hold your authentication hostage, and should under no circumstances be allowed to take root in the computing ecosystem.
- kbelder 2mo ago>...they are the mark of the beast, intrinsically evil, and should be avoided at all costs That's basically my recommendations to people. 1. Avoid using them if possible. 2. If you have to use them, make sure you have a password login to fall back on. 3. If the site forces you to use them, make sure you don't use it for any thing you rely on.
- seemaze 2mo agoI use bitwarden[0]. It covers all cases and devices in question. As a bonus, I self host using the open source vaultwarden[1] server implementation, which is packaged in alpine linux. [0] https://bitwarden.com/ https://bitwarden.com/ [1] https://github.com/dani-garcia/vaultwarden https://github.com/dani-garcia/vaultwarden
- giantg2 2mo agoThe thing I find burdensome is managing all the keys in a secure way. I think I would want a hardware token to store the keys on, have separate keys for every site, need to back up my keys onto a second token in case the first one is lost, etc. It gets burdensome. At least with passwords you can store them in various ways that are not hardware or software dependent.
- Macha 2mo agoIn practice, because site owners know users are going to mess up having their passkeys on all devices, I've not seen any insist that a passkey _must_ be used, and you can always log in with your password (or worst case, email magic links) as a fallback. However, this negates the primary stated objective of passkeys, removing the possibility of users being phished, so I'm not sure how long that will remain the case everywhere. I've also encountered sites that have a login with passkey prompt that then turns around and asks for TOTP 2FA or email confirmation anyway, which to me seems to negate the primary customer benefit of passkeys...
- jolmg 2mo ago> I've not seen any insist that a passkey _must_ be used, and you can always log in with your password (or worst case, email magic links) as a fallback. With the exception of Github, and banks.
- dfabulich 2mo agoDid you try it? That’s not correct. I just logged into GitHub with a password (+ 2FA), on an account that also has a passkey. No major bank revokes your password when you setup a passkey, either.
- jolmg 2mo agoIs "passkey" only supposed to mean devices that implement specifically U2F, WebAuthn, etc.? I would have thought TOTP and challenge-response hardware tokens to count, including cellphones with apps that implement such. As to > No major bank revokes your password when you setup a passkey, either. If we're talking about requiring 2FA via TOTP or challenge-response hardware tokens or banking apps implementing such, that depends on the country. It's the status-quo in some places. Some banks even put the input field for the token output as a third input in the login form on their website because all customers have them. The rest separate their login form in multiple steps, but they likely require it of all customers too.
- 2mo ago
- ilchalpenl 2mo ago> Edit: One final consideration, my spouse and I share user/name passwords for some things (notably Pandora and our Amazon Prime account) since they don’t handle things like family logins well; how do both my wife and I use amazon or Pandora with passkeys? Do we each set up passkeys? How do I get her Pass if that’s not an option? Lets say it is a android phone. Open amazon app. login in the usual user/password + 2FA (like with QRcode or phone). create passkey. done. This passkey would have been now synced to your google account. Take next spouse phone. Open amazon website or app. try login it will try for passkey but cannot find it. so - login in the usual user/password + 2FA (like with QRcode or phone). create passkey. done - Now this passkey would have synced to spouse google account. In future, assuming you have apple or windows laptop. assume you have signed into Google (chrome). Now go to amazon. It will ask - shall I sign in with passkey. Yes, give your macos fingerprint or windows hello or password of that laptop. login Done magically. You dont even need to remember username or password. Assuming you both have iPhones. You can sync the passkey to icloud account. And for every new iDevice it will be available. The main bottleneck of passkey would be that all 3rd party sites will have another non-passkey way as backup to login. I have never seen a website that would say - remove all other methods and keep only passkey. In a way passkey is 99% convenience. If a hacker would some how get your sms and password they can by-pass.
- gortok 2mo agoThanks. One glaring issue I see is that right now police can’t ask you for your password in the USA (a violation of the right against self-incrimination). They can however get a search warrant for your device and your biometrics, and wouldn’t need your password if they can gain access through your pass key.
- srparish 2mo agoIf you have it enabled, and you're in custody or at a border or similar, and have biometric auth enabled on your phone/computer, they can hold it up to your face or force you to put your finger on it to unlock it. Search warrant be damned.
- 2mo ago
- radial_symmetry 2mo agooh good I thought it was just me who didn't understand them
- PaulHoule 2mo agoI find it abjectly terrifying. Like if I log into your site with a Passkey what happens if my device breaks? What if some big tech company decides to nuke my account for no good reason?
- Saris 2mo ago>If I accidentally set up a passkey on my phone (let’s say I use Safari one day instead of my go-to, Brave), can I still log in without that passkey on other devices? Yes, but you can also add the passkey to your password manager so it's available on all your devices. >Can I add another passkey on another device? Yes. >How many passkeys can I set up for a particular site/app? I haven't really seen a specified limit on any sites, but also if you're using a password manager it's only 1 passkey for all your devices anyways. > For now, I’m going to stick with LastPass and use Passwords; because no matter whether I lose my device or not or whether I’m on my own devices or not, I can be sure I’ll be able to get into a site/app. Your passkeys would be in LastPass as well like your passwords, so arguably the same result regardless of which you use. >Edit: One final consideration, my spouse and I share user/name passwords for some things (notably Pandora and our Amazon Prime account) since they don’t handle things like family logins well; how do both my wife and I use amazon or Pandora with passkeys? Do we each set up passkeys? How do I get her Pass if that’s not an option? If it was me I'd add a second passkey to my password manager for your wife under a new entry, and share that entry to her lastpass account. Or if she's not on lastpass, you could just copy the data from the passkey over to whatever she does use.
- halJordan 2mo agoI get your problem, i don't really accept it as valid. Passkeys were always supposed to be fungible. You have one in your iPhone, a different one on your desktop. A third in your significant other's phone. All stored in the hardware tpm equivalent. You can have 7 passkeys. You can have 14. The real failure of passkeys (emphasis on the s!) is that people think they must only have one.
- tsimionescu 2mo agoAgain, is this true for all major sites that support passkeys? And how do you set it up? My passwords are automatically synced between my devices, how to I achieve the same thing if I set up an account with a passkey?
- halJordan 2mo agoWhy would you take one passkey and move it between devices? Generate a new one. They're fungible. You set it ask to the exact same way you do today. It's not a problem.
- pibaker 2mo agoThis assumes all services let you generate new passkeys with no hassle, which is not true.
- tsimionescu 2mo agoAgain, do all major sites allow you to register 6-10 passkeys? Not asking if they could in principle, but do they in practice do it? And how easy is it to log in with a new device to generate that passkey? Do I have to jump through hoops on my laptop, second phone, secondary browser, and so on? Finally, if it is easy to register a new device, how does the anti-phishing still work? Can't an attacker just convince me to use whatever means I would normally use to register a new device, instead of an existing secure passkey?
- chrisandchris 2mo ago> [...] people think they must only have one. That's the real failure? I think the real failure is that people must have _more than one_. I thought so hard to add all my credentials to 1Password. Now people tell me I should use a Yubikey (or better two or three of them). What do you think, I'm going to register a couple of hundred accounts times three for something I already have (my password manager)? The real advante in passkeys is in allowing me to log in into a service on a foreign device without typing [my password], which is (honestly) something now sane person should ever do.
- NautilusWave 2mo agoI save all my passkeys in Bitwarden and they sync across devices.
- SoftTalker 2mo agoSame. I'm a tech professional, and I don't set up passkeys for similar reasons. I log in to online services from a lot of different devices and browsers. I use a password manager but the keys to the kingdom (my email password) exists only in my head.
- jmalicki 2mo agoI don't know the exact tech behind it, but for a phone passkey I get a QR code on my laptop screen to scan with my phone, I accept it, and it logs me in.
- sharts 2mo agoNot sure about lastpass, but you can save passkeys to 1password. Works just fine.
- clickety_clack 2mo agoNotwithstanding the danger of having everything on a single platform, the Apple passkey works great. Sign into one and you’re signed in everywhere and you can share passwords with others.
- OptionOfT 2mo agoWife and I use bitwarden. For shared accounts we put them in a shared folder, and the passkey is attached in there, in bitwarden, meaning it survives device resets.
- beAbU 2mo agoI store my passkeys in Bitwarden. Can you not do the same in LastPass?
- tecoholic 2mo ago> and I use LastPass Oh! No. Please switch to something else. Last pass has had so many breaches, at this point it’s just not worth it.
- inigyou 2mo agoOne time, before passkeys, I tried SMS 2FA since everyone was saying 2FA was the future, if you didn't have it you'd be hacked, so I set it up. Next day, phone is bootlooping. Had the recovery codes of course. This sort of thing happened to me three times before I said never again 2FA. It seems to be a device to lock you out of your accounts. You know how many of my passworded accounts got hacked in my lifetime? Zero.
- spaqin 2mo agoAt least with an SMS 2FA, you can get the SIM card out and put it in another device. If you happen lose the SIM card, your phone operator will probably get you another with the same number once you identify yourself. With authenticator apps or yubikeys, if you lose them (or get a bootloop, or wipe your phone forgetting to back up everything first), there's no path of recovery at all.
- inigyou 2mo agoNot if it's a prepaid eSIM
- dizhn 2mo agoI didn't know the answer to any of these either and don't have a hardware key (I thought this was required for a long time) but one day I just clicked add a passkey on a site and the Bitwarden extension picked up the flow and everything was ridiculously easy. Now I also do get how it works, having used it on a few sites. Highly recommend.
- marysol5 2mo agoEverything you ask is nothing to do with PassKeys, but to do with whatever platform you use authentication flow...