Way too soon for anything that takes itself seriously to rely on passkeys.
Passkeys are just a mess right now. Despite attempts to improve things, it’s gotten even worse over the past few years. The tech giants, password managers, browsers and websites have just not been willing to work well with one another through FIDO. I’m guessing the tech giants are most at fault but who knows.
I keep saying this myself. I feel bad because there is a real problem they are solving (phishing) but ultimately it is an overly technical solution to an extremely human problem. They’re only as strong as their weakest recovery method and the inability for the average user to understand the technical implementation and ramifications takes power away from a personally held secret (problematic as that may be) and shifts it towards more platformization.
It all just makes me vaguely uncomfortable in ways I have a problem fully articulating.
I haven’t been following what these are or why they’re flawed. It looks to me like they’re taking Two Factor Auth, and removing one of the factors (the password). Now all you need is a device? If the device is lost or itself compromised, isn’t that still a single point of failure?
Use a password manager that supports passkeys. Then you can back them up and sync them between all of your devices the same way you do with your passwords and 2fa keys.
Way too soon for anything that takes itself seriously to rely on passkeys.
Passkeys are just a mess right now. Despite attempts to improve things, it’s gotten even worse over the past few years. The tech giants, password managers, browsers and websites have just not been willing to work well with one another through FIDO. I’m guessing the tech giants are most at fault but who knows.
I keep saying this myself. I feel bad because there is a real problem they are solving (phishing) but ultimately it is an overly technical solution to an extremely human problem. They’re only as strong as their weakest recovery method and the inability for the average user to understand the technical implementation and ramifications takes power away from a personally held secret (problematic as that may be) and shifts it towards more platformization.
It all just makes me vaguely uncomfortable in ways I have a problem fully articulating.
I haven’t been following what these are or why they’re flawed. It looks to me like they’re taking Two Factor Auth, and removing one of the factors (the password). Now all you need is a device? If the device is lost or itself compromised, isn’t that still a single point of failure?
You can backup a 2fa code on so many multiple managers at the same time, how the hell can one backup a pass key?
I’ve lost so many of those over the years lol
Use a password manager that supports passkeys. Then you can back them up and sync them between all of your devices the same way you do with your passwords and 2fa keys.
Isn’t the main issue moving them and that was effectively solved this week?
Still doesn’t work for me in my browser
What browser?
Vivaldi, with passkeys in proton pass