The Problem with Passkeys
bulwark.id
bulwark.id
1Password is also working on passkeys, which I think is great! Their support currently isn't out yet, but they also recognize that passkeys need to be exportable and transferable, which gives me a lot of hope for the future. I would also say that my preferred passkey manager is open source, which is part of why I built my own, but I do not mind at all people who want to use 1Password instead.
I've been working on passkeys for almost a year now, and I wanted to share my thoughts on how this part of the industry is going and what I think needs to happen next. Thanks for reading!
Also requires sites and services actually accept another -- or weaker -- device/secret as a backup.
IMO Passkeys are dead unless both services and device makers can automate adding another device easily, securely, and for all active services at once. Otherwise their benefits are too small and costs too large to justify broad and indefinite support.
Account recovery is usually the weakest point of any system (e.g. social engineering calling support to reset account access)
I don't have the answer to this, but a single key locked into one device is definitely a strategy for disaster (or doesn't offer much additional security when still paired with passwords)
https://pages.nist.gov/sp800-63a.html
Let’s assume crypto proofing is insufficient (because people lose their cryptographic primitives, secure authenticators, and recovery codes), and US digital identity is still playing catch-up to the developed world (I assume one day login.gov, the USPS, and other trust anchors will be able to attest to who you are). Therefore, having a commercial identity proofing provider providing account recovery seems like the optimal solution.
(management of customer digital identity is a component of my work at a fintech)
Have a couple devices. Your phone, security key, etc and use at least 2 for every service you use.
And if one needs a backup device then one must also register both with every new service.
Doesn't autofill by a password manager already achieve this? It will not autofill on a fishing domain