So is the idea there that that basically goes away with passkeys, and that your only "thing-you-know" protection is the x-digit passcode you punch into your phone?
So is the idea there that that basically goes away with passkeys, and that your only "thing-you-know" protection is the x-digit passcode you punch into your phone?
Technically, those are "things you are", not "things you have". A Yubikey would be an example of a "thing you have".
I think the ideal is that you're supposed to use a hardware key that uses a biometric like a fingerprint to unlock it. Then the passkey itself is the "thing you know", the hardware key is the "thing you have", and the fingerprint is the "thing you are".
But in practice, that's pretty onerous, so the passkey implementation being discussed eases up on those requirements a bit.
But, honestly, this is a point of little importance. Almost all of the "something you..." categories are only a rough guide, and most items can arguably fall into more than one of them.
So whenever people authenticate using a FIDO2 key as their passkey, they also need to enter its password.
The benefit of passkeys are:
- the Webapps only store a specific public key instead of a hashed password
- a direct connection is necessary for the challenge/response flow so that phishing attacks or MITM are impossible (AFAIK)
- with macbook fingerprint sensor: something you have (private key on your device) and something you are (fingerprint)
- with yubikey without fingerprint: something you know (passcode, hopefully required) and something you have (private key on yubikey)
- with yubikey with fingerprint sensor: something you are (fingerprint, falling back to passcode which is something you know) and something you have (private key on yubikey)