Passkeys Public Beta
github.blog
github.blog
how is this better? you only have 1 factor auth now. earlier you have 2 or even multi-factor.
also, how is passkeys different/better than ssh public key auth? sure with proper infra, why can't we do website auth with your installed keychain than this? that would have the additional benefit of power users already using the same for terminal auth to servers so this would be just another channel
you're right that at its guts it does still rely on an asymmetric key pair. but FIDO passkey implementations are certified and have been built for enterprise and consumer grade use cases.
for macos and iOS, implementations will normally be using your keychain and are providing an easy user experience on top of your keychain
Generically, "passkey" refers to a FIDO2 passkey which is a cryptographic key PLUS (preferably) a biometric prompt or (more weakly) a pin or password. You cannot use your key to sign a challenge without the 2nd factor.
A password protected SSH key is effectively a weak FIDO2 passkey.
> why can't we do website auth with your installed keychain
You can. This is roughly Apple's implementation of FIDO2
So, you instead use a password to unlock the device -- something you know -- rather than giving the website the password, and then offer up a cryptographic proof that you're a specific user -- something you have, much like TOTP works today. WebAuthn keys are also unphishable and don't leak usable information for other websites by design. If you already used a password manager the second one was to some extent true, but no phising is a big one.
It is basically a different take on the same ideas behind SSH key exchange, yes. Though in the case of SSH, you have both the transport (Secure Shell) and the key exchange/authentication system. In theory you could use WebAuthn keys or something to negotiate a Secure Shell transport and replace SSH keys; after all, you can already replace it with certificates, etc. So there's mix-and-match possibilities.
Some systems like 1Password apparently even have support for acting like an SSH Agent and storing your SSH keys, too. I don't use it, it nagged me about it the other day, but this would further consolidate all these separate storage mechanisms into one place.
Basically, the unifying idea here that everyone is converging on that you just use a single password or short-term session (FaceID, etc) to unlock some shared, encrypted vault containing everything else -- and that "everything else" can include randomly generated passwords, cryptographic keys (Passkeys, SSH Keys, etc), other proofs and info (TOTP), etc. that you then offer on demand. So there's a unified UX to all these things.