Modulo the whole privacy/vendor lockin issue, passkeys are not a terrible alternative to people without 2FA reusing the same basic password on every single website.
However, when you actually rely on it to secure things, it quickly becomes a massive nightmare - made even worse by it being treated as equivalent to password+2FA.
passkeys are significantly more secure than the most widely-used/most popular forms of 2FA, because the most popular forms of 2FA are TOTP and SMS, and both are subject to phishing attacks. A passkey alone is much more secure than the vast majority of password + 2FA combinations.
The only thing stronger than a passkey standing alone is a Security Key, but Security Keys come with a lot of usability downsides that can easily bite the average user, including:
- inconvenience: you have to remember to carry it around with you everywhere (and not lose it!)
- recoverability: you're completely screwed if you lose it and don't have extras that you already previously added to your accounts. (this also means that you need to buy at least two security keys to have a decent recovery story.)
- rotation (have to log in to every single service, one by one, to re-add new key if you change keys)
And if you really want the extra security that a Security Key provides, you can use a Security Key as a passkey.
Blanket statements like this demonstrate a misunderstanding that "security" is just one thing in a single lineal scale.
In reality you have to ask, secure against what? And to answer that meaningfully you need to a thorough threat model for the specific use case of person P and account A.
The same person P will have a different threat model for every account they have.
The D in STRIDE is for denial of service. Passkeys are much worse on this axis than any other solution. You need to evaluate for the specific combination (P,A) how much this matters vs. other criteria.
Here's the full context again:
passkeys are significantly more secure than the most widely-used/most popular forms of 2FA, because the most popular forms of 2FA are TOTP and SMS, and both are subject to phishing attacks.
>The D in STRIDE is for denial of service. Passkeys are much worse on this axis than any other solution. You need to evaluate for the specific combination (P,A) how much this matters vs. other criteria.
How are passkeys (really, WebAuthn credentials in general) any worse in terms of denial-of-service attacks than passwords?
I think you're trying to make a point about specific passkey/password managers, rather than the actual credentials themselves. Is that accurate?
He says it's "easy to find" but apaprently he can't find it. https://mastodon.laurenweinstein.org/@lauren/111211489395997...
Why is "weak device password" a reason to avoid passkeys, when those users presumably have weak service passwords as well?
But that argument doesn't address how passkeys somehow make that worse.
Sure, if you don't want your valuable stuff stolen, don't put it on your phone. But that's a problem whether you use passkeys or passwords or passwordless links sent to your email or SMS.
For Google in particular, password/passkey isn't a binary choice(currently). You can fall back to the password sign-in flow if your device doesn't have a passkey.
To compare the risks and benefits, we need to know how often people actually re-use passwords, use 2FA, rely solely on their phone screen lock for access to all their accounts, use biometrics, need account recovery, and so on. That data is the only way to settle the debate (and would allow each person can settle it for themselves, perhaps differently based on their circumstances).
Google has most of this data. They should publish it to back up their claims.
The passkeys design, though, has a number of obvious deficiencies and limitations. It is drastically better than ye olde <input type="password" /> but it's not a good standard.
The other alternative is SRP, but no browser vendor had bothered to do anything about this, so it remains a curiosity implemented on a couple websites (with all JS crypto gotchas, so - no good).