That, to me, is less secure.
That, to me, is less secure.
Yes, that's the common rebuttal. It's resistant to MITM and phishing, but it's still not two-factor.
If you store your passkey on a yubikey with PIN, I suppose it's two-factor in the sense that you need the key and a PIN, but you can only store so many passkeys that way.
Is it just that more is better?
Traditional server-side 2FA (e.g., "give me a password and a 1-time code") is superfluous in a passkey world, because it's ultimately just a hack to make up for the fact that password-only auth is weak. Key auth is incredibly strong, so a server-side 2FA challenge doesn't buy you much.
Put all of your passkeys in a single repo (as most people will), and you're literally putting all of your eggs in a single basket. Better hope nobody gets ahold of that basket.
And if people are generating good passwords and storing them anyway- we may as well store digital keys instead.
My password manager is still protected by a good password + 2FA. Passkeys will be protected by this as well. On my phone there is biometric that can replace the password as well.
How secure your passkeys are comes down to how protect them. But it’s definitely an improvement over passwords.
1. Open source implementations will be indistinguishable to a 3rd party from the big tech versions (so that services can't refuse to authenticate devices that haven't been locked down), and
2. The private key can be extracted from the device by the user and backed up.
If it can be extracted, it can be stolen. Better to stick your secret material in a HSM that takes the key with it when it dies.
So yeah...your second factor is an actual second factor.
I completely get the argument that passkeys are an improvement for most people. But if you're already using password + pw manager + 2FA, it seems to me that you're a good bit more secure than a passkey alone.
That "usually" may exclude the two implementations that most people will use (but I doubt it), but it's a quite standard feature.
The remote server only sees the result of the "do you have the correct private key?" challenge, not the biometric/PIN/password unlocking the private key that happens locally.