A second Yubikey in a safe is a lower cost option than a second passkey compatible device...
What is the recovery process and what prevents it from being gamed itself?
But I bet those scenarios you've posited apply equally to the devices with your passkeys on em, right? I'm confident enough that between the one on my keyring in my pocket and the one in my lockbox at home, if I've somehow lost access to _both_ of those I've got more problems in my life than my gmail/github/whatever logins.
And the recovery process and gaming thereof questions apply equally to the passkey protected accounts as well, no?
Particularly if they only have one device (a phone), and they lose it.
A passkey only authenticates a device (or group of devices). All passkey providers must provide secondary methods for validating the identity of their users so that additional passkeys can be issued when a device is lost.
But if that secondary validation is garbage then the passkey is also garbage, but that problem is not unique to passkeys. (Strong passwords have the same problem, they're only as strong as the reset mechanism).
Browser generated strong passwords with auto fill exists today, pretty much solves all security concerns, and doesn't have the same pitfalls.
Great, all day I dream of making someone else's job easier by adding hassles to my life.
What's next from the "security experts", booby-trapping front door entrances to deter thieves?
Oh, I have another idea. Let's restrict the number of accounts people can have to, like, two, so that they don't have to struggle with remembering passwords! From the perspective of IT helpdesk, it's a feature and a requirement.
Wasn't the whole point of passkeys over FIDO2 keys the fact that you can have the same secrets stored on more than one device? (thus mitigating the largest pitfall of FIDO2 keys -- losing the physical key)
In this way the promise of passkeys, and the main marketing message around passkeys, is that they are phishing-resistant. This isn't strictly true though, because within some of these syncable ecosystems you can share a passkey. For example I can AirDrop a Cloudflare passkey to someone else's iPhone. If they accept, they can now authenticate as me.
The core intentions of FIDO2 generally and passkeys specifically is sound, but solving the age-old problems of device loss, resets, impersonation, sharing, etc, are human issues that the tech companies and consortiums still can't solve. In this way I would argue that passkeys are an improvement but are oversold. They are still better than passwords for many use cases though. And IMHO should remain optional.
So, it is not true.
However, what's true is that if you're arrested, the police won't have to ask Google/Apple/anyone to give them access to your accounts.
They'll just hold the phone to your face, and get a convenient list of all your accounts and a means to log into them.
Granted, you'd need to have biometrics involved. But you can be simply asked to unlock the phone, if that's FSB doing the asking, you won't say "no".
> They'll just hold the phone to your face, and get a convenient list of all your accounts and a means to log into them.
As with any password manager installed on your phone. Passkeys don’t claim to solve and are not intended to solve that particular kind of threat.
Apparently, the FIDO alliance is considering adding an attestation feature that would allow websites to block various passkey implementations:
https://github.com/keepassxreboot/keepassxc/issues/10407#iss...
e.g., they could block ones that allow exports, or they could block ones that are FOSS. To their credit, it looks like Apple's throwing their weight around to prevent such blocking from being technically possible.
The more I hear about this standard, the more concerned I become.
I use AAGUID attestation for Yubikeys at work, but that addresses an actual security need to enforce known authenticator types and prevent enrollment of non-hardware tokens.
Always do threat modeling when talking about security, otherwise you end up just bike shedding.
No joke, I once recovered access to google account by loading a TOTP backup in an app in Android emulator. Otherwise I might have been a bit in trouble.
If I didn’t have my GitHub recovery codes, I would have been in trouble.
Arguably, that’s what those are for. But the key point is that I did a mundane, routine transaction. My house didn’t catch fire, my phone wasn’t stolen, I didn’t act negligently. But I was potentially this ][ close to disaster.
If device loss (or a google/apple account ban) leads to permanent loss of access to your (other) accounts, then passkeys aren't providing availability, so they're not secure.
Put another way: If you ignore availability, then passwords are even more secure than passkeys when used "correctly":
When creating a new account, choose a random 80 digit string for your password and don't record it anywhere. Also, don't set up an account recovery email address / phone number / etc.
Have you considered the case of "the wrong person" taking the device from you non-accidentally?
I'm glad that you live in a world where you've never had anything stolen (..or confiscated by officials).
What a wonderful feature: give anyone who can snatch/break my phone an easy way to lock me out of all my accounts. Especially useful when traveling.
Not to mention the absolutely-never-happening scenarios like, um, dropping the phone. Should've backed up you keys!
(Apple will gladly restore them for you from the cloud once you purchase a new iPhone)
Oh wait, never mind: "The inability to move them is a feature, not a bug."
>All passkey providers must provide secondary methods for validating the identity of their users
Like what, getting an OTP on a known device / phone number / email that you no longer have access to?
Who's enforcing that must?
And finally, and please think about it for a moment:
If another means to verify identity MUST be provided, passkeys are not REPLACING anything - so why do we need them?
See 1:10-ish[0] for the demo - I found this at least somewhat surprising, though I submit this as a passkey advocate (for a while, my side business only-supported passkeys, but we backed away from that).
[0]: https://developer.apple.com/videos/play/wwdc2024/10125/?time...
If I were to switch to Linux, I guess it just means that I'd have to go through the forgotten pass(key) flow on every site on first login?
I'll stick to Yubikeys and TOTP 2FA for as long as I can instead of jumping into passkeys.