If the password manager is unlocked, I get logged in automatically anyways.
If the password manager is unlocked, I get logged in automatically anyways.
With a password manager storing passkeys, your private passkey is not transmitted as part of the website request. It can't be intercepted or accidentally/negligently stored in plaintext in a database or server logs.
You still have to trust the secure syncing of your passkeys, just like you do with passwords, but there are still fewer threat vectors than with passwords.
2. Passkeys can't be to short, in contrast to passwords
Passkeys essentially remove almost all risks for websites and moves them to the user (lost passkey, attacks on their password managers). It is not perfect, but it removes a lot of problems that we have right now (like more than a billion leaked passwords in the wild)
And it does provide some benefits: phishing protection (no shared secret that can be intercepted or given to the wrong party) and the service does not need to store as much sensitive information (don't need password hashes that could be leaked and cracked, just a public key).
The main difference I see with passkeys from a usability standpoint is that Firefox doesn't have built-in support for a software implementation, making them literally unusable for me.
For example 1Password can be used for passkeys in Firefox.
No ability to export your credentials.*
Device attestation to allow blocking "undesirable" devices from authenticating and lock in purposes.
*keypass was working on an export feature and there were already threats to use the attestation club to ban them from the landscape for not falling in line
https://github.com/keepassxreboot/keepassxc/issues/10407#iss...
That attack on KeepassXC is despicable.
They can: 1. Impersonate you, gaining access to anything your keys unlock 1.a. Impersonate you, claiming to be you in a violation of “key use enables non-repudiation” 2. Deny you the ability to use your keys 2.a. Change any of your keys, locking you out of things 3. Deny you the ability to transfer your keys to anyone they “don’t like” 3. Provide your keys to anyone else, e.g. “with a court order” 3.a. Anyone “benefitting” under (3) can then do (1(a)) …and surely more Bad Things.
Every single time “passkeys” seems to like “okay, maybe”… some fucktards pull another one of these.
Then I go, “okay, ssh keys, PIV, or whatever else is Just Fine, and these people who are either state agents, idiots, or power hungry idiots working to advance total control over humans with lack of freedom and no way back can go die, or as an alternative be sentenced to serious computer-things-reeducation”. …and I kinda mean it. There are certain things you just don’t come back from, as a society, etc. and I just won’t support it. You only get one chance not to.
timcappalli from FIDO Alliance mentioned in that above thread that plain text exports shouldn't be allowed, and that password managers/providers should be blocked if they implement plain text export.
Since that thread, there's a new spec that allows users to securely migrate passkeys from one provider to another, but no way to export to plain text (for debug purposes, or if there's a bug in the export/import and you need to troubleshoot, etc).
For me, threatening to block providers for implementing a feature that I desire is a great way for me to lose all interest in passkeys completely. I don't trust FIDO Alliance to make the right call nor do I trust big tech companies to produce bug-free software.
A passkey doesn't transmit your actual, full, repeatable credential over the wire. It's a challenge-response protocol, so only that one authenticated session would be intercepted. Kill all questionable sessions and you're good, they're not reusing it.
are impossible to enforce. If you present users with password field, a sizable percentage of them will just manually type in the same weak, compromised password that they've used on every other site they've ever created an account on in their life. Passkeys are much harder to misuse. That's where 99% of their value is.
Yes there are also other advantages, like the fact that passkeys use public key cryptography, but those are tiny compared to the human factors improvements.
Just like passwords. What is the difference ?
> Passkeys can't be to short, in contrast to passwords
So a "long password" is a "passkey" ?
> Just like passwords. What is the difference ?
>> Passkeys can't be to short, in contrast to passwords
> So a "long password" is a "passkey" ?
Of course not.
Passkeys are effectively just key pairs defined by a FIDO standard. It’s much more productive to think of passkeys as mutual certificate authentication designed for use by the masses.
If you’ve ever used a Yubikey for primary authentication, you’ve already used a passkey.
That’s why the mainstream implementations are synced. Or why you have an extra Yubikey.
Not really relevant for password manager users.
> 2. Passkeys can't be to short, in contrast to passwords
Not really relevant for password manager users.
Echoed in his ears.
From that perspective it just makes the UX slightly smoother and makes it impossible for the site to screw up and leak your plaintext creds. Other than that yeah there's not a big difference compared to using an autofilled, unique, randomly generated password. Which is good, because eventually sites are going to start phasing out that latter option for the exact reasons I outlined in my previous comment.
The thing about good design is that it makes it impossible to "hold it wrong".
That's a big "if".