I’m not anti-passkey, but I got caught really off guard by a site automatically creating a passkey for me with zero user input. Imagine if I’d logged in on a shared device and now the device owner gets passwordless access to my eBay account!
@misty *buys up all the famicom disks*
@misty It seems to be an Apple feature. Saw this today: https://mastodon.social/@monkeydom/117382425456803989
@peacegiverman I believe this may be a standard webauthn feature, but I don’t know what browsers implement it. I definitely saw it in Safari.
@misty Yeah, I like the idea of passkeys a *lot*, for specific threat models they're a threat eliminator for entire families of attacks, utterly brilliant.
But their implementation? Hot dogshit, once again by companies trying to trap you into an ecosystem instead of providing something useful.
@misty that’s wild, have never seen this
@philnelson Apparently automatic passkey upgrade is a standard webauthn feature, but I have no idea which browsers support it.
This is I think my biggest problem with the passkey ecosystem. It’s very poorly explained and yet every site is very eager to get me to switch to passkeys without making sure the user knows anything about what’s going on or the implications of any of it.
@misty Yeah I am not anti-passkey (it seems like a good idea, though maybe more useful for industry than average end users) but poorly implemented. I have seen many novice tech users at my library wind up with passkeys b/c it's often harder to go through a login sequence and NOT get a passkey. These are people who are often device-insecure who should really not be getting passkeys w/o fully understanding them. I think more people would happily adopt if you made it a choice, not a coercive move.
@misty feel like the poor explanation extends to a lot of people recommending passkeys, too. or did for a while.
like, at first, it just seemed like the pitch was "let google do it for you instead of using a password". and when I tried to discuss that or see what the actual pitch was, all I heard was "well it's better than insecure passwords". which wasn't particularly compelling when 1) it's google 2) I've been using a password manager for a decade.
@misty I just enquired of the internet what the advantages of a passkey were and before the internet would respond I had to tell two robots that I was not a robot. I get that passkeys cannot be extracted from my device by intruders but anyone using my device can get a free ride the same as with my saved passwords.
And another thing - aren't passkey something setup and controlled by Google?