Discussion
Loading...

Post

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
tante
@tante@tldr.nettime.org  ·  activity timestamp 2 weeks ago

So I think I'll need to read up on it a bit. I understand that "Passkeys" try to do something similar as SSH pubkeys.
But do you know a good technical explainer of what's going on and how it works?

(Yes, I could search myself but I am looking for recommendations of articles you have read that you found helpful and clear.)

EDIT: https://passkeys.io did make some things clearer.

  • Copy link
  • Flag this post
  • Block
Dan
@dan@social.coop replied  ·  activity timestamp last week

@tante an addendum to the enshittification that has taken place with passkeys from someone with first-hand knowledge: https://fy.blackhats.net.au/blog/2024-04-26-passkeys-a-shattered-dream/

Firstyear's blog-a-log

Firstyear's blog
  • Copy link
  • Flag this comment
  • Block
blackstream #RIPNatenom
@blackstream@mastodontech.de replied  ·  activity timestamp 2 weeks ago

@tante however, the compatibility chart (https://www.passkeys.io/compatible-devices) makes me doubt the „usable anywhere“ claim

Passkeys: Device and Browser Compatibility

Find out Which Devices and Browsers Support Passkeys and What May Still Be Missing. Can Your Device Create and Use Passkeys?
  • Copy link
  • Flag this comment
  • Block
Karl Voit :emacs: :orgmode:
@publicvoit@graz.social replied  ·  activity timestamp 2 weeks ago

@tante Ich habe auf https://karl-voit.at/FIDO2-vs-Passkeys/ zu #Passkeys und #FIDO2 gebloggt und u.a. auch erklärt, weshalb Passkeys in immer mehr Situationen leider nicht mehr gänzlich gegen #Phishing schützen, FIDO2 meiner Meinung nach aber sehr wohl.

D.h. die Hardware-Tokens liefern aktuell den einzig wasserdichten Schutz gegen Phishing. Trotzdem haben Passkeys viele Vorteile gegenüber den üblichen Methoden wie #TOTP, #TAN via #SMS oder #Email, ...

#publicvoit

Authentifizierung mit FIDO2 und Passkeys

  • Copy link
  • Flag this comment
  • Block
xeophin
@xeophin@swiss.social replied  ·  activity timestamp 2 weeks ago

@tante I may have written about it (from a user perspective, though, not very technical): Abschied vom Passwort: wie man sich in Zukunft einloggen wird https://www.nzz.ch/technologie/abschied-vom-passwort-wie-man-sich-in-zukunft-einloggen-wird-ld.1701475?gift=34OENPvY

  • Copy link
  • Flag this comment
  • Block
CryptGoat
@cryptgoat@fedifreu.de replied  ·  activity timestamp 2 weeks ago

@tante The major problem with passkeys is that Google, Apple and Microsoft abuse(d) them as a method to enforce a vendor lock-in: "Here, have this nice convenient feature as long as you stick with our accounts and devices." Now, it looks like we will be able to export passkeys from their accounts but passkey management needs to become convenient for everyone to make them an attractive alternative.

And we still lack truly free options to manage them across all devices. #Bitwarden / #Vaultwarden can do it but there is no point in using KeePass if not all platforms have at least one #KeePass client supporting passkeys.

Kind of reminds me of PGP keys, which are still a pain in the ass to manage across multiple devices, even after all these years.

  • Copy link
  • Flag this comment
  • Block
Chris
@cy@chaos.social replied  ·  activity timestamp 2 weeks ago

@tante ich hab das hier mal versucht mit bildchen zu erklären:
https://media.ccc.de/v/gpn22-303-passkeys-login-ohne-passwort-#t=1434

  • Copy link
  • Flag this comment
  • Block
Wilfried Klaebe
@wonka@chaos.social replied  ·  activity timestamp 2 weeks ago

@tante But how to transfer them to a different device? For backup purposes, or just to not need to use the phone when at the desktop? I don't see anything about that there.

  • Copy link
  • Flag this comment
  • Block
tante
@tante@tldr.nettime.org replied  ·  activity timestamp 2 weeks ago

@wonka I think that largely depends on the provider you use. like if you store them in bitwarden/vaultwarden, they should sync but if your browser/OS pushes them into the TPM layer on your device that's obviously harder.

  • Copy link
  • Flag this comment
  • Block
Claudius
@claudius@darmstadt.social replied  ·  activity timestamp 2 weeks ago

@tante @wonka KeePassXC and its browser extension have Passkey support. Mobile App support is still not universal, though.

With KeePassXC, you have all your passwords in a regular boring old file (encrypted, of course) and it's very easy to avoid getting locked into one of the shiny proprietary cages.

  • Copy link
  • Flag this comment
  • Block
Konstantin Weddige
@weddige@gruene.social replied  ·  activity timestamp 2 weeks ago

@tante @wonka bitwarden/vaultwarden can handle that, but you generally shouldn't need to. Create a backup Passkey instead of backing up the Passkey. You can have more than one.

Passkeys aren't a 1:1 replacement for passwords. They link your established trusted environment with your account. If that trusted environment stretches over multiple devices (vaultwarden, your iCloud or whatever), great. But if not, don't compromise that security by moving the passkey around.

  • Copy link
  • Flag this comment
  • Block
Oliver Pfleiderer
@LinHead@d-64.social replied  ·  activity timestamp 2 weeks ago

@tante @wonka I am so glad people more into tech than I am have the same questions...

  • Copy link
  • Flag this comment
  • Block
Emelia 👸🏻
@thisismissem@hachyderm.io replied  ·  activity timestamp 2 weeks ago

@tante maybe https://www.passkeys.io ?

  • Copy link
  • Flag this comment
  • Block
tante
@tante@tldr.nettime.org replied  ·  activity timestamp 2 weeks ago

@thisismissem thank you!

  • Copy link
  • Flag this comment
  • Block
Wilfried Klaebe
@wonka@chaos.social replied  ·  activity timestamp 2 weeks ago

@antijingoist From what I gather about passkeys, that's not "passkeys done right" then.

One absolutely MUST be able to have a backup passkey / trusted environment. Smartphones do get unavailable (defective, lost, robbed, ...), only being able to have one is a hard fail.

@weddige @tante

  • Copy link
  • Flag this comment
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.0-rc.3.21 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login