I am going to be giving some public talks about passkeys in the next few months. What questions do you have about passkeys and what topics do you want covered in me exploring passkeys?
Post
@rmondello if I'm already using a password manager, passkeys are basically an equivalent user experience. Are there reasons to use them anyway?
@rmondello
If you can access an account without a passkey using alternative methods is it not a bit moot as a security layer.
@rmondello if any are developer focused, definitely some kind of best practices guide for making using passkeys to login easier for users.
It’s so confusing to trigger the passkey prompt as a user, and I end up using passkeys less than half the time I could because the site doesn’t make the passkey flow easy to find - the fact that it’s separate at all is part of the frustration.
@rmondello what's a generally-accessible, single-sentence definition of what a passkey is?
(not explaining to the user why it's better, but explaining what it is, so they have a mental model)
@rmondello sometimes my fingers get too dry and TouchID stops recognising me which makes passkeys less joyful.
So my question is can you recommend a good hand cream or moisturiser?
@rmondello For me, the very basic. How is it secured? Is it standard? What are the implementations in free software? Why should I use them instead of TOTP?
how ready are passkeys for post quantum? I know in general asymmetrical crypto is said to be endangered, is it possible to "just" upgrade to post quantum or hybrid algorithms within the current implementations/protocol, or would a larger change be necessary? Or are they "safe" already?
I've seen people go back to passwords that are like 128 chars long since those seem to be safe from quantum, since they aren't used asymmetrically/with a "public key"
@rmondello making passkey UX user friendly. Most of the integrations with webauthn I know of make it hard to tell a) what is (not) happening when things go wrong and b) where the passkey went and sometimes even c) why there is a passkey if the user already had another auth method
@rmondello exports and more in the form: how to keep them alive and accessible when I lose my credentials (eg iCloud access), thus the option to export to another tool is important, but maybe a paper edition as a backup too?
@rmondello How do non-techies know to, and create, backups?