A couple thoughts on your post of the attached article about Passkey failures.
- At the very end of the article, carefully hidden behind a double negative, is the statement that these attacks all indicate that passes are working.
- The article is written by a company selling biometric security.
- All of those attacks involve attacking the infrastructure outside of the past Key in order to bypass or simulate it. Woth the possible exception of the share device attacks... which I assume a corporate entity would not enable, they all involve first compromising the users computer. That is not the case for passwords. So this is a huge step forward.
It took me a while to commit to passkeys. And I didn't do it until they were shared between devices. Which yes, definitely does open up a potential attack vector, but it's one that was, like all the others, also available when attacking passwords. I have found them hugely useful, and hugely simple. They were a little tricky at first. But also, the user interfaces have improved greatly since then.
Among other things, I love the fact that, although I have multiple Google accounts, the passkey knows which one I'm logging into. The chances of my sending the wrong password to the wrong site are now zero.