RE: https://mastodon.social/@monkeydom/117382425456803989
100% true. “Automatic passkey upgrades” is a feature of WebAuthn that allows for websites and apps to turn around and add a passkey to your saved account in a password manager right after you sign in with your password, assisted by that password manager.
Apple Passwords allows these upgrades by default (and tells users when it happens!) and I strongly believe it’s the right default. Why?
Passkeys make signing into accounts faster than passwords + traditional, phishable 2FA. If the user is already using the Passwords app for their password for an account, they’ve asked for the software to help them have a secure and smooth experience. Once someone has a passkey and starts using it in place of their password, one day, a website can start retiring passwords for users who are comfortable with that, which will finally deliver the phishing-resistance benefits of passkeys to accounts themselves.
Do not underestimate how many people are hurt by phishing every day. You might think that you’re safe, but nobody is truly safe from phishing until phishable sign-in and recovery mechanisms are removed from an account. **This might not be achievable or desirable for some people**, but people who use the computers and the internet should have a path to secure accounts.
I discuss this and more in this talk I gave: https://www.youtube.com/watch?v=yVadD-Lfrfk
@rmondello with login/password, I know exactly what’s going to happens, and… it works in two seconds. With “passkeys” I have no idea what will happen as that term now encompasses a zillion different things.
The whole things is deeply confusing, and I’m very into design/tech.
Changing people’s auth behind their back is NOT respectful or helpful.
I also do tech support for relatives and it’s hard enough without the added complexity of multiple login methods per site, all varying between sites.