RE: https://mastodon.social/@monkeydom/117382425456803989
100% true. “Automatic passkey upgrades” is a feature of WebAuthn that allows for websites and apps to turn around and add a passkey to your saved account in a password manager right after you sign in with your password, assisted by that password manager.
Apple Passwords allows these upgrades by default (and tells users when it happens!) and I strongly believe it’s the right default. Why?
Passkeys make signing into accounts faster than passwords + traditional, phishable 2FA. If the user is already using the Passwords app for their password for an account, they’ve asked for the software to help them have a secure and smooth experience. Once someone has a passkey and starts using it in place of their password, one day, a website can start retiring passwords for users who are comfortable with that, which will finally deliver the phishing-resistance benefits of passkeys to accounts themselves.
Do not underestimate how many people are hurt by phishing every day. You might think that you’re safe, but nobody is truly safe from phishing until phishable sign-in and recovery mechanisms are removed from an account. **This might not be achievable or desirable for some people**, but people who use the computers and the internet should have a path to secure accounts.
I discuss this and more in this talk I gave: https://www.youtube.com/watch?v=yVadD-Lfrfk
@rmondello @monkeydom Although I agree with the benefits, I think consent should carry more weight.
I fully trust passkeys now that I understand them. But if an unfamiliar technology “upgraded” me automatically, without asking, I'd be concerned and upset, especially for something as sensitive as authentication.