| ▲ | MBCook an hour ago | ||||||||||||||||||||||||||||||||||
Boy I’m so tired of people trying to make clever attack names. They don’t help remember things, there are too many. So all 3 “pass-ta-key” attacks are not attacks on passkeys, they’re attacks on the Google vault. And if you get access to the vault, then you get everything. OK. And if you get access to a synced traditional password vault, then you get everything. So… meh. These are bugs, they will be fixed. Good on them for disclosing them. But this does not prove that passkeys are terrible. This does not make them less secure than random passwords. If it wasn’t for the fact that they just happen to be getting passkeys, seems like this wouldn’t be worth a headline or discussing at all. And if they have this level of access, then they also get all the standard password credentials in the vault too, right? | |||||||||||||||||||||||||||||||||||
| ▲ | nixpulvis an hour ago | parent | next [-] | ||||||||||||||||||||||||||||||||||
Have we standardized a way to backup and export passkeys yet? Do websites commonly allow multiple passkeys to be registered? | |||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||
| ▲ | tamimio 7 minutes ago | parent | prev [-] | ||||||||||||||||||||||||||||||||||
> And if you get access to the vault, then you get everything. OK. And if you get access to a synced traditional password vault, then you get everything. No? It’s why 2FA exists. I have an email with password of 5 characters only and the password leaked decade ago, never changed it and no one accessed it because it has 2fa. I can share my whole password vault and I would not care about it because it’s useless without 2fa. Not the case with passkey, glad I never set it up on any of my accounts, pass+mfa is good for 99% of accounts (not sms obviously), rest are public private keys. | |||||||||||||||||||||||||||||||||||