Remix.run Logo
mschuster91 3 hours ago

> And honestly, nowadays, if tech companies are pushing really hard for something then that is an immediate red flag for me and it bears more scrutiny.

The reason is the ever increasing number of hijacks of social media presences and code hosting portals, with the latter being a serious financial threat. Done right, passkeys stay in the Secure Enclave, at least for anything Apple and most of the Android sphere. There is no reasonable way to obtain login credentials for accounts protected by passkeys without physical access to the user's device(s).

zamadatix 3 hours ago | parent | next [-]

The doubt is more "how will tech companies use passkeys as an excuse to do something stupid" than "passkeys themselves must have inherent problems because tech companies are pushing them".

Passkeys could be the savior of all security problems worldwide from a capability point of view and tech companies would still ruin it by trying to force ways it pushes you into their ecosystem instead of just being whats both secure and convenient.

As an example, I have 3 different passkey _APPS_ on my phone and cannot go down to one because of various reasons with each (such as MS authenticator, forced for integrating to Microsoft at work).

iso1631 3 hours ago | parent | prev [-]

> There is no reasonable way to obtain login credentials for accounts protected by passkeys without physical access to the user's device(s).

Click "I lost my device", enter contact, get a reset link via email/sms

terminalbraid 3 hours ago | parent | next [-]

Email and SMS are not reasonable and both have an extraordinary number of flaws.

jmbwell 3 hours ago | parent | next [-]

So use the recovery codes. Or scan the QR code and auth from another device

I’d buy that there are too many different confusing ways to recover from this situation, but not that it’s impossible

Barbing 2 hours ago | parent [-]

>use the recovery codes.

Fun fact: Google can decide to reject these. Lose access to the original device, try to rely on recovery codes to login with known current password on family member’s device… nope!

iso1631 2 hours ago | parent | prev [-]

Sure, yet in the real world those are the acceptable means if you want your customer to continue to pay you when they've lost their phone.

3 hours ago | parent | prev [-]
[deleted]