| ▲ | bennetthilberg 3 hours ago | |||||||||||||||||||||||||||||||||||||||||||
> Passkeys are grotesquely insecure. Lockout is a real risk, but there is nothing insecure about passkeys. Private keys stored on the secure enclave + biometrics or passcode before any signature is produced + origin binding mogs a static string and a 6-digit TOTP (often generated with a secret key outside the secure enclave) that can be phished and entered from anywhere. Also, in many (possibly the majority) of scenarios where someone is locked out of their passkeys, they’d also be locked out of TOTPs and passwords. > The only possible way to consider them more secure is if phishing attacks were more common and more damaging than lockout You’d be surprised. | ||||||||||||||||||||||||||||||||||||||||||||
| ▲ | rcxdude an hour ago | parent | next [-] | |||||||||||||||||||||||||||||||||||||||||||
Security as a field would be a lot less obnoxious if it did not neglect availability as an important facet of security. A 'security' system that obstructs legitimate access is also failing at its job. | ||||||||||||||||||||||||||||||||||||||||||||
| ▲ | torstenvl 3 hours ago | parent | prev [-] | |||||||||||||||||||||||||||||||||||||||||||
> Lockout is a real risk, but there is nothing insecure about passkeys. secure - adjective se· cure si-ˈkyu̇r -ˈkyər securer; securest 1 a: free from danger b: affording safety (a secure hideaway) c: TRUSTWORTHY, DEPENDABLE (a secure foundation) d: free from risk of loss Passkeys as a sole/required method of authentication increase the risk of permanent loss. In any other configuration they do not mitigate phishing risk. It is not possible to say there is nothing insecure about them. | ||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||