Comment on Passkeys Explained: The End of Passwords

<- View Parent
lmmarsano@lemmynsfw.com ⁨1⁩ ⁨day⁩ ago

If they can intercept my password despite TLS, they can probably also steal my session.

Security is all about layers & reducing risk/surface area of attack. Anyhow, that’s not necessarily true: it could leak due to flaw or defect that doesn’t affect the session token. By getting your secret, they can leak it. Leaking a secret they don’t have, however, is impossible.

I’m going to disagree that passkeys really have multifactor authentication built in.

Then you’re disagreeing with standards & definitions. Passkeys are encrypted in an authenticator that needs a biometric or secret (ie, something you are or know) to unlock the key (something you have).

Authenticator is a multi-factor cryptographic authenticator that uses public-key cryptography to sign an authentication assertion targeted at the WebAuthn Relying Party. Assuming the authenticator uses either a facial recognition, fingerprint or PIN for user verification, the authenticator itself is something you have while the facial recognition and fingerprint (biometric) are something you are and the PIN is something you know.

my one attempt to use it

While it’s fine to share, “I tried something once, it sucked” is not a great argument to draw a generalization that technology sucks or isn’t better than your limited impression. Maybe piefed sucks: if piefed implemented password authentication wrong, would you blame password authentication?

source
Sort:hotnewtop