Skip to main content
October 28, 2023
Question

What am I missing with passkeys?

  • October 28, 2023
  • 12 replies
  • 1362 views

I am finally getting around to putting passkeys into action.. but something isn't adding up.

As a low risk test, I added a passkey to a bestbuy account. Started up an incognito session, and logged back in with my PASSWORD. Uhhh...?

Soooooo - passkeys are great (who doesn't like public key cryptography?!).. but if you can continue to log in with a password (didn't see a way to disable it), then what good are passkeys?

Shouldn't it be a password OR passkey - but not both? Or, at a minimum, the ability to disable the password? What am I missing? Do most passkey enabled sites allow the password fallback?

Thanks!


1Password Version: Not Provided
Extension Version: Not Provided
OS Version: Not Provided
Browser: Not Provided

12 replies

November 10, 2023

@jonpw I will slightly (and only slightly) disagree there. I am making some assumptions here (because I think the idea is to combine PIN or biometrics with the passkey), but if Yubikey is the sole method of unlocking whatever account you want to access, then someone stealing the physical possession of it would potentially introduce a slightly elevated risk -- again I am making assumptions here as this would be somewhat targeted. My post of course also assumes that there is a separate method of authentication other than the same Yubikey to access the password (e.g. 1Password) in the first place.

November 10, 2023

@XIII said: Actually passkeys can still be 2FA, if the RP (relying party) requires User Verification (biometric or PIN)

That type of second factor is great and I'm all for it, but it's just a question of semantics -- that second factor is simply some additional protection on the private key so that it can't be easily reused like a lost house key found lying on the ground. It's not the same as the legacy password system where the "something you know" part has no connection to the "something you have" part.

My point is still the same: using something like 1password with high entropy site passwords, a high entropy One Password, and traditional 2FA is great, and (IMO) equally secure as passkeys. But it's no more secure, and suffers from the flaw that it can easily be less secure.

@lodaka The problem is that using 1password plus yubikey is no longer "something you know + something you have", it's two "something you haves" since 1password is "something you have". So at that point we're just talking about redudancy, which is a burden on most people and comes with its own flaws. (Like easily being able to lock yourself out.) But sure, if FIDO wants to add formal, optional support for requiring two separate passkeys to log into a site, so that a user would require two "something you haves" like the double-keyed missile launcher in War Games, then maybe that will become a thing one day.