Forum Discussion
Two yubikey 5ci - advice appreciated
I upgraded to 8…transferred my info from 7 to 8 and everything seemed ok with transfer so I deleted 7. Now when I try to use for logging in to sites it the password info is still linked to 7 and I can’t reinstall it…how do I get the app to recognize 8 now?
Thanks for the reply. Unlike passwords, you can’t create a weak passkey. Passkeys are generated by 1Password using a public-private key pair, which makes them strong and unique by default. Passkeys can’t be phished like a traditional password because the underlying private key never leaves 1Password – this also makes them resistant to social engineering scams.
Some websites will allow you to remove the username/password entirely but others require that you keep both options. Part of the reason why many services leave passwords as a fallback option is because, for their website and apps, passkeys may not be supported across all devices and platforms yet. Even if you can't remove your old password then you still get the benefit of increased protection from phishing every time that you use your passkey to sign into a website or app.
If you do keep your passwords alongside your passkeys for certain websites, make sure that all of your passwords are strong and unique: Use the password generator to change and strengthen your passwords
Let me know if you have any questions. 🙂
-Dave
- passwordnerd2 years agoNew Contributor
Thanks for the feedback. That was helpful for me because now I know I'm not crazy. I'll keep an eye on that, and I'll try disabling 2FA. On the other hand: As long as it is also possible to log in via user/password, don't I create another vulnerability? Why does it all have to be so exhausting?
Hi there passwordnerd
You're right that some websites, like PayPal, have implemented passkeys in different ways from others. On mobile, 1Password can auto-copy a one-time password to the clipboard after it autofills a username and password for a website, but since using a passkey works differently, 1Password isn't informed that this has taken place, and so it can't auto-copy a one-time password in the same way.
As you've found, you may well be able to choose to turn two-factor authentication off for a website or app that uses passkeys (if they allow that), and this will definitely grease the wheels in getting you signed in – a bonus if it's an app you might use a lot, like PayPal.
I hope that answers your question fully, but please do let me know if I can be of any further help. :)
— Grey