It’s Cybersecurity Awareness Month! Join our interactive training session, or learn about security and AI from 1Password experts.
Forum Discussion
System
2 years agoSuper Contributor
Confusion about passkeys
This discussion was created from comments split from: Confused About Passkeys.
snoringelephant
2 years agoFrequent Contributor
I can appreciate and agree with the comments and observations by brettn . I struggle with the same types of issues on understanding how to best use the passkey feature of 1Password.
I looked at the instruction page referenced by 1P_Dave and I don't really feel I am any closer to feeling comfortable enough to embark on changing my password management approach to embrace passkeys (currently, I have opted out of 1Password offering to store passkeys due to this feeling).
One thing I struggle with is the fact that 1Password seems to collide with other software on the same device competing to save/use the passkey (either Apple keychain -- or Apple's new Password Manager or Windows Security). The above screenshot provided by brettn looks like some of this competition in action and it ends up making things confusing for the end user.
The cross-platform and cross-device nature of 1Password is the primary reason why I am such a strong proponent of 1Password. It took me a while to figure out how to best use the "One Time Password" (OTP) 2FA feature of 1Password and I love it. Before embracing the OTP feature, I was using a variety of code generator authenticators (Microsoft Authenticator, Google Authenticator, Entrust, etc.) but they were only available on my mobile devices (e.g. iPhone & iPad), so if I was working on my Windows PC and didn't have access to my mobile device, I was screwed.
The ubiquity of 1Password is its biggest strength. My computing world consists of multiple iPhones, iPads, Mac Books, Mac Minis, Microsoft Windows and Linux devices. Not all of these devices have biometrics or facial recognition. So, for example, if I am creating a new account on my Mac Mini and it asks me to create a passkey, I don't have a fingerprint sensor or facial recognition for it to use to create a passkey. Under these circumstances, I have learned that creating a passkey requires the password used to login to the Mac Mini (in lieu of the typical biometrics).
Based on my understanding of the explanations in this thread, this generated passkey is just like any other generated password. Therefore, it doesn't matter where the passkey was generated. It can be generated from any of your devices and the fact that you are saving it in 1Password gives you this cross-platform access to the passkey (because you know how to login to 1Password on different devices).
I suspect that I will eventually become more comfortable with passkeys over time; however, I am still struggling with understanding the 'flow' of creating and using them given the implementation inconsistencies across websites and 'smart' browsers trying to inject their preferred method of saving/accessing these keys.