←back to thread

225 points Terretta | 1 comments | | HN request time: 0.211s | source
Show context
solarkraft ◴[] No.41860069[source]
I had hope for passkeys, with all the interop-promises.

It turned out that no (mainstream) passkey provider allows backups however, making them infinitely worse than just using passwords.

Maybe this will help, but fuck me, it’s all complicated, especially for a damn foundational security mechanism!

It could be so simple, just look at SSH keys, which I think largely use the same principle.

replies(5): >>41860481 #>>41863668 #>>41864115 #>>41864718 #>>41866900 #
skybrian ◴[] No.41860481[source]
You can create backup keys by creating more passkeys.
replies(2): >>41862445 #>>41871701 #
lelandbatey ◴[] No.41862445[source]
That's not a backup, that's just another secret. If I can't record the secret onto paper that I can put in a safe deposit box at a bank (or several), then it ain't backed up.
replies(2): >>41862467 #>>41862675 #
dixie_land ◴[] No.41862467[source]
I understand the semantic difference but wouldn't you be able to say add a "backup" Yubikey and lock it in a safe?
replies(3): >>41862523 #>>41864017 #>>41867699 #
eikenberry ◴[] No.41864017[source]
No. How do you use it if it's in a safe? The only way this works is if you use the yubikey to log into google or some other auth provider and then use that auth provider for everything. But you are even worse off then as that auth provider now is a single point of failure... get that account revoked for any reason and you've lost access everywhere.
replies(1): >>41865485 #
skybrian ◴[] No.41865485[source]
Why do that, though?

Figure out which doors you need to unlock and make sure you have at least two independent ways to get through each door. Some doors support Yubikey, so that counts as one, for those doors.

replies(2): >>41866763 #>>41867701 #
1. lxgr ◴[] No.41867701[source]
My doors don’t change every other week. My set of passkeys does.