Elektrine lite

← Feed

@firstyear@infosec.exchange

Post #1444047

2025-12-17 03:22 UTC

I have been avoiding this for a long time, but once again I have written about the state of passkeys - https://fy.blackhats.net.au/blog/2025-12-17-yep-passkeys-still-have-problems/

Replies (9)

  • @Mirppc@mastodon.social 2025-12-17 04:18

    @firstyear@infosec.exchange Good write up. Thanks!

    Open ##2567760

  • @firstyear@infosec.exchange i quarrel with Software engineers don't understand consent the engineers are the vehicle, but not remotely the impetus. furthermore, and more importantly, they absolutely do understand consent. they are actively choosing to undermine it

    Open ##2567761

  • @ireneista@adhd.irenes.space 2025-12-17 06:06

    @firstyear@infosec.exchange yes. well written. for anyone who listens to us: we agree with this piece's observations and core take-aways.

    Open ##2567762

  • @firstyear@infosec.exchange I have steadfastly refused almost all passkeys since your original post. One of the banks I use decided that it was required, so I had to create that one (with 1Password). Amazingly a couple of months later it stopped working, so I removed it and created a new one, which just stopped working last week too. Curiously the bank has restored the option to use a password and TOTP since their original mandate. I will continue to avoid.

    Open ##2567763

  • @vbabka@mastodon.social 2025-12-17 07:35

    @firstyear@infosec.exchange can't wait to see how our long promised new company SSO solution will behave!

    Open ##2567766

  • @emdash@defcon.social 2025-12-17 13:18

    @firstyear@infosec.exchange Fantastic write-up! I’m an IAM lead at a large non-profit and we’ve held-off (to-date) on implementing Passkey support because it feels like the ground is continually shifting while the various platform and browser vendors change their UX from day-to-day. I think the broader questions I still have are 1) Have we reached a point where it’s worth it to roll out support in our IDP (as an optional factor) even with the trade-offs? and 2) For users who need highly secure authenticators for regulatory reasons, where ought we steer them? YubiKeys are great but they’re spendy and I feel like we’d need to roll some management tooling to support enrollment.

    Open ##2567772

  • @iMeddles@mastodon.eddmil.es 2025-12-17 16:14

    @firstyear@infosec.exchange As an absolute passkey fanboy, I... Don't disagree with anything here. The tech is fundamentally a great idea, the *implementations* make me tear my hair out. Today's hate is for LinkedIn, who will let me enroll a passkey (on a yubikey) in Firefox, but then won't let me log in using it (and won't even display the button to try the passkey log in) And on top of that, they don't let you name the passkeys, so I just have 'passkey 1 - Firefox on Linux' and 'passkey 2 - Firefox on Linux', so if I ever lose one of these keys, rotating the correct one is going to be 'fun'.

    Open ##2567775

  • @flyingcakes@flux.snehit.dev 2025-12-18 03:26

    @firstyear@infosec.exchange been using passkeys with vaultwarden since few months and it's still a black box to me

    Open ##2567776

  • @mattcen@aus.social 2026-01-19 21:55

    @firstyear@infosec.exchange just read this excellent write-up! Some of the consent-related discussion reminded me of https://developer.apple.com/videos/play/wwdc2025/279/?time=888, in which Apple describes transparent Passkey upgrades. I see what they're trying to do, and think it *could* be done well to encourage low-friction Passkey adoption, but it's also easy to mess up and opt users into a platform without informed consent.

    Open ##2567777