Post #2567772
2025-12-17 13:18 UTC
@firstyear@infosec.exchange Fantastic write-up! I’m an IAM lead at a large non-profit and we’ve held-off (to-date) on implementing Passkey support because it feels like the ground is continually shifting while the various platform and browser vendors change their UX from day-to-day.
I think the broader questions I still have are 1) Have we reached a point where it’s worth it to roll out support in our IDP (as an optional factor) even with the trade-offs? and 2) For users who need highly secure authenticators for regulatory reasons, where ought we steer them? YubiKeys are great but they’re spendy and I feel like we’d need to roll some management tooling to support enrollment.
Replies (1)
-
@firstyear@infosec.exchange 2025-12-17 23:48
@emdash@defcon.social The post is written from a view of "consumers". When you have a more controlled system like you do, then a lot of the risks go away because you can control a lot more about the devices involved and the flows. So my advice is 1) Passkeys aren't a "factor" they are a full self-contained MFA authenticator. So you have to put a lot of trust into those devices 2) Yubikeys are the only security keys worth buying, and they are far ahead of anything else security wise. They are worth the investment for high profile accounts. Ensure you have attestation enabled to prevent non-yubikeys being enrolled.