Elektrine lite

← Feed

@firstyear@infosec.exchange

Post #2567773

2025-12-17 23:48 UTC

@emdash@defcon.social The post is written from a view of "consumers". When you have a more controlled system like you do, then a lot of the risks go away because you can control a lot more about the devices involved and the flows. So my advice is 1) Passkeys aren't a "factor" they are a full self-contained MFA authenticator. So you have to put a lot of trust into those devices 2) Yubikeys are the only security keys worth buying, and they are far ahead of anything else security wise. They are worth the investment for high profile accounts. Ensure you have attestation enabled to prevent non-yubikeys being enrolled.

Replies (1)

  • @emdash@defcon.social 2025-12-18 04:17

    @firstyear@infosec.exchange Thanks for the response! We've got more control for some populations, but not all—we're a research university and affiliated health system (total FTE ~30,000, and more than that many again for our students). Staff: well controlled (at least on work-issued hardware), faculty: it's a coin-flip, students: no chance. Agreed on the both pieces of advice (and apologies for the sloppy use of terminology re: factor). When I said "optional factor" I should have just said "option", i.e. "something our users can use, period". The beauty of passkeys, as you said, is that you get a complete MFA flow in a single authenticator. I'd love to simplify the login flow (for those who opt-in) to Passkeys: use it, and you're in. Trusting the authenticator in such a heterogenous environment is the tricky part. Credential managers are a good option, but platform authenticators (or well-designed roaming authenticators like a YubiKey) still seem more trustworthy, at least as I see it.

    Open ##2567774