Elektrine lite

← Feed

@ErikvanStraten@todon.nl

Post #2595469

2026-05-10 19:52 UTC

@rmondello@hachyderm.io : what makes passkeys strong: 1. Software checks the domain name, which makes phishing hard; 2. Https is enforced, which helps prevent AitM attacks (unless Cloudflare et al. come into play); 3. A unique, long, unguessible, randomly generated "password" (public key) per account: dumb password rules and broken human RNG's no longer apply. The rest is marketing (including the -hyped- asymmetric cryptography). The "advantage" of denying the owner access to their own private keys hardly makes sense as long as session cookies are not device-bound. The disadvantage of not being able to back up ones own private keys is the risk of vendor lock-in and the underestimated huge risk of account lockout [1]. And the latter leads to the necessity of being able to log in using weak authentication after the user loses access to their private keys. @brandonbutler@mastodon.social [1] https://seclists.org/fulldisclosure/2024/Feb/15 #Passkeys #Phishing #PhishingResistant #AsymmetricCryptography #AndroidPasskeys #androidPasskeysGone #iOSpasskeys #iPadOSpasskeys #ApplePasskeys #BackUp #Export #BackUpPasskeys #ExportPassKeys #PasskeyBackUps #PasskeyExports

Replies (1)

  • @jtb@toot.wales 2026-05-10 20:03

    @ErikvanStraten@todon.nl @rmondello@hachyderm.io @brandonbutler@mastodon.social That's a very old article, Feb 2024.#Passkeys secret keys can be stored and backed up from #bitwarden

    Open ##2595470