Skip to content

Comment on Pass the Passkey: A Novel Attack Surface in Passwordless Authenticationparent

Comments

Those are the right questions: While I'd personally prefer full copy/import/export control, having the ability to set up an second key in advance is functionally-similar to having a backup of the first one. If I had my 'druthers:

1. All sites/services would allow the registration of 5 or more keys, which can be tracked/revoked separately. That way if one device is stolen, you can invalidate that key without affecting others.

2. There are two sets of keys: "Regular Use" and "Backup/Recovery".

3. Attempting to use a Backup/Recovery key prompts to user to confirm that they want to invalidate the Regular keys and promote the backup key(s) to the new regular. In this way, a compromised backup cannot be used in secret.

It's not functionally equivalent, but it is a workaround, but requires doing it on every site (if they allow it) and it cannot be freely moved and re-backed up offline from the site.

The actual reason is people have many devices. I assume this is at least somewhat common, but I still avoid passkeys so IDK.

You're designing a system where we should just be able to backup our own keys if we want to.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.