Skip to content

Comment on Pass the Passkey: A Novel Attack Surface in Passwordless Authenticationparent

Comments

And if you get access to the vault, then you get everything. OK. And if you get access to a synced traditional password vault, then you get everything.

No? It’s why 2FA exists. I have an email with password of 5 characters only and the password leaked decade ago, never changed it and no one accessed it because it has 2fa. I can share my whole password vault and I would not care about it because it’s useless without 2fa. Not the case with passkey, glad I never set it up on any of my accounts, pass+mfa is good for 99% of accounts (not sms obviously), rest are public private keys.

Majority of second factors are phishable. If you are using a password (phishable) + a phishable second factor (any kind of 6 digit code that you need to type or paste into a text box), you are less secure than if you were using only a passkey.

There is nothing stopping people from using passkeys with MFA. I’ve seen them do it. It’s against the suggestion, but they can do it.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.