Passkey support

So basically it would need to support passkeys natively as there isn’t any way to either pass fingerprint or device pin code to Android side?

Well either that or enable the credential manager api inside AAS (assuming it’s disabled now, or maybe partly bridged for things SfOS does natively support?). But then you’d only be able to use passkeys with apps running in AAS.

Sorry, I’m not trying to bait anyone. I’m just expressing my honest view on passkeys. I think overall they’re fine, they’re just not the be-all-end-all of authentication. Especially when it’s Google or Microsoft that’s saying it and trying to tie you into their ecosystem.

I would say the way the general public uses passkeys, which is by storing them in Chrome or Edge, is worse than a strong password. You’re now tied in to their ecosystem, they don’t (didn’t anyway, might have changed) offer an easy way of transferring passkeys, and they’re using them “improperly” by syncing them between devices.

2 Likes

Suppose you receive:

“Your Microsoft account has been locked. Click here to log in.”

With a password, you might enter your password into a convincing fake site.

With a passkey, the credential is bound to the legitimate website’s origin. A fake microsoft-login.example site can’t simply ask your passkey to authenticate as Microsoft.

That’s one of the biggest security advantages.

We were comparing to password managers, where this is not an issue either. Every password manager I’ve used will simply not show the passwords on non-matching domains, and for example 1Password even has a setting now where they’ll show you a warning if you paste anything into a password field on a domain that 1Password doesn’t know.

There is nothing inherent in passkeys apart from hype and integration that makes it any better whatsoever than a properly managed password.

There is nothing in the concept of passkeys themselves that guarantees they check origins or are protected with e.g. biometrics - that is all in the “password manager” - thus it can be replicated by a password manager.

Personally i dislike them, not least because of all the insincere marketing hype around them.

5 Likes

Heya @attah

I would like to challenge your belief that it is hype with real evidence and hope to change your mind.

Please go to https://breachdirectory.org and type my personal Reddit username “deepembrace”.

You will see a list of my passwords leaked. At the top is my 18 character secure password. As a user, I did everything right. But the large corp who is meant to protect our data failed. This story sounds familiar right? (Adobe hack, LinkedIn hack… all passwords leaked)

Now, what is the fastest and simplest solution that:

  1. Businesses can implement
  2. Customers can understand

When I sign in with a passkey, it does not matter if the platform gets hacked. That session token can be rotated/removed just like that. (I don’t think it can even be used… but I’ll let a cyber sec correct me)

You are not wrong that the master password of the password manager then becomes the biggest danger. But we never need to type this into a public facing system. And getting my parents to remember one password is easier than 100. Getting them to remember one password then using their face to auth makes them happy and keeps them secure

4 Likes

2FA. If a password is leaked but one of a number of proper 2FA (TOTP etc) approaches in place, the leaked password is no longer an issue. Any single point of failure, including a single passkey is not that secure.

2 Likes

I would love to be able to use passkeys on Jolla phone. I’ve not taken delivery of my device yet (batch 3). As a cybersecurity professional I regularly make use of passkeys! I would be genuinely disappointed to land on a platform where I can’t do that. I’m thinking worst case scenario I could somehow integrate something into TOH.

Edit: A TOH module with an embedded security key would be a fun community project, mind you.

1 Like

Heya @Zackslash

There is no passkey support yet, I’ve tried :frowning:

To login to some of my services, I need to copy the auth url and open it on my iPhone.

But i hope the community can vote to prioritise it :heart:

2 Likes

Hey, well thanks for giving it a try!

That’s unfortunate, but I did kinda walk into this with the mindset of “some things won’t work right away”. It would be wonderful to have passkeys natively supported in the OS, that being said I think once I have my device for as my daily driver I may need to come up with some workaround in the meantime.

If there is any specific place to vote for this then I would be happy to add my vote :smiley:

2 Likes

I agree that a phone OS that claims to be secure, should have native support for passkeys. Whether or not they are more or less secure than passwords, they are now a common method used for logins. It seems that Linux itself still lacks support for passkeys natively, though, so this might take a while.

1 Like

On Desktop though it’s not a problem at all. KeepassXC supports passkeys, including their browser extensions.

1 Like

Yes, keys (in general, not just PassKeys™ specifically) are better in the way you describe. This is an inherent property of keys - very much in contrast to the usual main selling points of passkeys.

Supposedly guaranteeing biometrics and only talking to the correct site are not inherent properties or unique to PassKeys respectively. This dishonest marketing really sours it for me.

Arguably if the platform is hacked, they already got what they were after. If they stole the private key of the service, then they can at least pretend to be the site in question from a PassKey standpoint. Then you’d sensibly say that the website can and should be verified over SSL - to which i say that it is exactly what a good password manager can do for passwords.

A correctly implemented service will not have your password in plaintext - nor even transfer it in a reversibly encrypted form for verification.
This is damn near the same level of security as a key - the difference is just that sites can do it wrong.

I’d rather see users caring about what exact authentication method is used (and browsers enforcing it) rather than switching over to PassKeys with dishonest marketing and ecosystem lock-in.

None of this is unique to PassKeys. It may be default, but definitely easily replicated by any sensible password manager.

Exactly, once device is compromised then you are cooked. Passkeys idea from a security point of view is a nightmare. I wonder why “big tech” is promoting it so much and the only explanation comes to my mind is that to force “something” backdoor.

In general we are living a nightmare:
ID can be " certified" in many digital ways and some are considered Strong ones. The stonger classification the certificarion has the more " kafka " situation a person can end in cases where the chain of trust has been broken but it’s still not verified to be not fully solid.
When there is no reasonable doubt about ID beeing false one can end behind bars before truth is found. Talking about fingerprints / face ID, yes, your fingers are yours and your face is yours… But in the end only crypted piece of info. Like any other key.