Ancestors

Toot

Written by Ken Kinder :clubtwit: on 2024-08-10 at 15:54

How do people using #passkeys migrate from one vault to another?

=> More informations about this toot | More toots from bouncing@twit.social

Descendants

Written by Jarek Samic on 2024-08-10 at 16:06

@bouncing it's not ready yet, but eventually software that manages passkeys and other credentials will implement the Credential Exchange Protocol: https://fidoalliance.org/specs/cx/cxp-v1.0-wd-20240522.html

=> More informations about this toot | More toots from Cldfire@hachyderm.io

Written by Ken Kinder :clubtwit: on 2024-08-11 at 07:34

@Cldfire Apple is notably absent from the roster of contributors. Presumably they and Google will be the biggest vault providers. Have they committed at all to this? 😬

=> More informations about this toot | More toots from bouncing@twit.social

Written by Jarek Samic on 2024-08-15 at 02:59

@bouncing I'm not sure if they've committed or not, but I have no reason to believe that they wouldn't end up implementing it

=> More informations about this toot | More toots from Cldfire@hachyderm.io

Written by Daniel Fisher(lennybacon) on 2024-09-17 at 13:14

@bouncing The idea is that you don’t. You should register another passkey.

That approach, especially when using hardware keys, is pretty secure.

But…

  1. Web sites sometimes don’t let you register multiple keys.

  1. Some user expectations are not met. Especially hardware keys are more complicated (you got to have them, connect them, use them, don’t lose them,…).

They could have decided to distinguish between “secure hardware” and “easy software” but didn’t.

So there is ongoing work for export/interchange of passkeys - which, with some expertise in key management, is a horrible idea. But this is what the average user expects…

=> More informations about this toot | More toots from lennybacon@infosec.exchange

Written by Ken Kinder :clubtwit: on 2024-09-17 at 19:15

@lennybacon Expectations on users have to be realistic. For example, if losing a hardware key locked you out of every site you sign into, no one would knowingly use such a key.

And the average person has what — 200 entries in a password manager? Registering passkeys twice every time you switch dongles or ecosystems won’t work.

=> More informations about this toot | More toots from bouncing@twit.social

Proxy Information
Original URL
gemini://mastogem.picasoft.net/thread/112938534332312586
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
282.60278 milliseconds
Gemini-to-HTML Time
1.312644 milliseconds

This content has been proxied by September (ba2dc).