• Valmond@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    2
    ·
    29 days ago

    So one password to access them all basically?

    That’s quite a weakness.

    • johannesvanderwhales@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      29 days ago

      It’'s really up to the end device (and the user of said device) to decide how much security to put around the local keys. But importantly, it also requires access to the device the passkeys are stored on which is a second factor. And notably many of the implementations of it require biometrics to unlock.

      The “one password” thing is also true of password managers, of course. One thing about having one master passphrase is that if you do not have to remember 50 of them, then you can make that passphrase better then you otherwise might, plus it should be unique, which prevents one of the most common attack vectors.

    • Spotlight7573@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      29 days ago

      So one password to access them all basically?

      That’s essentially how all password managers work currently though?

        • Spotlight7573@lemmy.world
          link
          fedilink
          English
          arrow-up
          3
          ·
          29 days ago

          If it makes you feel better, most PINs on modern devices are hardware backed in some way (TPM, secure enclave, etc) and do things like rate limiting. They’ll lock out using a PIN if it’s entered incorrectly too many times.

      • Valmond@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        1
        ·
        29 days ago

        As I said to Spotlight7573 yes true, I just hoped for something better.

        • johannesvanderwhales@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          29 days ago

          If you’re paranoid about this, go buy a yubikey and use that to secure your device/access to your passkeys. Being able to secure your own data instead of relying on the admin who may or may not know what they’re doing to secure the server is an advantage of passkeys.