Signing back into the Community for the first time? You'll need to reset your password to access your account. Find out more.
Forum Discussion
datx
2 years agoNew Contributor
What am I missing with passkeys?
I am finally getting around to putting passkeys into action.. but something isn't adding up.
As a low risk test, I added a passkey to a bestbuy account. Started up an incognito session, and logge...
lodaka
2 years agoFrequent Contributor
Note that I am just an average joe, who's a bit security conscious -- i.e. just about 0 technical knowledge about any of this but only what I've been able to read what's on the Internet.
The way that I understood passkeys has been that it will improve security for average users, who, again on average, tend to think that "P@55w0rd" is a difficult password to break. I think attempt was made to help these folks with (first with SMS, email, etc.) authenticators and what not. For these folks, passkeys provide exponentially more secure way to interact online while also making it easy to do so.
For those that are a bit more security conscious (which I think most of us are, seeing how we are all here), I am not convinced that passkeys are necessarily more secure. For instance, if someone has a 30-char password (using 1Password) with Yubikey as a multi-factor, is that not more secure?
Lastly, again I blame my lack of technical knowledge on this subject matter, but if passkeys are sync'd (e.g. through 1Password), if a threat actor gains access to someone's 1Pasword vaults, I am assuming the TA will be able to fully use that, correct?