this post was submitted on 14 Feb 2024
265 points (89.3% liked)
Technology
59960 readers
3388 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related content.
- Be excellent to each another!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, to ask if your bot can be added please contact us.
- Check for duplicates before posting, duplicates may be removed
Approved Bots
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
So you really need two independent devices with their own passkeys to back each other up.
Not sure exactly what you're getting at, but any authentication model must be designed with the assumption that a user can lose all their devices, passkeys included. That's where fallbacks come into play. Even with Apple's system, you can recover your keychain through iCloud Keychain escrow, which (according to their help page) uses SMS:
While SIM swaps aren't super common, they're not the most difficult attack. Passkeys are strong against direct attacks, for sure. But if I can reset your account using a text message sent to a device I control, is it really that much more secure?
So if you lose access to all of your devices, you're completely locked out of everything until you're able to get a new working phone activated on a trusted phone number? The trade-off of inconvenience for security here just doesn't seem worth it to me.
Depends on the provider in question. While Apple does allow SMS recovery, they also let you designate a trusted contact who can let you in as an alternative. This is obviously more convenient (if you have a friend or family member who can be available when you need them), but the situation with SMS vulnerabilities is still my main gripe.