• Bitrot@lemmy.sdf.org
    link
    fedilink
    English
    arrow-up
    0
    ·
    edit-2
    7 months ago

    Are your non-discoverable credentials also locked on the key, or can someone who knows your handle and possesses your key access your accounts? Online usernames are not well protected, I’d rather my key lock out after a few failed attempts to access it.

    • jet@hackertalks.com
      link
      fedilink
      English
      arrow-up
      0
      ·
      edit-2
      7 months ago

      The non-discoverable keys cannot be removed from the device. The secret is non-transferable.

      In the yubikey bio series, this is implemented as a second factor. So you log in, and then present your hardware key as a second factor. You need your fingerprint, the key, your username. Fairly secure.

      I think this is a more secure model than pass keys as they’re being promoted today

      • Bitrot@lemmy.sdf.org
        link
        fedilink
        English
        arrow-up
        0
        ·
        7 months ago

        Yes, but do you need to unlock your key to use it? Possession is not enough to access discoverable credentials.

          • Bitrot@lemmy.sdf.org
            link
            fedilink
            English
            arrow-up
            0
            ·
            7 months ago

            In that case it does sound better, and many sites using passkeys still have you enter your username first anyway, at least at this point. I don’t know how Android implements it, I think iOS likely supports this use case and know that it also works as a second factor to a password through the same Passkey workflow. Unlike the Yubikey it always stores the key when you register though, even if it isn’t fully passwordless. Unfortunately what’s easy for the consumer will dominate.