Jump to content

Recommended Posts

Posted (edited)

Has anyone started using passkeys instead of 2FA on their personal Google accounts?

 

https://arstechnica.com/information-technology/2022/10/passkeys-microsoft-apple-and-googles-password-killer-are-finally-here/

 

https://www.androidpolice.com/google-passkeys-replace-passwords-guide-setup/

 

https://developers.google.com/identity/passkeys

 

https://developer.apple.com/passkeys/

 

How could we deploy passkeys in schools in future? Will we require a cheap FIDO device or similar?

 

Also I see a weak link in that device biometrics fall back to a lock screen PIN so are all our creds protected by a 6 digit or 4 digit pincode? How does it work when I loose my only phone?

Edited by Alis_Klar
Posted
Has anyone started using passkeys instead of 2FA on their personal Google accounts?

 

https://arstechnica.com/information-technology/2022/10/passkeys-microsoft-apple-and-googles-password-killer-are-finally-here/

 

https://www.androidpolice.com/google-passkeys-replace-passwords-guide-setup/

 

https://developers.google.com/identity/passkeys

 

https://developer.apple.com/passkeys/

 

How could we deploy passkeys in schools in future? Will we require a cheap FIDO device or similar?

 

Also I see a weak link in that device biometrics fall back to a lock screen PIN so are all our creds protected by a 6 digit or 4 digit pincode? How does it work when I loose my only phone?

 

I managed to register in Edge (iOS) but can’t login. But if an oversight on Microsoft’s part. Works fine in Safari (iOS).

Posted

Hi,

 

Looked into this a bit more.

 

If you have FIDO U2F stick Windows will store your Passkeys there.

 

Also chrome on iOS uses the iOS keystore not its own internal/Google one AFAIK.

 

There is a site here to try out Passkeys in a sandboxed safe environment. It seems to rely on sending you a 6 digit code by e-mail to register if hardware fails etc. Not sure if other developers would take this option or what protocol allows for account recovery etc.

 

https://www.passkeys.io/

Posted (edited)
Also I see a weak link in that device biometrics fall back to a lock screen PIN so are all our creds protected by a 6 digit or 4 digit pincode? How does it work when I loose my only phone?

 

Each passkey is device-specific, so a PIN would be more secure than it sounds. A stolen PIN wouldn't allow access from some other random device.

 

If you lose your phone, then you revert to using password/2FA. If you get a new phone, you'd similarly sign into that initially using password/2FA (or a cross-device QR if bluetooth proximity can be detected) and then a passkey is probably automatically added for you for the new phone. Yes, phishable authentication is still technically in play, but there's more friction there if passwords aren't the regular way to sign in.

 

Trying g.co/passkeys on my Workspace account, it tells me "Passkeys aren’t allowed on this account.". Not sure if that's because they're not available for Workspace yet, or just that they need enabling in Admin. In principle, I can't see why there would be any issue with Workspace users having them. It's pretty similar to how they're able to add the 2FA methods that they want/need. With passkeys available, admins would still be able to provide users' with one-time 2FA backup codes.

 

Edit:

Just read on a blog post from last week https://blog.google/technology/safety-security/the-beginning-of-the-end-of-the-password/

For Google Workspace accounts, administrators will soon have the option to enable passkeys for their end-users during sign-in.
Edited by jthompson
  • Thanks 1
Posted
If you lose your phone, then you revert to using password/2FA

I thought passkeys did away with passwords altogether. How do we remember passwords generated by a password manager?

 

I think it will fall back to password resets over e-mail so the e-mail account will remain the honey pot for attacks and users will probably have to remember the password for that account only. Or carry a FIDO U2F on their keyring as a backup.

 

Not sure if Microsoft are merging "passwordless" with Passkeys? Keeper have written a critique of MS passwordless here

 

https://www.keepersecurity.com/blog/2021/10/11/microsofts-passwordless-login-isnt-all-its-hyped-up-to-be/

 

Also ArsTechnica have a good article and the comment section is illuminating

https://arstechnica.com/information-technology/2022/10/passkeys-microsoft-apple-and-googles-password-killer-are-finally-here

Posted

I suspect that Google's thinking is that as passwords start being used less and less by poeple (in favour of passkeys), that will allow them to treat each use of a password with more scepticism.

 

I don't know. Passkeys are one of those slippery things where each time I think I've grasped it, I then realise that I've not quite grasped it. Much of the PR from the big firms is written for a consumer audience in a tone of "it just works, accept a little bit of magic and don't think too much about it", whereas our job as admins is to understand and account for those edge cases a bit more.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...