Security News Nearly half of the world's passwords can be cracked in under a minute!

What happens if the device the passkeys are on, borks, due to a hardware issue. If you have to get a new device, laptop, how are you able to login to sites from the new PC? Do you need to use some kind of backup manager to sync from?
For the highest protection level (like ChatGPT Advanced Protection, with device-bound passkeys), you need backup passkey authenticators (security keys, Windows platforms with TPM, etc.) — if you lose all your keys, you lose the accounts. Add keys that support different platforms/USB ports. Higher security comes with inconvenience and a price.

Most default setups today keep passwords and 2FA while offering passkeys as an alternative (for example, MT itself), so logging in from a new device isn't a problem. Using passkeys while retaining passwords and 2FA is primarily convenient (fast and reassuringly safe). The anti‑phishing protection is stronger than password managers because it can't be overridden, so it's safer too.

Password manager sync is meant for convenience. Passkey is like a very strong password (anti‑phishing with no override, no leaks from the service side), but they mostly authenticate without an additional 2FA, so if your password managers leak, there is no second line of defense. OTH, if you password managers leak because of a malware on your system, your authentication tokens on the machine are most likely leaked too.
 
Last edited:
Accordingly, managing passkeys is more difficult than managing password managers because they don't sync and are difficult to recover if you switch devices, operating systems, or browsers, am I correct?
They do sync across some password managers, the Apple and Google password managers are definitely syncing. The key requires a device with authentication (though cheap Android tablets with passcodes water down the security of passkeys).

The requirement is a device with some sort of authentication. Windows writes them in the TPM (if available), Apple writes them in the secure enclave and Android in the Trusted Store.

Third-party password managers reduce security by writing in software storage. In any case to recover the keys you will need other authentication means.
 
The issue is that technology has become more complicated rather than simpler over time. It took me a long time to adapt to password managers, and now there are passkeys. 😩
The fun part is, that people still need to have all, you enter password, 2FA and that generates passkey for a simpler login, but it comes with a price.
I login on a new phone using biometry, that is like a passkey, but when it died, I had to use PIN, which I forgot, so I blocked access to my bank.
 
I login on a new phone using biometry, that is like a passkey, but when it died, I had to use PIN, which I forgot, so I blocked access to my bank.
This is a big NO NO for me, there are just way too many ways to abuse bio metrics. Whats stopping people hitting you with a $5 🔧 and unlocking your phone/device?
 
Whats stopping people hitting you with a $5 🔧 and unlocking your phone/device?
Me hitting them back with my pen, the pen is mightier than the sword. 🙃
 

Attachments

  • s-l1600_2_f5a4b7bd-e111-48bc-aa67-44cf11c91809_720x.webp
    s-l1600_2_f5a4b7bd-e111-48bc-aa67-44cf11c91809_720x.webp
    80.2 KB · Views: 52
I login on a new phone using biometry, that is like a passkey, but when it died, I had to use PIN, which I forgot, so I blocked access to my bank.
Note to family:

When I die, be quick and preserve my fingers and use them while they last. Maybe formaldehyde would help — you can try that.

Preserving the face for the iPhone and Windows hello probably won’t work, though — infrared and all. Heating it probably wouldn’t work either.
 
This is a big NO NO for me, there are just way too many ways to abuse bio metrics. Whats stopping people hitting you with a $5 🔧 and unlocking your phone/device?
They tried 2 nights ago to snatch my phone. I just saw a big black glove on top of my phone as I was looking at it. I moved the phone and the guy lost balance as he was flying past me on his bike.

If they hit you with the 5 dollar wrench 🔧 (again and again) you will voluntarily give everything at one point.
But there is no need to jump to this scenario.

Also, Face ID requires your eyes to be open.

Banks and stuff usually have additional protections.
 
I did a quick search and found that I can recover my accounts using recovery codes if I lose my passkeys, just as I can if I lose my 2FA generator. Is this true? And can I reuse my passwords and 2FA if I can't use or if I lose my passkeys?
It happened to me that I transfered everything from one phone to another, just not my Google 2FA. I’ve learned from this mistake now and my 2FA is cloud-synced.

I did manage to recover these accounts but there are different procedures. For many, just phone number, email, etc will be enough. For a few, I had to send emails.

Problem will be when you did not add phone number/valid alt email or anything.
The account will just be lost.
 
Security can be simple, when you do not overthink it. 🤫
I am saying the following in jest, but it may also be helpful if a user uses such a scheme.

Neither https[:]//malwaretips.com nor hxxps[:]//malwaretips.com has been pawned, but https[:]//www.google.com has:

1778572432401.png
As hackers catch up, it may be time to double down. Often, if you type the password twice, it hasn't been pwned.

One advantage of using a random password is, you don't have to guess the schemes hackers are using; the computational effort needed to crack random passwords is more predictable.
 

You may also like...