What a terrible headline.
Better: “Windows has such terrible security architecture that a compromised application can steal a user’s passwords, passkeys, and literally anything else.”
This is why passkeys were always supposed to be hardware tokens.
And yet were almost immediately converted to local storage for adoption reasons. Per the article.
Yes, and it was a huge mistake, as a passkey stored on insecure media is effectively just a password with extra steps as far as the cryptographic guarantees are concerned.
The argument that restricting them to secure devices such as TPMs would hurt adoption and prevent passkeys being migrated to other devices is a completely bogus one.
Firstly, all consumer devices now ship with TPMs or a secure enclave equivalent, so the argument that users simply don’t have the hardware is no longer true. Even if it was true before, there’s no value in a software passkey when it can be just as easily stolen as a saved password or browser cookie.
Secondly, the problem of migration has already (now) been solved by the FIDO spec writers and passkey migration has a well-defined protocol to support it. Moving to software implementations was never required to solve this problem.
So why did they allow this to happen? In my view it started because the usual Big Tech suspects saw passkeys as an opportunity to enhance their ecosystem lock-in by adding another repository of important data that they manage for the user in their OS product, instead of it being a separate ecosystem managed by a piece of hardware that the user purchases such as a Yubikey.
This is why the question of migration was expedited in the first place, not because migrating keys from secure devices is hard, but rather because people could see that vendor lock-in was going to occur with the software passkey implementations.
So why did they allow this to happen? In my view it started because the usual Big Tech suspects saw passkeys as an opportunity to enhance their ecosystem lock-in by adding another repository of important data that they manage for the user in their OS product, instead of it being a separate ecosystem managed by a piece of hardware that the user purchases such as a Yubikey.
Microsoft.
Malware installed on a device running macOS, iOS, and Android, for instance, has no ability to defeat this isolation unless the OS itself is compromised through some sort of exotic zero-day exploit. So far, these assumptions have been proven correct in real-world practice.
The lone exception is Windows.
Mmmmm.
From my understanding it is the same on linux though, theres no sandbox preventing an app or malware from accessing anothers app data
IMO storing Passkeys in Google Password Manager is a bad idea in general.
IMO storing
Passkeysin GooglePassword Manageris a bad idea in general.I’ve adjusted it
IMO
storing Passkeys inGooglePassword Managerisabadideain general.Pray I do not adjust it further.
Why not?
Google bad.
Using a big tech option for something like a password manager is a bad idea in general. Eggs, baskets, etc…
It’s nothing then that hasn’t already existed basically. You have to store the passkeys somewhere and somehow, but when your whole system is compromised, then your passkeys, like your passwords in managers can be compromised too.





