I don't understand one thing about hardware keys. Aren't they, like, easy to steal? Sure, someone could torture my Bitwarden masterkey out of me, but hardware keys seem to make sabotage much much easier.
Technology
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
They’re as easy to steal and misuse as a laptop with KeePassX on it. Hardware as a second factor was always a better use case.
Passkeys are a good idea with an insufficient compatibility issue.
In self host vaultwarden and it's great with my passkeys and very convenient.
Hosting? Passkeys is the thing with the Aegis app, no?
No, that's MFA, the rotating number code thing. Passkeys are another thing.
Totp
Hardware keys are nice but expensive solutions. I'd love to convince my boss we should have them for all senior people plus sensitive roles like accounts and HR. Currently liking the yubikey nano, although its a pain if I forget it. At least I'm not dependant on a third party service.
I agree with this article, i think all points mde are valid and true.
But is there a downside for using mozzila password manager? (other than being in the cloud) I think It allows you to sync your passwords and login information accross any device you use, it works well for phone apps, websites log in and cross platform credentials (ios, android, linux and webpages)
Microsoft & Bitwarden are my only two accounts currently that allowed me to use a physical Yubikey as a passkey and have it work on Firefox + Linux. Bitwarden login with passkey only works in the webapp though, not the browser extension, desktop app or mobile app.
Bitwarden login with passkey only works in the webapp though, not the browser extension, desktop app or mobile app.
Can't confirm, my yubikey is my 2nd factor for bitwarden and I login with it on both my phone and web browsers
It works as second factor, yes. It does for many services, but using it for actually passwordless passkey login doesn't work for most services with my yubikey.
Bitwarden login with passkey only works in the webapp though, not the browser extension, desktop app or mobile app.
I'm confused by this — I use passkeys stored in Bitwarden and they work fine in the browser extension and mobile app (I don't use the desktop app often so IDK). Are there particular sites that it doesn't work with?
I think they mean logging into Bitwarden with a physical passkey.
I mean logging into the bitwarden account with the yubikey. Passkeys stored in bitwarden are usually accepted
I still feel like phishing prevention alone justifies passkeys enough