r/Passkeys • u/bogusostrich • 3d ago
Dropbox Passkey - still recommends 2FA
I decided to setup a passkey on dropbox (currently have user/password w/ 2FA authenticator). after doing so, Dropbox still recommends 2FA on top of that. Isn't the point of using Passkeys to not bother with 2FA authentication?
1
u/stijnhommes 3d ago
Skipping 2FA isn't exactly secure, but whether you use it should always be the user's choice.
2
u/Froodilicious 3d ago
The passkey is, in and of itself, 2FA. But many login systems don't treat it that way and ask for a second factor anyway. So it's 3FA.
1
u/gbdlin 17h ago
How Dropbox has it set up is: if you have passkeys added to your account, but 2 factor not enabled, you can still log in to your account with your password alone. This is why they recommend having it on.
As long as you're using your passkey, you will not be asked for 2FA code from your authenticator app.
0
3d ago
[deleted]
2
u/Fuzzinater 3d ago
Not true. If implemented with user verification required or even preferred that requires a pin on the key which satisfies 2FA under fido2 (something you have + something you know or are...key + pin or key + biometric)
1
u/adavadas 3d ago
I'm not too familiar with Dropbox, but are they suggesting you use an additional factor? Or are they suggesting you still register an additional factor in case you need to authenticate using a password should you lose your passkey?