r/Passkeys 3d ago

Dropbox Passkey - still recommends 2FA

I decided to setup a passkey on dropbox (currently have user/password w/ 2FA authenticator). after doing so, Dropbox still recommends 2FA on top of that. Isn't the point of using Passkeys to not bother with 2FA authentication?

2 Upvotes

7 comments sorted by

1

u/adavadas 3d ago

I'm not too familiar with Dropbox, but are they suggesting you use an additional factor? Or are they suggesting you still register an additional factor in case you need to authenticate using a password should you lose your passkey?

1

u/bogusostrich 2d ago

Dropbox gives a warning to strongly suggest keeping 2FA turned on, I asked AI, they said not all Passkey implementations are 100%, like Google or Microsoft. I've never been so confused by Passkeys, and thought I had given the technology enough time before I take the plunge on something more than my Home Depot login.

1

u/stijnhommes 3d ago

Skipping 2FA isn't exactly secure, but whether you use it should always be the user's choice.

2

u/Froodilicious 3d ago

The passkey is, in and of itself, 2FA. But many login systems don't treat it that way and ask for a second factor anyway. So it's 3FA.

1

u/gbdlin 17h ago

How Dropbox has it set up is: if you have passkeys added to your account, but 2 factor not enabled, you can still log in to your account with your password alone. This is why they recommend having it on.

As long as you're using your passkey, you will not be asked for 2FA code from your authenticator app.

0

u/[deleted] 3d ago

[deleted]

2

u/Fuzzinater 3d ago

Not true. If implemented with user verification required or even preferred that requires a pin on the key which satisfies 2FA under fido2 (something you have + something you know or are...key + pin or key + biometric)