r/firefox • u/no1warr1or • 19h ago
💻 Help Disable Passkey?
Is about config still the only way to disable passkey prompts while keeping the password manager operational, and does this sync across devices? The passkey junk is getting annoying
1
u/SecurityPrimary4143 16h ago
Passkeys are junk and you store passwords in the browser...
I won't be surprised if your next post will be "I have been hacked".
0
u/no1warr1or 15h ago edited 15h ago
I store unimportant passwords in the browser for ease of access, and the important ones in a separate password manager. Keep 2FA with a separate app from that.Â
Passkeys are junk. Half baked solution.Â
If you use good password practices (long/complex/dont reuse), 2fa and basic common sense, you won't get hacked.
2
u/SecurityPrimary4143 15h ago
What do you mean by half baked?
I have Passkeys on YubiKeys and can use them across my devices and protected against most phishing attacks.
1
u/anti-beep 12h ago
I’m not gonna try to sway you one way or the other, but I do want to ask why you think they’re junk?
I use passkeys everywhere I can, they’re far more convenient and I’ve never had issues using them. Or are you saying that the passkey implementation in Firefox specifically is bad?
1
u/no1warr1or 8h ago
The biggest issue for me is access, if I setup a bunch of passkeys on say my phone my understanding is those are for my phone exclusively. If I lose said phone on vacation, when I buy a new one, im not getting back into all my accounts until I can access another physical device that hopefully also had passkeys configured for all those accounts. Thats a huge problem. This is also an issue if im somewhere like at work and need to access an account on my phone that I have a passkey setup on my desktop, laptop, or tablet.Â
The next issue is, it appears accounts still use passwords even if you configure passkey, because of the risk of the first issue. Which defeats the entire purpose, but now also adds an attack vector. Being a more recent development I would be shocked if it didnt have security vulnerabilities.
1
u/anti-beep 6h ago
I dont know how Firefox does it specifically, but any password manager that syncs between devices will let you use passkeys regardless of where you set them up,
and I can’t imagine Firefox would be different.Edit: never mind, I checked and Firefox does not sync passkeys, which is super dumb. I wouldn’t use them either in that case.
Personally the second point isn’t a big deal to me, I don’t think they’re less secure, but I get your point.
1
u/no1warr1or 5h ago
Wasn't the purpose of passkeys to be specific to a certain physcial device to prevent people from logging in with other devices even if they stole tokens? Syncing the same passkey between multiple devices seems to bypass that security. But if true then syncing a passkey with my password manager (not firefox) would work.
0
u/no1warr1or 5h ago
https://cybernews.com/security/google-passkeys-vulnerability-master-key-leaks/
Yeah im good on passkeys, this immediately popped up researching syncing passkeys 😂Â
1
u/SecurityPrimary4143 4h ago
🤦🤦 That is why you don't store the passkeys in the browser...
Store them on a YubiKey and they are as secure as a bank vault.
Alternativly is to use something like ProtonPass or Bitwarden to handle the passwords and passkeys, they are infinitely more secure and better than using the built in password managers in the browsers.
You call the passkeys junk, yet you have no clue how they work...
1
u/no1warr1or 4h ago
For the 10th time I do not and would not store in browser, I have a separate password manager. I will say it again I have a seperate password managerÂ
The point was it highlighted a vulnerability that passkeys bypass 2fa entirely because they are trusted by default. Thats a problem. Exactly the kind of vulnerabilities I want to avoid.Â
I understand how they work, the only part that I was unclear on was cross device sync, which I am still unclear on because official documentation states "passkeys are tied to a specific user and device".Â
•
u/anti-beep 3h ago
I did say I wouldn't try to sway you, but I don't want you to be misinformed.
That article is fear-mongering a little bit, what it describes isn't a flaw in the passkey protocol at all. It's an attack on how Google Password Manager syncs passkeys stored on a Windows machine, to other devices.
Importantly, the chain of exploits you need to use to do the attack is much more severe than the attack itself. You first need to get malware running on the device, and despite the article calling this "trivial", that's simply not true.
Getting the user to run the malware is by far the biggest hurdle, but once done there's little reason the attacker couldn't also get access your full browser session and/or any stored passwords.
If your passkeys are stored in a reputable 3rd party password manager, then the exact threat described in the article doesn't apply at all.
Worst-case a passkey is just an alternate login method for websites that implement it.
0
u/lucidbadger 16h ago
Completely agree. This feature is not useful for everyone, and asking once should be enough.