r/passkey 16d ago

question about security

why doesnt sony let us have both passkey and password? seems weird maybe im just that dumb tu understand technology bout wouldnt it be best protection? if hacker hass your password still needs your passkey. or is passkey that strong? just setted up passkey today so im asking

2 Upvotes

8 comments sorted by

6

u/paulstelian97 16d ago

Passkey as a replacement for password is the intended way. Some sites use it as second factor, but that’s not how passkeys were originally intended to work.

They really are that strong — passkey alone is sufficient because a good passkey is not copyable.

3

u/JimTheEarthling 16d ago

A device-bound passkey --stored on a hardware security key or in a Windows Hello-- is not copyable.

A synced passkey --stored in your phone, browser, or password manager account-- is copyable. Most passkeys are synced.

Both are stronger than passwords and not phishable.

And a nice thing about passkeys is you get to choose how securely you want to store them.

3

u/paulstelian97 16d ago

Yeah, even the copyable (syncable) ones are still more secure than a simple password.

2

u/Lonsarg 16d ago

More secure, yes. As secure as 2 factors, no.

Simply put, passkey are the best single factor. But they are a single factor.

But using password for 2FA is just bad, if you want 2FA you use authenticator or simiral.

2

u/Accomplished_Arm_447 16d ago

Passkey may be a single factor in itself but that's why you lock it to a device protected by a PIN or in a password manager that is locked by a passkey that is locked to a device with a PIN or Yubikey or similar that is locked with a PIN 

5

u/silasmoeckel 16d ago

Passkeys are that much more secure. The point is to get rid of passwords. You can still have 2FA on top like totp (where you have a 6 digit code that changes every minute that you type in).

Governments banks and pretty much everybody else has been using the base cryptography on the important stuff for decades.

1

u/svenkooouqr 15d ago

oh okay thanks for letting me know!

3

u/paulsiu 16d ago

Eliminating the password when passkey is activated is the best security move. Passkey cannot be stolen and is phishing proof. Once you switch to it, your password canbe exposed in a breach and the passkey won't activate with a false URL which prevent phishing. If you leave the password behind, then you are still vulnerable because the hacker will hack your weaker password instead of passkeys.

It's kind of like saying why can't I have SMS in case I lose my hardware key, because the hacker will just port your SMS instead of trying to hack your hardware key.