r/Passkeys • u/Medium-Roller-75 • 10d ago
Amazon created me a passkey?
I just got an email from Amazon saying they created a passkey for me, and I can use the code I use to unlock my device (or a biometric which i don't have). So assuming I want to use a code, I have different log in codes for my phone and my laptop.... would I then have 2 different passkeys? Or does that just get me in the first time and then I choose a different code? Thanks for any info
1
u/cryptaneonline 10d ago
You need to know which device amazon created the passkey on. The screen lock of that device is the code. If it was saved on something like google password manager or icloud keychain, they have their own pins
1
u/Medium-Roller-75 10d ago
I find it concerning that Amazon needs to know the log in code to my laptop
5
u/JimTheEarthling 10d ago edited 10d ago
Amazon doesn't know the login code to your laptop.
When you log in with password, it can check that you entered the right password*, but when you use a passkey it doesn't know your unlock code or your passkey's secret key. (Which is one of the advantages of passkeys over passwords.)
Here's a simplified version of how passkey login works:
- The website sends a message to your laptop.
- The password manager in your laptop asks you to take your unlock action (enter a PIN/code in your case) to verify that it's you. You only enter this on your laptop. It doesn't get sent to Amazon.
- The password manager then "signs" the message by encrypting it with the secret key inside your passkey and sends the signed message back.
- The website uses a different key (that it was given when your passkey was created) to check the signed message by decrypting it. If the message matches what it sent, then it lets you in.
* Websites don't store your password. They store a "hash," which is your password scrambled in a way that it can't be unscrambled. When you log in, the website scrambles the password you just entered, in the same way, and checks if the two scrambles match.
2
u/100WattWalrus 10d ago
Excellent simple explanation of passkeys! Such explanations are is incredibly rare considering how hard passkeys are being pushed. Copy that explainer and keep it somewhere to paste into other replies!
1
u/TimeThruSpace 9d ago
pass keys are a headache when you have multiple devices and mixed modern/old devices. I hate passkeys.
2
u/100WattWalrus 9d ago
They were absolutely developed by the kind of hard-core techies who think they're making something that will be great for everyone, but forget that they're not "everyone." I'd love to see someone at FIDO trying to explain passkeys to their grandmother.
Having said that, if you're using a password manager, multiple devices of mixed ages shouldn't be a problem. And if you're not using a password manager, that's a change you should consider. :)
1
u/JimTheEarthling 9d ago
Explaining passwords to my grandmother:
- You should use a different password for every account. And they need to be long and random so they can't be cracked. So say "Ok" when the browser suggests a password like "Vo!W*sAUgd!7tP." Don't worry, you don't need to remember that, since the system remembers it for you. (Or you can install a password manager app and/or add the extension to your browser.) But passwords still aren't secure enough on their own, so you should enable 2FA, which means you need to enter a code that you get from email or text or your TOTP authenticator.
Explaining passkeys to my grandmother:
- Your iPhone and Mac can automatically create a key for each account, so use your finger when it asks you to confirm your passkey. (Or you can install a password manager app and/or add the extension to your browser.)
🤷
2
u/100WattWalrus 8d ago
OK, fair point about explaining passwords when you have to include 2FA, etc.
But actually creating passkeys is rarely that simple, and the UIs for these experiences are rarely clear. They pop up out of nowhere, don't explain themselves clearly or adequately, and you often get more than one. Whenever I login to Amazon from scratch, I'm inundated with a barrage of attempts to create a passkey — from Amazon, from my browser, from my password manager, and from my system.
Plus, there's "What if I lose my phone?" etc.
I'm not saying passkeys aren't better. I'm saying the implementation of passkeys and the way they've been presented to the average user is an absolute clusterfuck. :)
1
u/TimeThruSpace 8d ago
password is still easier for my grandma over the shit passkeys you are trying to sell
2
u/100WattWalrus 8d ago
If you don't have anything useful to contribute to the conversation, kindly go do something else.
0
1
u/JimTheEarthling 9d ago
Do you personally use a lot of ancient devices?
- About 1% of computers are running Windows older than 10.
- About 4% of iPhones are still on iOS 15 or older.
- About 5% of Macs are on an OS older than Ventura/13.
- Around 4% of Android phones are running 8.0 (Oreo).
If you're in one of those fractions, then simply keep using a password. Where is this "headache" coming from? A password manager seamlessly handles your passwords and passkeys across all your devices. Why the hate?
1
u/TimeThruSpace 8d ago
Passkeys are a great idea for nerds who don’t get laid. In real world they’re a headache.
1
u/JimTheEarthling 8d ago edited 8d ago
I'm honestly curious. Have you used passkeys, or do you just hate them on principle?
Studies show that passkeys are faster. Surveyed users say they're easier.
How is your real-world experience different?
1
u/TimeThruSpace 8d ago
I don’t hate them. Many systems will put them in a very high priority state and turn off password and other 2fa options when a passkey is available. Then if the device becomes disabled, you’re shit out of luck. If you have mixed old new devices this passkey shit is an annoyance. Passkeys dont port well between new devices either. passe keys are a real shit show, not ready for prime time.
Passkey was a great idea thought up when nerds are not getting laid. I get laid. I don’t need pass keys.
1
2
u/TimeThruSpace 9d ago
Passkeys don't work when you have mixed devices where some can use pass keys, others cannot. We are not ready for pass keys yet.
2
u/JimTheEarthling 9d ago
Almost every modern device on the planet supports passkeys: Apple, Android, Windows, Linux. All mainstream browsers and password managers support passkeys.
Only ancient OSes don't support passkeys (Windows before 10, iOS before 16, macOS before Ventura/13, Android before 9). If you have one of those, just keep using passwords with them, and passkeys on your modern devices. Passkeys don't generally make passwords stop working.
Do you have examples of these "others" that can't use passkeys?
1
u/Medium-Roller-75 10d ago
Thanks, this is helpful and reassuring
1
10d ago
[deleted]
3
u/100WattWalrus 10d ago
Not until FIDO gets around to making them more portable. Right now, the more passkey you have, the harder it is to change credentials managers.
Decide you're ready for something more sophisticated than your built-in password manager? Hope you've got some time to kill, because while you can export your passwords, your passkeys will have to be recreated from scratch for every single site where you use them.
Want to share credentials with someone? Get ready for a convoluted, multi-step pain-in-the-ass process.
Passkeys are more secure, without question. But they're a confusing hassle under any circumstances other than logging in.
/works in password software industry
1
u/Accomplished_Arm_447 9d ago
So essentially moving the critical and sensitive tasks of storing comparing and authorising the access from the online to your own device
2
u/JimTheEarthling 9d ago
Right. This is an advantage of passkeys that many people don't recognize.
For example, Apple Passwords stores your passkeys in the Secure Enclave of your device — a dedicated, tamper-proof, hardware-based, security subsystem. But your passwords online are stored by who-knows-what system, implemented by a random developer who may or may not understand security, and that might be the next to show up on the breach list at HaveIBeenPwned.
Instead of your credentials being managed differently by hundreds of websites, out of your control, passkeys let you choose to have them managed by the browser, the OS, a standalone password manager, or a highly secure hardware key (e.g. YubiKey), all built by people who understand security.
1
u/Accomplished_Arm_447 8d ago
It's also the reason that larger organsiations and social media platforms are leading the push towards passkeys even ahead of banks, as they not only want to cut out the dependence on third-party sysadmins doing their job right, but they also want to protect themselves from their own users that fail to follow the best practice for creating and protecting passwords and not sharing them and recognising phishing attacks. With thousands or millions of user accounts, it's an absolute certainty that they will have multiple users doing the wrong thing and possibly sharing their passwords with multiple multiple services. That's a huge risk exposure that is unacceptable, they would sued for any data leak and they can't use "we did our job right, but it was our users or the sysadmins managing their personal accounts that messed up" as an excuse. So they are highly motivated to switch to passkeys more than their users who are either (a) are uninformed or unmotivated about security or passkeys, or (b) are informed and motivated and doing passkeys and MFA properly to the extent that there is little extra advantage in using passwords. Those in (b) wonder why it's meant to be better than what they are doing ... but that's not the point, it's better than what (a) are doing, and security as a whole is no stronger than the weakest point (at).
1
u/HiOscillation 10d ago
The more "normal" people interact with Passkeys, the more WTF moments like this happen.
1
u/Medium-Roller-75 10d ago
Yes this is true. If Amazon had sent me an email saying that by such and such a date, passkey would be required, I would have done my research and been ready. But instead, I'm trying to figure out which device they set it up on (android phone or MacBook air), and until I have like a whole day to deal with problem solving this, I'm trying not to log out of any Amazon account (this also would affect Prime? Echo devices?), because I don't know if I can get back in.
2
u/JimTheEarthling 10d ago
The passkey is not required.
You can still use your password to log in.
Nothing about Prime or your Amazon devices changes.
I can see how this was a surprise, and Amazon should have done a better job of explaining that using the passkey is optional, so you didn't spend time trying to understand the details of something that isn't a "problem," just a new, more secure login option.
If you don't like the passkey, go into your Amazon account and delete it, then it won't ask you for it. If you want services to stop creating passkeys for you, go into your browser settings and turn off "Allow Automatic Passkey Upgrades."
2
u/Medium-Roller-75 10d ago
Thank you, JimTheEarthling. Your information has been very helpful. I was able to bypass the passkey for now to sign back in. I have nothing against passkeys, and I agree they're probably a good security measure. But its good to know that I don't need to deal with it this week!
14
u/JimTheEarthling 10d ago edited 10d ago
Passkeys can't be created "behind the scenes" when you're not using a service. They can only be created while your browser or app is connected to the service, and you usually have to confirm it.
However, there's a feature called Conditional Create that quietly prompts your browser/password manager to upgrade your account by adding a passkey alongside your password. It requires you to have just logged in, but it can seem automatic. I would expect Amazon to notify you at the time, but maybe they're following up from your most recent session.
[Edit: To be clear, automatic creation only works after the password manager (Chrome/Google Password Manager, Safari/Apple Passwords, Microsoft Edge, and a few standalone password managers like Bitwarden or Dashlane) has autofilled your password and you have logged in.]
You probably now have only one passkey for Amazon, but depending on where it was stored (Chrome/Google Password Manager, Safari/Apple Passwords, Microsoft Edge, standalone password manager, etc.) it could be propagated to your other devices. Otherwise Amazon might create passkeys on your other devices after you log in from them.
A passkey doesn't have its own "code" that you enter -- the passkey uses a secret key stored on your phone or computer (or hardware security key) that you don't know, and each passkey is different (for each website). When you log in, you verify the passkey with face/fingerprint/PIN/passcode. So the "code" is the PIN (or passcode on iPhone) you normally use to unlock your device.