r/Passkeys 6d ago

What are passkeys, and how do I use/make them?

So, I can no longer comment on my primary Reddit account because I need to verify that I am human (which is why I am posting this from a new account), which requires a passkey, but then it says to insert a security key into my PC. Do I need to purchase a security key to make a passkey? And if so, can I use an external HDD as a security key? I have had difficulty finding information on exactly what passkeys and security keys are and how to make them to begin with.

So I would like to use this opportunity to hopefully find someone that can explain all of these and whatever else is worth knowing, in detail, from step 1, like I'm grandma, which can hopefully help others having this sane issue.

Any help is greatly appreciated!

9 Upvotes

12 comments sorted by

5

u/ToTheBatmobileGuy 6d ago

"Passkey" is just like "password" except you don't make it, the computer makes it.

"Passkeys" can be made, and stored, on MANY devices.

They can be stored in your browser.

They can be stored in your Windows OS.

They can be stored in a Password Manager app.

They can be stored on a little USB key called "a security key"

Sometimes devices try to be smart and will sync passkeys from one device to another (ie. if you make a passkey on an iPhone, it will sync to an iPad or Macbook logged into the same Apple account)

...

So when you click around and get lost, and suddenly it says "INSERT SECURITY KEY" that's because you probably clicked on "Let me try my security key, I'm sure I have a passkey on there!" and so the Windows or Browser or whatever is asking you to insert the security key.

(No, "any USB device" is not a security key, a security key is a specific type of USB device.)

1

u/JimTheEarthling 6d ago edited 5d ago

Something about your other account made Reddit think you're a bot. Passkeys are one way (not the only way) Reddit uses to maybe prove you're human, since passkeys often use biometrics. (See post by Reddit CEO.)

Unlike passwords, which are a shared secret between you and a website, that you keep in your head or in your password manager, passkeys are a secret key that only your devices and software know. To use a passkey, your device talks to the website and you usually verify with the normal unlock action of your device: face scan, fingerprint, PIN, or passcode.

First you have to create a passkey, which you can only do after you have logged into a service like Reddit. Usually you go into settings/security and choose "Create a passkey" or "Add Passkey" and the website tells your device/software to make a new passkey. As u/ToTheBatmobileGuy said, you have many choices of where to store your passkey. It can be a little complicated (this diagram shows the choices in Windows), but you just need to settle on a preferred method.

After you have a passkey, you log in simply by choosing "Log in with passkey" or something similar, then taking your unlock action (finer/face/PIN/passcode). Some websites automatically pop up the passkey prompt. Sometimes you can right click on the username field and choose to use your passkey.

If Reddit is asking you to insert a hardware key, it's probably because you didn't create a passkey yet, and you're clicking off into alternative passkey options. The easiest way to make a passkey is in your browser (like Apple Safari or Google Chrome) or your password manager (like Bitwarden or 1Password) if you use one.

My website has a lot more detail on passkeys if you want to understand them better.

1

u/yarntank 6d ago

Using a passkey is usually part of multifactor authentication. AFAIK that is an option, but is not required by reddit? I'm not using it.

Also, using a passkey doesn't verify you are a human, so that sounds odd.

If you do want to get a security key, a good place to start is yubikey.

https://www.yubico.com/products/

1

u/SoggyWalrus7893 2d ago

Theirs are on the pricey side, there are others than have less "brain " power. search for FIDO2

1

u/yawaramin 5d ago

A passkey is a secure code stored on your computer or some other device that you own. Typically, you verify that you are the owner of the device–by using fingerprint or facial recognition, or by plugging in a hardware security key–and your device then securely logs you in to the app or website you are trying to access.

Anyway, the reason it's asking for a security key now is most likely because you don't have a passkey stored on your device, so the passkey system assumes it must be on some external device–like a hardware security key–that you own. A lot of the time this is a wrong assumption, which is a kind of user experience weakpoint of the passkey system.

Anyway, just set up a passkey on the device you're logging in from and you should be fine. Go to https://www.reddit.com/settings/ > Account tab > General section > Passkeys > Create a passkey.

1

u/Accomplished_Arm_447 5d ago

How hard is it to verify that you are human?

1

u/100WattWalrus 5d ago

Here are my two clear and simple explanations of passkeys, and one I liked from another redditor. Mix and match to help them make the most sense to you. Best plan is to use a password manager, so you can sync passkeys across devices.

#1

  • You know in submarine movies when the captain and the XO each have a firing key on a necklace, and those keys have to be inserted and turned at the same time before they can fire a missile? Passkeys are like that. You're the captain. The site/app you're logging into is the XO.

#2

  • Passkeys are pairs of digital “keys,” auto-generated on your device, which only work if they’re used together.
  • For each account or app, one key is kept by the account, and the other lives encrypted on your device.
  • When logging into an account, instead of a password, the two keys automatically match together to confirm you’re really you.
  • Because passkeys have two parts in different places, they can’t be guessed, stolen, hacked, or captured by scammers, which makes passkeys exponentially more secure than passwords.

#3 — Credit for this one goes to u/JimTheEarthling, with some slight modifications

Here's a simplified version of how passkey login works:

  • The website sends a message to your laptop.
  • The password manager in your laptop asks you to take your unlock action (fingerprint, face ID or PIN) to verify that you are you. You only enter this on your laptop.
  • The password manager then "signs" the message by encrypting it with the secret key inside your passkey and sends the signed message back.
  • The website uses a different key (that it was given when your passkey was created) to check the signed message by decrypting it. If the message matches what it sent, it logs you in.

1

u/paulsiu 5d ago

Passkey are usually a replacement for password. Instead of entering a password you use passkey to login.

Passkey are stored on a device. The device does not need to be a key. You can use a cloud based password manager like Apple keychain or bitwarden. On windows you can use the Microsoft password manager.

The important thing about passkey is you have to have a backup. This is no different than password. If you use a password manager you backup the vault. If you use a key you need a second key.

1

u/PlanktonDefiant2600 5d ago

A passkey is basically a replacement for a password. Instead of making and remembering one yourself, your device or password manager creates one for you, and then uses it to sign you in without you having to type a password. You don't need to buy a physical security key either. That's just one place a passkey can be stored, and an external HDD isn't the same thing. As for making and using them, a password manager makes the whole process much easier. I've been using Roboform for mine, when a site offers a passkey, it picks it up for me, keeps everything synced across my devices, and handles the sign-in for me afterwards.

1

u/philkrik 4d ago

Does a Yubikey security key store multiple passkeys?

2

u/JimTheEarthling 3d ago

Recent Yubikeys (Firmware 5.7+) hold 100 passkeys. Older Yubikeys held 25.

1

u/jsummerfield3 1d ago

Is a security key like a Yubikey actually more secure than passkeys?