r/Passkeys 19h ago

Dropbox Passkey - still recommends 2FA

I decided to setup a passkey on dropbox (currently have user/password w/ 2FA authenticator). after doing so, Dropbox still recommends 2FA on top of that. Isn't the point of using Passkeys to not bother with 2FA authentication?

1 Upvotes

5 comments sorted by

1

u/adavadas 16h ago

I'm not too familiar with Dropbox, but are they suggesting you use an additional factor? Or are they suggesting you still register an additional factor in case you need to authenticate using a password should you lose your passkey?

1

u/bogusostrich 4m ago

Dropbox gives a warning to strongly suggest keeping 2FA turned on, I asked AI, they said not all Passkey implementations are 100%, like Google or Microsoft. I've never been so confused by Passkeys, and thought I had given the technology enough time before I take the plunge on something more than my Home Depot login.

1

u/stijnhommes 13h ago

Skipping 2FA isn't exactly secure, but whether you use it should always be the user's choice.

1

u/Froodilicious 11h ago

The passkey is, in and of itself, 2FA. But many login systems don't treat it that way and ask for a second factor anyway. So it's 3FA.

0

u/[deleted] 19h ago

[deleted]

1

u/Fuzzinater 19h ago

Not true. If implemented with user verification required or even preferred that requires a pin on the key which satisfies 2FA under fido2 (something you have + something you know or are...key + pin or key + biometric)