“Passkeys,” the secure authentication mechanism built to replace passwords, are getting more portable and easier for organizations to implement thanks to new initiatives the FIDO Alliance announced on Monday.

  • @_bcron_
    link
    English
    0
    edit-2
    7 hours ago

    I’m not in software but from what I read the importer sends a request and that request is used by the exporter and importer to encrypt and decrypt, so I think there’s a way to tweak the whole process a little and instead have both the exporter and importer ask Netflix or whoever to provide a key as opposed to using the request. Could be wrong tho

    • umami_wasabi
      link
      fedilink
      English
      5
      edit-2
      6 hours ago

      That’s not how Passkey, and the underlying WebAuthn works.

      (Highly simplifies but still a bit technical) During regiateration, your key and the service provider website interacts. Your key generated a private key locally that don’t get sent out, and it is the password you hold. The service provider instead get a puclic key which can be used to verifiy you hold the private key. When you login in, instead of senting the private key like passwords, the website sent something to your key, which needs to be signed with the private key, and they can verify the signature with the public key.

      The CXP allows you export the private key from a keystore to another securely. Service providers (Netflix) can’t do anything to stop that as it doesn’t hold anything meaningful, let alone a key (what key?), to stop the exchange.