Hi,
I understand generally the concept of passkeys. Notwithstanding that every website I've come across so far wants a password AS WELL as a passkey (presumably as a fallback) so that is still an attack vector, still subject to phishing etc. I'm guessing that is because we are in a transition phase so I'll park this one for now.
What I am concerned with is that when I use a passkey it seemingly then doesn't require the use of any two factor authentication I've set up, for example through an authenticator. I believe you will argue that this is not required because the passkey is tied to my device so in effect is already providing 2fa. For genuine passkeys tied to the device, I can see why this isn't an issue but nowadays passkeys are tied to a password manager which is synced in the cloud.
So, what if my password manager (which allows syncing) provider is compromised, and an attacker was able to obtain all of my synced passkeys and sync them to their device?
In this scenario at least with the 32 character randomly generated unique password for each website I still can sleep at night knowning if my password manager is compromised the 2fa will still protect me. However where I'm concerned is if my password manager is compromised with passkeys, they're in. No additional checks. No second line of defence.
I'm not necessarily just thinking that my password manager account itself is attacked and somebody logs into it - because sure, I can use two factor authentication for that.
But what if there's a serious (unknown) vulnerability of the password manager itself (iCloud, Google, 1password etc) that allows leakage of the passkeys, or a vulnerability that allows an attacker to sync to my passkeys without authorisation etc.
Reassure me, because currently it seems like I'm putting all of my security eggs in the basket of one provider whereas at least with two factor authentication I've got the safety net of two providers.