Skip to content
Passkey Jack's conference talk
Archive.zip
93.9 MB

Reference materials

Demo

Resources


Distributor
Solution provider (50 of 1000 in australia)
Select tier
revenue 25 000 month
billing
3(majority), 4(advances), +5(partner login apportunity)
jumpstart (strartup migration to AWS, app development, modernisation) as Advanced
>>> recognition:
partner originated opportunity:
ACE - log the customer
MRR
partner opportunity
strart-up customers
SMB (small media buisness)
Financials
Enterprise
APN not discounts

AAA:
conflicting requirement

Talk plan


Why is the hype
Goole Apple and Microsoft commited to implement FIDO2
multi-device public key
could be backed up and replicated
point to point security
security spectrum
not repeating apple amazing talks:
What is Passkey
brief overview
public key cryptography - no weak password
bound to origin - no phishing
cross-platform and cross-ecosystem and cross-device sync- enables account recovery
zero trust to 3rd party, you have to trust platform: browser and OS
familiar US inspired by password managers
DPK provides context for higher security
save from server leaks
Passkey vs passwords
security vs convince tradeoffs
weak passwords
fishing
reuse passwords among websites
too many to remember
as soon as you remember you have to rotate or forced to rotate your passwords
password transfer via network while registration or password reset
passkey vs OTP SMS
long wait
expensive
phone could be stolen
SIM cards are not protected, all you need to know is name and address
phishing
passkey vs 2FA
complex
expensive
hard to restore
hybrid, ask only on new devices
MFA fatigue (teenage attack), push notification push too much and accidentially press “yes”
passkey vs Youbikey (FIDO vs FIDO2)
you need at least two hardware keys (Apple required it)
whenever register new service you need to register second key from safe
it could be stolen
you can lost it
you have to have it with your
order from original trusted vendor, Youbikey is not available in Austrlaia
YoubiKeys 5 now can generate and store 25 passkeys, FIDO1+
Passkey vs Sign in With Apple
Sign in with apple is platform depended
Sign in with apple is tighly connected to your apple ID
could be deprecated in future beacues of Passkey (no new talks about that on WWDC or updates)
could be used together on your apple devices
What is Passkey
FIDO2 (WebauthN and CTAP)
regular and hybrid flow (login with other device)
cross-platform first class sign in expierence
not just QR code
CTAP2 from FIDO
local key agreement
proving proximity
establishing end-to-end ecrypted communication channel
sign in
require platform support
bound (embedded_ authenticators): biometricts and PINs, and external (roaming) authenticators: FIDO security keys, mobile devices, wearables
keys sync (icloud, google, 1password)
don’t need username
bluetooth should be enabled
CTAP1 (2FA only) and CTAP2 (passwordless and 2FA)
Passkey could be used as FIDO1 device with existente sites with no code change
Passkey has a device info boud to auth request, the same passkey + device info could identify that the login is from new device and trigger conditional 2FA
Share passkey
Advantages for business
faster login
lower bounce rate
Disadvantages
learning curve (your role in it)
user account restore and reset (aooth could help)
not widely supported (aooth could help)
rely on your phone security (your iCloud password), which is yubikey
because passkey is saved in your iCloud, anuyone could buy an iPhone and login to all your passkeys
passkeys should be supported on your phone
don’t have advanced features as password mangers: share passwor4ds, password delegation, auth groups
Apple adds sharing with AirDrop, but not centalised
managed environments
ensure passkeys only syunc to managed devices
stroe passkeys created for work in icloud keyachanein og manged accounts
proof the passkey has been created in managed device
managed passkeys could not been shared
Mac OS Venture and iOS 16 only
Want to print your doc?
This is not the way.
Try clicking the ··· in the right corner or using a keyboard shortcut (
CtrlP
) instead.