r/Passkeys

▲ 6 r/Passkeys+3 crossposts

Being bombarded with Account Recovery Requests

I am being bombarded with Account Recovery requests. Bombarded may be overstating it a little bit, but I'm getting 3-10 requests a day and oftentimes 5 or 6 in a row. Of course I hit "No" every time it asks if it is me trying to recover.

I have Advanced Protection turned on. My phone set up as a passkey. I have an excellent password that is completely unique to Google. I also changed my password just to be safe. I've logged in and I recognize all of my connected devices.

I am pretty sure that I haven't been hacked, but I am being targeted. The messages that come along with the account recovery prompts state that my password hasn't been compromised, but the persistence of the hacker still worries me. It's been going on for about 2 weeks. I suppose the hacker is attempting to guess my passwords using old compromised ones bought off the web. I am mostly afraid of inadvertently hitting "Yes" to a prompt just one time and then I'm cooked. I don't THINK that completely opens me up, but I'm not 100% certain. I plan to get a physical security key, but I don't think that bypasses the Account Recovery prompts either.

Any thoughts or suggestions? Thanks.

reddit.com
u/This-Cardiologist525 — 19 hours ago

Is this problem solvable?

Hello,

I am a newbie when it comes to passkeys.

So when a collegue has a project connected with his own Microsoft Windows Account (Passkeys are saved there)

Is there a way to transact them into Android? I made a Account with WISE on my PC but it wont let me login now, because its another plattform?

Do I have a choice to fix it or is it something support related now?

Sorry, just not a fan of those passkeys. If you ever lose access to your windows everything would be gone?

reddit.com
u/BigApe040 — 4 days ago
▲ 60 r/Passkeys+1 crossposts

📥 Introducing receive.link: anyone can send you files encrypted to your YubiKey [Open Source]

Hey r/YubiKey!
About a year ago we launched FileKey here (encrypt files with passkeys), and the most common request was: can people send files to me?

So we built receive.link. It allows you to receive files only you can open.

How it works: you share one link. Anyone can send you files through it, right from their browser, nothing to install or sign up for. Files are encrypted before they leave the sender's device, to your passkey, so no one can see what's inside. You get an email when something arrives, and we actually send that email without ever storing your address (it's a neat trick!). The sender never sees your address either, so you can share your link with strangers safely.

It's free to start and open source. Would love feedback if you have a moment, especially from this community, since your feedback shaped FileKey a lot.

Key Features

  • Share one link, and anyone can send you files (senders need no account, app, or key)
  • Files are E2E encrypted in the sender's browser, and only your passkey can open them
  • Up to 5 TB per file
  • No accounts, no passwords, no tracking
  • Free to start, then a penny per GB you download. No subscriptions
  • Files auto-delete from the server after 7 days (or when you delete them)
  • Senders never see your contact info
  • Free and open source (GPLv3), client and server both
  • Works with YubiKey 5 series via passkeys (FIDO2 PRF). Synced passkeys (Apple, Google, 1Password) work too

You can try it at receive.link or view the code on GitHub.

u/RockwellShah — 6 days ago
▲ 3 r/Passkeys+1 crossposts

Phishing-Resistant MFA: Planning Your Passkey Rollout in Microsoft 365

There's a ton of resources out there from great people in the space but I wanted to share my thoughts and typical process for helping organisations adopt passkeys. Hopefully it helps someone out.

The blog covers:

  • Info on the Microsoft notification to retire SMS and Voice, and why
  • The different types of passkeys available
  • Strategy and rollout approach
  • Considerations for legacy systems
  • Considerations around downgrade attacks

Phishing-Resistant MFA: Planning Your Passkey Rollout in Microsoft 365

u/NateHutchinson — 6 days ago

iPhone got stolen, and my android asks for a passkey

so my iPhone got stolen a few days ago, I was able to retrieve my emails and even verify my TikTok account with it, but it still asks for a passkey where I have no idea to find it.. I am only logged into my PC and it wont even scan the QR code. I need help.

reddit.com
u/BabyKriel08 — 6 days ago

Passkey issue on FIDO card on Android

I am playing around with a Cryptnox FIDO card. The card works fine on IOS over NFC but I running into issues on Android 14 and 16.

On IOS I can log into Google using the passkey on the FIDO card. On Android, I get the something went wrong. I tried the Fidobridge app but it errors out with a limit reached error. I am using brave on both platform but other chromium browser fails, too.

On Android, I also can’t save the passkey properly. It saves the non discoverable key into Google instead.

Anyone have an idea what’s going on?

Update
The issue seems to be related to lack of support for ctap2 for Android. Android 16 is supposed to fix the issue but ctap2 still doesn’t work on the most recent Samsung android 16. The issue is that no prompt for the pin appears.

Installing fidobridge but the issue with Google remain

- I can login into ms, google and bitwarden using the Cryptnox card passkey on iOS
- I cannot login to sites using passkey on android without the Fidobridge.
- I can log into webauthn.io, ms and bitwarden using the Cryptnox card with the Fidobridge on android but not Google.
- I can log into webauthn.io, ms, bitwarden, and google using a yubikey with passkey and fidobridge.
- The error return is LIMIT_EXCEEDED. I don’t know what this error is. It’s does not seemed to be a rate exceeded

reddit.com
u/paulsiu — 7 days ago
▲ 18 r/Passkeys+2 crossposts

Chrome's latest passkey vulnerability is a classic example of why Google sync is a trap

Unit 42 just dropped research on a Chrome attack dubbed 'Pass-Ta-Key', and it highlights everything wrong with Google's ecosystem strategy.

If malware infects a Windows PC, it can grab the master key from Chrome's process memory, pull WebAuthn credentials out of Chrome's LevelDB sync database, and hijack synced passkeys. The attack manipulates the cloud authenticator to bypass PIN prompts without triggering alerts.

Predictably, defenders are hand-waving this because "malware means you are compromised anyway." I do not buy that logic. Passkeys were originally sold to us as hardware-isolated and immune to credential dumping. Google broke that security boundary just to lock people into Chrome sync. They took an open web standard and turned it into another reason to stay logged into a Google account.

Yes, strict server-side verification checks can stop this, but most websites implement WebAuthn lazily anyway.

This is precisely why de-Googling your authentication layer matters. Storing private keys in a big tech browser sync database for convenience is a mistake. I keep my credentials on standalone hardware tokens.

Source: PCMag, link in comments

reddit.com
u/EnthusiasmRoutine — 10 days ago
▲ 7 r/Passkeys+1 crossposts

My passkeys are locked?

I lost my acc to a phishing scam (I know I’m slow) and I still have a passkey on my phone (Apple iPhone 15 running iOS 27 developer beta. Risky I know) and the passkey is on google passkey “manager” and it keeps saying this. How do I stop it or unlock my passkey?

u/PastySunset — 11 days ago
▲ 0 r/Passkeys+1 crossposts

Wordless Passkey

Hi so I am going into my 2nd or 3rd week on OF, and im having incredible difficulty adding my bank card onto my site to be paid. It wants me to create a wordless passkey which I have on both my devices I work off of. I've got to be missing something but I don't know what. PLEASE PLEASE HELP! I'm getting paid and cannot access my $$$.

reddit.com
u/Shanelle-Aaliyah — 8 days ago

Google forcing passkey that would be 10000km across the Atlantic if it even exists at all

It's possible that I created a Windows passkey unintentionally on my PC. I cannot log into my gmail to get a verification code for my bank account and check if I've missed a payment. I cannot get into any of my accounts. It just goes log in->QR code pops up and I cancel->verify with my password->QR code pops up again and I cancel-> only option left is "use passkey". I am technically logged in to my browser now, but if I try to check my passkeys or use Gmail, it just goes back through this same loop again.

reddit.com
u/117-night-hawk — 11 days ago

Cant log in due to passkey and support sucks

Ok basicly I have tiktok only on my computer and ipad browser. I need to acsess it on my ipad app but when I log in it says I need a passkey which is like a qr code from another device. But there is no device which i can use that uses passkey. And a few days ago after hours I was able to log in via my safari browser. But I cant remember how to do it anymore and I tried again but still nothing, if anyone knows how please help me I need to acsess the app specifically bcs the browser version sucks and i cant acsess other devices from these 2 atm. tiktok tickets and supports r useless for me and havent changed anything. Thank you!

reddit.com
u/Durrmatohead468 — 9 days ago

All brokers forced to use passkeys and remove 2FA?

This caught my eye from a broker:

“The SFC has issued a circular requiring large internet brokers, including Interactive Brokers, to enforce phishing-resistant authentication for all client account logins immediately. 

To comply with this requirement, we are in the process of rolling out passkey authentication for all client accounts and trading access. This means your current method of two-factor authentication ("2FA") will have to be replaced with passkey. 

Switching to passkey is simple and will result in more effective protection against phishing attacks. 

You can enroll in passkey immediately via the User ("head/shoulders" icon) > Settings > Security > Secure Login System section in Client Portal or act upon the pop-up message that will appear over the upcoming weeks when you log in to a trading app or the Client Portal. 

Please note that the switch to passkey is a regulatory mandate and with rare exception, will be required to access your account.”

reddit.com
u/After-Cell — 12 days ago

Google Passkey - Something Went Wrong

Hi, I'm using my iPhone Passwords for Passkeys and want to log in with my saved Google passkey to my account on Win11 PC Vivaldi, but keep getting "Something went wrong" if I choose the passkey option. No QR code is showing up, just this error. What is wrong with my setup?

reddit.com
u/dreynreh — 9 days ago
▲ 2 r/Passkeys+1 crossposts

Fingerprint Phrase

So my online identity was hacked. Best way I can describe it.

They literally changed my login username and email account associated with it on my laptop computer. I was either using my phone or TV at the time.

I'm sure y'all know but password/ pin your smart TV 😊

So I've gotten pretty involved in online security using bitwarden, as far as user interface, I'm not finding it. Super friendly.

This specific question is reference to fingerprint phrases

Between the app and getting rerouted to the website to do 2fa things. And honestly, I can't even remember what third one I clicked, but I have three different fingerprint phases. Given to me from bitwarden

And only one showed up on my phone (via notifications) and it has the wrong fingerprint phrase. Andis asking me to confirm if it's me

What does this mean? What should I do? Any input is appreciated.

reddit.com
u/Budget-Bug442 — 12 days ago

Cannot create Google passkey on Windows PC

I don't know if there's some sort of issue on my systems or whether I'm just misunderstanding something. I've recently started using passkeys, my intention is to always have keys on more than one device (Android phone and a Windows PC) so I don't have a single point of failure. I am currently not using a 3rd party password manager or hardware key. For the passkeys on Android, I'm using Google's password manager.

So far all has been good, but I've encountered a problem with Google:

I have 2FA turned on, which prompts confirmation via my phone when logging in to my Google account on Windows (I typically keep "Remember this device" off so confirmation is required whenever logging-in. This makes me nervous, as in the event I loose the phone, I won't be able to get the authentication (I wouldn't be complete knackered as I do have recovery codes available).

I thought that it should be possible to create a Google passkey on my Windows PC (thinking this would bypass the 2FA requirement, or at least let me use a passkey on Windows instead of my Google password).

Under Windows on Edge, logging in to Google>Manage your Google account>Security & sign-in>Passkeys & security keys:

-I was expecting to be able to create a passkey here, and indeed there is the option to "Create a passkey"

-clicking that just generates a "Something went wrong. We weren’t able to save your changes. Return to your account settings, and try again." error.

The only passkey listed under "Passkeys" in the Google account manager is one for the phone, "Created automatically by Android".

Any ideas? Should it be possible for me to create a Google passkey for logging on using my Windows PC?

Thanks

reddit.com
u/NobodyElectronic9970 — 11 days ago