That to me sounds like a disadvantage... But then I only do online shopping on a secure desktop
That to me sounds like a disadvantage... But then I only do online shopping on a secure desktop
No, because Amazon never learns or has access to your passkey (or your face or fingerprint etc). All it will know is that the specific device it setup a trusted relationship with, is being used to login, and that the user of that device has given permission for that to happen.
If someone has access to your device, then they would also need to be able to access that device with a pin, password or biometric. So if they can't do that, they are still stuffed. Even if they manage to phish you passkey it is still no use to them without access to your device.
If they can access and login to your device, then yes, they may be able to do more (depending on how they logged in), but at that point they are probably in a similar case to the one where they are logged into a device and you have used a web browser's password manager to store passwords. (or you have session cookies on your computer that keep you logged into a specific site for a period of time)
That's what I meant. If someone discovers the PIN for the computer it would be logical to try the same PIN again.
Try the same pin again on what?
The pin[1] is just for the computer - never used elsewhere.
[1] bit of a misnomer since the PIN for a computer can be alphanumeric, not just digits.
That's what I thought until I discovered that the passkey for my Amazon account was the same as the PIN for my computer (and specifically not my Amazon password). And, yes, the PIN can include letters but only if you tick the box.
Yes. Passkeys (like SSH private keys) have to be 'unlocked' before they can be used. The unlocking method can vary based on whatever you have set up (PIN, passphrase, fingerprint, face, smartcard, ...). You can safely use the same unlock method across all your passkeys (ie you don't need a unique PIN or fingerprint for each one).
Unlike saved passwords, somebody who steals your passkey can't use it without also doing the unlock step which needs access to your fingerprint/etc. That makes it more difficult for someone who attacks your machine to get a login to the website, compared with plaintext passwords.
The complications come when you're using them across multiple machines - either you set up duplicate passkeys (ie every account+machine pair needs to run the setup process, if the website allows it) or you arrange some way to sync them between systems. If you let Apple, Microsoft or Google manage them then they have proprietary methods to sync (iCloud/etc). Cross-platform syncing protocols have only recently been standardised.
Theo
If you don't want to allow your PIN* to log you in to passkey websites, you can a biometric?
[*] it isn't another number that happens to be the same as your Windows PIN, it *is* your windows PIN, which is stored in your TPM if you have it enabled.
The PIN isn't the passkey, the passkey is usually a 256 bits, the PIN just protects access to your passkeys.
Sure, but of you decide that BitWarden or Lastpass are charging too much[1], don't you then lose all your passwords?
[1] Or payment to them hiccups for some reason.
Currently, isn't it only the mega-corporations that use passkeys? So you will still need passwords for all the other websites you deal with.
Yes, I wish it would get wider adoption, not sure if it's hard to implement on the server-side?
I only use the free version.
+1
It sounds like some sort of Windows thing to me. I also use Linux (Mint) and have never been asked for anything other than my email address and a password to log in.
I also use a Password Manager (KeePassXC). It's free (I have donated) and works well.
I was intrigued enough by this thread to investigate further, so did a search on Amazon + Passkey. This was the first hit:
Selected points...
"With passkeys, you can sign in to your Amazon account by simply using your fingerprint, or the PIN that you use to unlock your device. You will not need to provide your Amazon password to sign in.
Passkeys are secure and convenient sing in options as they:
- Work on most major platforms and browsers. For example, iPhones, Android phones, Apple and Windows desktops."
So *NOT* Linux.
And...
"To enable passkeys:
I haven't checked to see if the Amazon set up is intelligent enough to see if you're using Linux and so doesn't offer a passkey as an option.
No apple, linux, android can all do passkeys ...
It sounds a lot like client certificates, which any https web server can enforce. Normally, of course, only server certificates are used in https, but both can be.
See my other reply; not sure why Amazon don't mention it.
However, I'm not certain that Linux can do passkeys as easily as Windows, Apple, etc. There's an interesting fairly recent thread here:
That seems to suggest a Password Manager which does passkeys might be more user friendly if you're using Linux than the OS itself. Unfortunately, I'm on an earlier version of KeyPassXC (obtained via Mint's software manager) which does not support passkeys. If I wanted to use passkeys, I'd have to change to the latest version obtainable from a specific repo.
I think it's just a plugin in whatever website building thingy they're using.
But the passkey rollout has been bumpy, and likely small-time websites don't want to be on the bleeding edge. Not least because they don't want any additional support burden.
Also, passkeys are being used as a power-play to keep you within the Apple/Google/etc ecosystems. Luckily, with better syncing between different platforms, that is starting to change.
Theo
As with a lot of linux, you'd need to add it in if you want it.
To use passkeys with Amazon on Linux, first ensure your browser supports WebAuthn (such as Firefox or Chromium). Install and enable a security device or platform authenticator, like a USB security key (e.g., YubiKey) or a system credential manager supported through FIDO2.
In your browser, sign in to your Amazon account and open Login & Security settings. Choose Passkey setup and follow the prompts. When asked, insert or activate your security key or device authenticator and confirm.
Your browser will store or reference the passkey. Next time you log in, select Passkey sign-in and authenticate with the security key or biometric device instead of entering your password.
Google and MS also use passkeys
Have something to add? Share your thoughts — no account required.
Ask the community — no account required