Do mandatory passkeys bypass traditional two-factor authentication?
Mandatory passkeys can completely bypass traditional two-factor authentication with a single button click if a computer is left unlocked. This leaves systems vulnerable to internal actors and agents that can inflict damage regardless of scoped access or marketing claims about sandboxing.
What people tried
Every workaround mentioned in the threads below. We haven’t tested any of them — and nobody here is claiming they worked.
- 1patching exploits as soon as possible
- 2utilizing network segmentation
- 3moving to strong encryption 2FA, and current best practice password policies
- 4planning for failure as a foregone conclusion and planning for recovery
- 5Using hardware passkeys like Yubico or Token2 that require a PIN
- 6Falling back to traditional security methods like password reset by email where supported
- 7Storing passkeys in password managers that require biometrics or a PIN
In their words
Unedited, grouped by where they were said, most upvoted first within each place, each linked to the thread it came from.
“I have not seen the attack I am worried about. agent poisoning at the LLM level. The attacker will already be in the building and even if access is scoped correctly damage will occur.”source ↗
“how did it find credentials if it was sandboxed? Or is sandboxed just a general term to make CEO's and investors think the latest Frankenstein just broke its chains”source ↗
“A bunch of tools we use are rolling out passkeys as mandatory instead of password/2FA requirement.”source ↗
“A user leaves their computer unlocked. A bad actor enters the user's email address on their computer. They click the one button to use the passkey. 2FA never played a factor in that login, it's barely even one factor...”source ↗
Where this came up
People with this problem also raised
- 4Locked out of new network switches because the consultant left
- 2Why does accounting software force logins for every company file?
- 6How to clean up a hacked website and fix malware
- 2Why is rushed custom software so insecure?
- 3Why do former employees still have active logins?
- 2How to migrate away from 1Password safely