Why do I have a "passkey" on havenandhearth.com?

General discussion and socializing.

Why do I have a "passkey" on havenandhearth.com?

Postby xyzzy57 » Mon Aug 10, 2026 9:15 am

It appears that I somehow got a "passkey" for havenandhearth.com / http://www.havenandhearth.com into my Apple keychain.

Why? How? Why would I want one anyway?

Note that I'm on a desktop, lacking any kind of biometric sign in. To use this passkey, I *think* I'd have to type either the password for my Mac account, or possibly the password for my Apple ID. I can't see how this would be an improvement on having my password safe supply my haven user ID and password when I login to the haven web site. It might be a slight improvement on logging into the client, which can't be fed information directly from either my password safe or my apple keychain - but given that the client doesn't talk to the keychain, I doubt the passkey would work with it.

I don't object to passkeys per se, on devices with biometric login, but AFAICT on a classic desktop they are about as useful as teats on a boar.

FWIW, I seem to have acquired 2 passkeys I never requested. The other one was given to me by Amazon. They at least had the courtesy to email me when they created it. I found the Haven one when I finally got around to deleting the one from Amazon. (Their website warned me I shouldn't just delete it on their site - I'd get weird behaviour if the keychain remembered one that no longer existed.)

Does anyone else have a passkey from Haven, particularly one they don't recall having ever requested?

Devs, if you are reading this, can you explain how this could have happened.

And yes, I am living under a rock, happy with a simple desktop computer without web cam, face ID, or fingerprint sensor. It's a very comfortable place for me. I do have both of these on my cell phone. But I'm not going to be logging into Haven from there.
xyzzy57
 
Posts: 199
Joined: Thu Aug 19, 2021 9:41 pm

Re: Why do I have a "passkey" on havenandhearth.com?

Postby xyzzy57 » Tue Aug 11, 2026 9:08 pm

I've had time to do a little bit of research on passkeys. Implemented properly, and used consistently from/with a single "identity provider", aka something like the Apple key chain, they appear to be more secure than passwords, except of course that the code is probably newer and therefore more likely to have undiscovered bugs.

I haven't been able to find a coherent story on the security or lack thereof in e.g. a passkey created using safari on MacOS that you want to use in chrome on windows or firefox on linux. (Handwaving that "of course it's OK" is not a coherent story.)

It's also clear that, as usual, the theory is stronger than the practice - a perfect implementation of passkeys _is_ more secure than a perfect implementation of passwords. But we don't have perfect implementations in the real world.

I've also discovered that the use of biometric verification is somewhat of a red herring, at least in theory. Such methods seem to have nothing to do with the underlying passkey standards - it's just that devices having such facilities usually bolt them onto their passkey implementation, as a means of convincing users to switch, and sites offering passkeys often presume the user is on such a device, with such an implementation.

I'm still amazed to have a passkey from Haven, but am no longer expecting it to bite me. Worst case it's a crappy implementation and will let someone hijack my Haven account - but such a person could already do that via various attacks available with passwords, even if they are perfectly implemented. (And they still can - having a passkey as well as a password won't protect you from password based attacks.)
xyzzy57
 
Posts: 199
Joined: Thu Aug 19, 2021 9:41 pm

Re: Why do I have a "passkey" on havenandhearth.com?

Postby mvgulik » Wed Aug 12, 2026 12:44 am

Nice to read something that lines up with my general thoughts on the subject.
mvgulik
 
Posts: 4052
Joined: Fri May 21, 2010 2:29 am


Return to The Inn of Brodgar

Who is online

Users browsing this forum: Claude [Bot], Donni, Google [Bot], Yandex [Bot]