How can passkeys be protected on machines that don’t have biometrics?

I recently found out that on macs without biometrics (no hardware, or not enrolled by user), that passkeys are still available to create and use.


But there doesn’t seem to be a mechanism that protects them. If I want to use the passwords I have stored on my Mac, I at least would be ask to type my password. But for passkeys, it doesn’t. I suppose it’s because it’s going against the philosophy of passkeys to have anything to do with passwords. But then, it’s just one less barrier against attacks on non biometrics protected systems? Why allow passkeys on systems not protected by biometrics? It just makes a hole in security…


BTW, I do know that biometrics is not bulletproof security. If I have the password on someone’s Mac, I can add my own biometrics to use the passkeys. But for this case. I still need to get the password of the account.

Posted on Dec 1, 2023 9:01 PM

Reply

Similar questions

11 replies

Dec 2, 2023 1:35 AM in response to AD2015

As an admin, I am wary of allowing passkeys now on services, knowing some Mac users might end up unknowingly set up passkeys in systems that offer a control mechanism like biometrics or even the account password. It just makes it easier for attackers.


Also, I don’t believe there’s an option for me to block passkeys on these systems via MDM, which IMO would be ideal. No biometrics should mean no passkeys access, or at least should have required the macOS account password to unlock access to them.


I provided this feedback to Apple, and I await to hear an explanation.


I hope, I am just missing some information. Otherwise, this is a glaring bug.

Dec 5, 2023 1:58 AM in response to AD2015

I found out that without enabling biometrics on a Mac, it's a similar thing with just passwords. It will make the password in the built-in password manager in macOS available without prompting to input the user's macOS account password.


Only when biometrics is enabled does it provide password as a fallback option to access the password or passkey.


I've been using MacBooks with TouchID for a long time, I failed to realize this.


The message I am getting is that if you don't care enough to have biometrics, Apple will offer access to credentials in a Mac with the lowest possible barrier.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

How can passkeys be protected on machines that don’t have biometrics?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.