Yadis

Identity, trust and the plumbing of the web·on the home of the Yadis discovery protocol since 2005

§01  Identity & Access

Passkeys and the Lost Phone: How Passkey Recovery Works When Your Device is Gone

Passkeys and the Lost Phone: How Passkey Recovery Works When Your Device is Gone

Black YubiKey 01 / Jonathan Molina, CC BY-SA 2.0

Device-bound passkeys are lost forever if the hardware storing them fails or is stolen. With a synced passkey, the private key is stored online. Once added to a password manager, its associated accounts follow the user to a replacement or backup device.

Device-Bound vs. Synced Passkeys

The problem begins with the foundation of the passkey.

Synced passkeys are among the accounts available once the user signs in from any device. The user account acts as their credential backup location. The stored passkeys reappear even while signing in on a device that never saw them before.

Device-bound passkeys offer no security over their associated device. The private key is stored in the device authenticator hardware. Quantum computing may enumerate private keys, but breaking or losing the device accomplishes the same. The credential’s time is with the device.

Synced keys are saved to a user's account. Once the user logs in to their account, the synced passkeys appear on a new authorized device. Device-bound credentials are left behind. The synced passkey does not leave the user on a new device, but the device-bound key is not recovered..

What Happens After a Phone is Lost

If you lose a phone that held a device-bound passkey, losing the phone spelled losing the passkey. The only recovery is by parachuting back in to the service and requesting a reset there. The service has to let the user onto their account again, invalidate the lost passkey, and let them make a new credential.

For users of synced passkeys, the phone maybe gone, but the passkey is with the sync account. Sign in there on a new device and the credentials are back.

Here is the how-to for a synced user upgrading from and old Android device to a new one:

  1. Enable Account Auto Sign-in. Move on.
  2. Sign into your Google Account on the new device.
  3. Open the Password Manager on the new device.
  4. The Passkeys that were on the old device show up in the new Password Manager.
  5. Sign into the service with the passkey as you normally would.

One source did not define Auto Sign-in, and other largely did not list the Android Password Manager as a passkey-haver.

Synced passkeys can be added to a second device on the same account.

What a Second Device or Backup Key Does

The different between syncing and device binding plays out between the keys, where the difference matters is: on the new devices.

A second device is just another place to store a credential. It is a good idea, but not a guarantee. If you can sign in to the syncing service, that is the path you want. You can't just do a passkey reset on the new device.

If you require greater insurance, here is how to create a hardware-based backup key. [TO VERIFY What kind of hardware works, how to get one, what gives it the status of a backup, and spell out the process of associating it with a key or account..

In the phone-first future, it is more practical to rely on a second phone for backup keys. Be aware that the service or account proves the phone is approved. You cannot just borrow a friend's phone and sign in--the passkey will not recognize it.

When Recovery Fails

There are many ways to lose a passkey--and many ways not to lose it. If a credential dies on a failed or factory-reset device, it is gone because it was a device-bound credential in the first place.A synced or fully upgraded passkey made with a second phone or backup key has a much better chance of surviving, as long has the passkey backup and the account that authenticated the backup are not compromised.

But what if you just lost or forgot your account password? It's a harder question than you would think, and one that depends almost entirely on the way you interact with the service. In other words, Google can't even figure out how to recover one of its own passkeys from a lost phone.

The only advice is: use every means you can, and early while you can, to add a backup key.

What Services Should Offer

"Just reset your passkey" is terrible recovery advice. Well-founded services should offer three approaches when a user reports a missing passkey.

  1. Account recovery: use existing methods, like an authentication token or backup code to validate the user, then let them create a new passkey.
  1. Invalidating minimal credentials. Disabling the lost passkey minimizes the risk, and helps the user move on to an alternate auth.
  1. Allowing a device reset. The service should allow the user to reset to a trusted state so the passkeys can be used again.

No single service does all of this, and many do not to the level of backup a passkey should require.

More importantly, no major service is willing to recommend creating and storing a hardware backup key, relying entirely instead on one-time passwords or backup codes shipped after a discovery step.

Prevention

Worried about losing a phone? So are most people. Being human usually means having enough struggle that you should expect to lose a phone at some point.

Prepare yourself by having passkeys that can roam with you between devices. This should be your default, and your fallback from losing a device-bound passkey.

A recovery plan should include:

  1. Keep passkeys in your service account. Some services back it up on Windows Hello, Google Password Manager, and Apple iCloud Keychain.
  2. Enable account to a spare device. (TODO: check how.)
  3. Add an account recovery code. (TODO: check how)
  4. Know how to contact customer support.
  5. Log in to the device.
  6. Store your codes on the device.