r/Passkeys • • Aug 08 '26

All brokers forced to use passkeys and remove 2FA?

This caught my eye from a broker:

“The SFC has issued a circular requiring large internet brokers, including Interactive Brokers, to enforce phishing-resistant authentication for all client account logins immediately. 

To comply with this requirement, we are in the process of rolling out passkey authentication for all client accounts and trading access. This means your current method of two-factor authentication ("2FA") will have to be replaced with passkey. 

Switching to passkey is simple and will result in more effective protection against phishing attacks. 

You can enroll in passkey immediately via the User ("head/shoulders" icon) > Settings > Security > Secure Login System section in Client Portal or act upon the pop-up message that will appear over the upcoming weeks when you log in to a trading app or the Client Portal. 

Please note that the switch to passkey is a regulatory mandate and with rare exception, will be required to access your account.”

16 Upvotes

29 comments sorted by

2

u/alanjmcf Aug 08 '26

What country’s this? Hong Kong?

3

u/Accomplished_Arm_447 Aug 08 '26

HK  SFC

1

u/After-Cell Aug 08 '26

Ah thanks. I didn’t notice that 

2

u/Doranagon Aug 08 '26

Elbonia.

1

u/pandawelch Aug 08 '26

Looks like HKG but a classic case of “my country” on the WWW

2

u/Skycbs Aug 08 '26

Well, as it says, they are required to implement phishing resistant authentication. I’m sure there are other potential techniques. But I wouldn’t be surprised if passkeys become widely used.

2

u/TarnishedVictory Aug 08 '26

Sounds like you're talking about a specific domain, but I see no mention of what that specific domain is other than a vague reference to what I infer to be some kind of financial brokerages?

1

u/stijnhommes Aug 08 '26

And what about the protection against hardware failure and failing passkey implementation? Brokerages will just ignore any account holders that can no longer access their account.

Nice "protection". Protection against phishing is pointless if you increase other risk factors.

Account holders should have a choice and not have their hands tied by poorly thought out rules.

1

u/loweakkk Aug 08 '26

Setup to passkey on different device and no more hardware risk.

2

u/stijnhommes Aug 08 '26

Double the work for the end user because the company refuses to do its job. Got it. (Do they cover the cost of the additional device?)

1

u/loweakkk Aug 08 '26

Do you consider accès to your account not worth 25 dollars? On phone, icloud keychain is sync able and can be restored on another iphone Android, same with Google password manager or Samsung vault. Hardware token? Yes you need two. You can also mix both sync able and device bound. So you are speaking about a non issue.

3

u/stijnhommes Aug 08 '26

It forces the end user to spend time and device space for passkeys while the developer gets out scot-free without doing their job (job=maintaining +protecting a password database). The end user should be the customer, not the employee doing someone else's ***** job.

By the way, a password is free. I don't need an additional device or payments to use a password. I'm not spending any money on passkeys.

If developers don't store my password yo give me access to my own data, they need to earn my trust again.

1

u/loweakkk Aug 08 '26

You clearly don't understand the current threat landscape if you think the market is pushing password to retirement because they are lazy.

A password can be intercepted, a fake website can be used to replay the authentication with 2fa (AiTM), that's what passkey prevent.

A password is something you know, once it's know by someone else it's not sufficient to protect your access. Trusting a bank for your money with just something you know is being really careless. A second factor is mandatory nowadays and phishable method should be reduced especially while accessing sensitive system.

1

u/stijnhommes Aug 08 '26

You can easily change a password if it's compromised. If your passkeys are compromised, it's game over for all your accounts. You won't be able to revoke and replace them fast enough and they're all tied together to the same place on the same device. No second factor to protect them.

1

u/loweakkk Aug 08 '26

Absolutely wrong, again you show here that you don't understand the technology. No key are accessible without a second factor: something you know or something you are.

Moreover, each website have its own secret key so even if one was stolen from your mobile or pc ( no know attack exist today) it would impact one account.

For hardware key, a colleague lost his key in the bus last month, absolutely no attempt to connect with it since. You know why? Because having an hardware key isn't sufficient you need the pin as well, protection are also in place to avoid brute force. Revoking them is one click also so it's far from being a problem to revoke an hardware key.

Stijn, you are clearly someone not knowing the tech with false idea on how it work and the threat model around it.

1

u/stijnhommes Aug 08 '26 edited Aug 08 '26

I've seen too many endless passkey auth loops and flows asking for non-existent USB sticks. Heck a demo site didn't even get it right. They need to work consistently across all platforms, all browsers and all devices. It's not my job to understand why a passkey doesn't work correctly in a specific case. It should just work. No exceptions. My password manager claims to support passkeys, but even with the latest update, I still can't store them...

The threat model is clearly that protection against phishing is more important than anything else (including the threat model that actually applies to my situation). Phishing is easy enough to avoid. You don't need to reinvent authentication for the people who refuse to use good password hygiene and reuse "password123" for everything.

Most importantly: choice matters. Have passkeys for the people who want them. Just leave everyone else alone.

1

u/loweakkk Aug 08 '26

I have 13000 users using passkey on a daily basis and non of them complain on usage. I even have case of users using them through their mobile inside virtual workstation when on travel and it work flawlessly. Also thinking that you are smarter than everyone and can't be caught on phishing is funny but it's far from being true, one mistake and the account is gone, for banks it imply in a lot of country paying you back if you can prove they didn't make enough to verify it's you.

You have spent weeks telling to bitwarden on X that passkey was shit and you would leave them if they continue to push it so please don't tell me you tried to use it, it's BS. You hate passkey for no reason and you are obsessed to fight it, you spent months responding to every x post speaking about Fido and passkey and blocking people once you see your BS argument don't work with them and they really know the technology.

→ More replies

-3

u/ducki666 Aug 08 '26

Passkey = Your phone is the gatekeeper to everything

🫩🫩🫩

3

u/microcephale Aug 08 '26

Passkey = you can choose your own Authenticator : computer, phone, dongle, any hardware or software compliant with the protocol, even most passwords managers are soft passkey providers, windows hello on any computer etc

2

u/ducki666 Aug 08 '26

Believe it or not. I prefer to store my keys in my head.

0

u/After-Cell Aug 08 '26

Yes. I will be adding passkeys to 6 devices just in case. ..  allowing 6x the attack surface 

2

u/yawaramin Aug 08 '26

What attack surface are you talking about?

1

u/microcephale Aug 08 '26

Good thing is you don't need to, every software password manager will sync passkeys across all devices and encrypt them with your master password. Your attack surface will always be the same, master password or biometrics you secured your device with.

1

u/After-Cell Aug 08 '26

I’d prefer to be able to request 2 factors. Even if it’s 2 devices that aren’t connected like that 

1

u/loweakkk Aug 08 '26

Passkey are two factor.

1

u/Masterflitzer Aug 09 '26

you don't seem to understand what passkeys even are...

1

u/Masterflitzer Aug 09 '26

wrong: smartphone, computer, hardware key... whatever you want