Skip to main content
Open for votes

Add Passkey support to online/app services

Related products:Online account

Blastoise186
Plan Zero Hero

Passkeys are really cool - not least because they can replace passwords completely!

It’d be pretty sweet if I could use them with OVO’s stuff...

10 replies

Firedog
Plan Zero Hero
Forum|alt.badge.img
  • Plan Zero Hero
  • 2096 replies
  • October 3, 2024

Explanation, please. What’s the difference between a password and a passkey? Or rather, how does one replace the other?

I hope you’re not talking about another bit of kit to lose ...


Blastoise186
Plan Zero Hero
Forum|alt.badge.img+1
  • Author
  • Plan Zero Hero
  • 7974 replies
  • October 3, 2024

Passkeys are a form of Passwordless authentication - long story short it lets you use biometrics instead of passwords.

External keys such as Google Titan are available, but optional. You can do it using your device built-in features if you prefer.


Shads_OVO
Retired Moderator
  • Retired Moderator
  • 465 replies
  • October 3, 2024
NewOpen for votes

Firedog
Plan Zero Hero
Forum|alt.badge.img
  • Plan Zero Hero
  • 2096 replies
  • October 3, 2024
Blastoise186 wrote:

Passkeys … lets you use biometrics instead of passwords.

You can do it using your device built-in features if you prefer.

 

Isn’t that what the Fingerprint option in the OVO Energy app does?


Blastoise186
Plan Zero Hero
Forum|alt.badge.img+1
  • Author
  • Plan Zero Hero
  • 7974 replies
  • October 3, 2024

Nope, different system.

The one in the app currently works only in the app and doesn’t do proper FIDO WebAuthn. Passkeys replace Passwords completely and work across devices.

The device that holds the Passkey can also beam tokens to other devices to log those in too if needed.


Firedog
Plan Zero Hero
Forum|alt.badge.img
  • Plan Zero Hero
  • 2096 replies
  • October 3, 2024
Blastoise186 wrote:

The one in the app currently works only in the app ...

 

Errr … sorry to be so dim, but isn’t that the whole point? I should hate to think that because I signed into my electricity account that I was also signed in to my bank account without actually doing anything. Further, that if I signed in on my phone, I later discovered that I had simultaneously been signed in on - say - my son’s computer because I once used it to demonstrate how my account worked. 

I’m all for convenience, but this sounds really dangerous to me. 


Blastoise186
Plan Zero Hero
Forum|alt.badge.img+1
  • Author
  • Plan Zero Hero
  • 7974 replies
  • October 3, 2024

Yes and no. The idea is that Passkeys replace the existing methods. But each Passkey generated works ONLY for the domain/app it’s been generated for. The one for OVO won’t work on the bank for example!

You must also approve every single attempt, every single time.

https://www.youtube.com/watch?v=2xdV-xut7EQ

Long story short, it’s basically an expansion of the fingerprint unlock that you get with apps. It just makes it so that said fingerprint unlock works on desktop too.


Shads_OVO
Retired Moderator
  • Retired Moderator
  • 465 replies
  • October 3, 2024

Hi @Blastoise186,

 

It sounds like an interesting idea. I’ve changed this from new to opened to vote. 

 

I’ll also ask internally to see if our app team would find this useful. 


Blastoise186
Plan Zero Hero
Forum|alt.badge.img+1
  • Author
  • Plan Zero Hero
  • 7974 replies
  • October 3, 2024

No worries! This will probably take more than just the app team to implement. It’d need to be done for the entire authentication system so that Web and Mobile can both make use of it. :)


Nukecad
Plan Zero Hero
  • Plan Zero Hero
  • 789 replies
  • October 3, 2024

More about passkeys if you don't know what they are

https://www.wired.com/story/stopped-using-passwords-passkeys/

The article is titled “I Stopped Using Passwords. It’s Great—and a Total Mess”.

Make your own mind up.


Reply


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings