UPDATE: Reviews section refreshed, redesigned, searchable: Go take a look
As I'm sure all of you are I keep getting asked to create a Passkey to login to many websites. So far I've just clicked set up later.
I understand a Passkey uses a bit of info held on a companies server that then matches with your fingerprint/face ID.
But what happens if I get run over by a bus and my wife needs access to said websites!? Facebook, subscriptions etc.
With a Passkey is it 100% attached to me? And only I can use it?
Same as when you die taking your password with you. There’s always a recovery method. Whether the company involved is helpful to those you leave behind is another matter.
It's more attached to your device, is my understanding. Or your password vault, if you decide to store them there.
So up to you who you grant access to those - you can have more than one fingerprint registered.
What confuses me is they don't replace your password; that's still there with any security vulnerabilities it may have. It's in addition. So 2FA on your password login is still a good idea.
Thread hijack. Is it possible to set things up so that, if I happened to die unexpectedly, my family could access my bank details, etc., but not be bothered with the boring details of my browsing history?
Same as when you die taking your password with you. There’s always a recovery method. Whether the company involved is helpful to those you leave behind is another matter.
Passwords and passkeys are for your access to your online access to an account. If you die your exectors or whoever mops up after you don't just log into your accounts and rummage around in them - basically passing themselves off as you. They contact those companies as the executor with the relevant documentation to arrange for the accounts to be closed. They don't need your login details to do that. Even in instances where I've had access to someones account as a POA I had MY login to that account (and my brother who was joint POA had his own login) - we didn't just log in the account pretending to be them using their credentials.
if I happened to die unexpectedly, my family could access my bank details, etc., but not be bothered with the boring details of my browsing history?
they just need a list of the accounts - the banks involved will simply want to close those accounts and move the money into an agreed executors account. In my recent experience for sums less that £50k the bank didn't even want to wait til we had grant of probate to do that - they just required a death certificate. Theres also sense in not taking any actions straight away as one of the first things someone has to do as executor is deal with any overpayments or refund from things like standing orders going into or out of the account. So doing nothing for a few weeks - other than acting to stop further payments in and out - make it easier to track who needs to refund you and who needs payments returned.
With a Passkey is it 100% attached to me? And only I can use it?
No, it's 100% attached to a device, or I suppose being pedantic, a specific app/browser on that device. So you might have 2 or more passkeys set up... one from phone, and one from laptop, etc.
But you'd also have backup setup, with 2FA for when you lose the phone (for example). Passkeys only make little sense imho.
But then there's 2FA and there's 2FA. If SMS is the chosen 2FA method, then it is about as secure as writing your password down on a sticky note. Google/MS Authenticator or Yubikey etc. would be much better, or any other app or password manager that does OTP code. My preference is Google app over MS because it needs no 4G/Wifi connection.
If you cark it, then the executor does whatever they need to do to access critical accounts, once probate has been granted?
If it's a joint account, then they will have their own access?
Theres also sense in not taking any actions straight away as one of the first things someone has to do as executor is deal with any overpayments or refund from things like standing orders going into or out of the account.
Yeah. When I informed my mum's bank of her death the first thing they did - whilst I was still standing in the branch - was freeze the account. Nothing goes out, nothing comes in. This, with the benefit of hindsight, was a mistake.
I'm not talking about the main financial services - I know that would have to go through a legal process. My current account is in my name only but the bulk of our cash is in a joint account.
It's more logging into the Octopus, Talk Talk account and all the other random stuff you have to deal with on a regular basis.
The main one of course is an email account - if you can't gain access to that you are pretty screwed.
At the minute all key passwords are 'securely' written down! 🙂
I logged into something on my partners computer the other day and it sent an SMS 2FA. Because her phone is linked to that computer it automatically completed it *even though she wasn't home at the time* which rather surprised me. I'd always assumed there as a check that your phone was 'local' (same wifi network? BT connection? direct wifi?).
Nope.
It's more logging into the Octopus, Talk Talk account and all the other random stuff you have to deal with on a regular basis.
I imagine I'll get absolutely shot down in flames here, but I've written my mobile phone pin code on the paper copy of my will. Frankly, once I've turned up my toes, I won't give a ****.
