Quicken needs to support passkey login to accounts now. I already have one institution that only accepts passkey logins
My HealthEquity HSA is the only account I have that is requiring passkeys, so until Quicken Simplifi adds passkey support, I'm unable to add my account to Simplifi. I expect that other banks and brokerages are heading in a similar direction. Thank you for your attention on this!
Agreed on this for HealthEquity! I don't see any other way to bypass it. Maybe there can be a browser-based authentication that then puts you back into Quicken?
This Product Idea regards Quicken Classic. Quicken Classic and Quicken Simplifi are 2 separate and non-compatible personal financial planning Quicken platforms. Since you are using Simplifi you might want to go to the Community for Simplifi and posting this improvement idea for Simplifi. You can read more about how to access the Quicken Simplifi Community and how to submit ideas there via this link: https://support.simplifi.quicken.com/en/articles/3828518-give-feedback-or-suggest-features-in-quicken-simplifi .
I agree that there is a trend that is starting to head down this path of requiring passkeys instead of traditional logins. It's just really been getting started over the last 1-2 yrs but indications are that this will start becoming much more prevalent in the not too distant future. Perhaps Quicken is already involved in this and I'm guessing Intuit needs to be as well but it is good to post this idea to help ensure this need is or gets on their radar.
I would also like to see passkey support added so that some of the accounts that I've had to switch to manual maintenance can be updated using OSU again. HealthEquity is just one of several for which this is now the case.
Quicken developers, please consider implementing passkeys on your website and also the connectivity to accounts in Quicken and LifeHub. Passkeys are one way to implement phishing-resistant authentication and are inherently more secure than text messages or emails. Tycoon 2FA is still operating and will continue to try and intercept and steal information. We need a way to connect to our financial institutions that have already implemented passkeys which are required to login.
I also would like to join LifeHub but do not feel comfortable entering my Personal Information to possibly have it compromised by a man in the middle attack like Tycoon. It is just a matter of time, before someone clicks on a phishing link by accident as they are convincingly good at their phishing emails and fake website designs even more now that AI plays a part.
Is there an update that can be shared on this topic and whether it is in the current sprint or increment for this year and what priority it is assigned?
Voted and agree.
Most FIs that have implemented passkeys, still support passwords. But I have two FIs that switched exclusively to passkeys. They no longer allow, support or accept passwords. And neither provide QFX downloads. Hence these accounts are now disconnected in my Quicken data file. Fortunately in my specific case I only have a few monthly transactions that I can enter manually. If this trend continues faster than anticipated, there will be no way to use Quicken downloads and therefore both, Quicken and users will suffer.
A note to the Moderators: IMHO Quicken should not wait for more votes on this, rather encourage the teams to take this seriously given that it may take a year+ in collaboration with Intuit to implement it. Assuming Quicken is already working on this, then it will be helpful to accordingly update the status of this idea post. Thank you.
This forum is for the desktop Q products. You're referencing Simplifi, which is an entirely different product, with a separate forum.
I.E., you're barking up the wrong tree.
Click SUPPORT at the top of this page to be directed to the Simplifi site.
I agree with BK. Implementing passkeys is vital, but if you leave password login in place also then you are leaving the front door unlocked.
Agreed!!
@tlpwis , I suggest to click on the vote button at the top of the post to increment the vote count. Unless I am mistaken I think the count was 21 yesterday before your comment and still is 21 now. Quicken requires about 50 counts (not comments) to consider the idea. Thank you.
I agree that passkey support or authenticator app support is necessary. I have two financial institutions that have moved to these and quite frankly, with all the data breaches out there, password/user id combinations are a disaster waiting to happen.
From chat just now with HealthEquity…
Just so people know. If the financial institution supports Express Web Connect + this isn't an issue because the "login" is changed to the secure OAuth system which was designed to be a secure system for programs/computers connections.
So, this basically a "pretend you are the user" problem.
And this breaks when talking about passkeys. They aren't "passwords". If they were then they wouldn't be adding any more security.
Whereas it seems to me that Simplfi might be able to do this (but I don't think so), I'm highly doubtful that Quicken Classic can as I learn about how passkeys work.
The whole point seems to be that they have ensured that the user is correct and that there isn't any "middleman" to steal/break into the communications.
They ensure the first part by confirming the user is "present". In the case of a web browser, they are the "WebAuthn" which invokes the OSes checking that you are you with things like Windows Hello. The key to understand here is that Quicken (the program) could work as a WebAuth, but if it did, it would be the "endpoint", it can't do the authorization and then "forward it" to the Intuit server. If this was Direct Connect where it was talking directly to the financial institution then this would be fine, but it isn't. The flow is Quicken (the program) ←> Quicken server ←> Intuit server ←> financial institution.
Where Intuit sits in this flow, they can't directly talk to the user, and that by definition make them a "middleman" program, which isn't allowed for the very reason that they have to ensure that there isn't any "middleman" to be secure.
And circling back to Simplifi even though this is really a question for their support, I'm fairly confident they are in the same boat for these financial institutions.
You make a really good point. I don't really know a lot about passkeys. I had always simply assumed that passkeys were really nothing more than a more modern replacement of passwords, kind of like how some businesses replaced "passwords" with "PINs". This thought was also reinforced for me by some of the things I've read stating that I can use my PW manager app to also manage passkeys. So, for me it has been rather confusing.
But with much of the financial industry now migrating away from the EWC connection method and implementing the EWC+ connection method this passkey issue becomes moot. This is because the actual user authorization process takes place on the financial institution's (FI's) website, not in Quicken. As I think about it some more, EWC+ might just be Quicken's and Intuit's response to passkeys. If so, that means that it is the FI that needs to contract with Intuit to implement EWC+. And implementing this type of authorization process (which seems to be slowly becoming the new industry standard) would also be applicable toward the FI resolving passkey authorization issues with most other 3rd party financial planning/reporting applications/aggregators, not just with Quicken.
If EWC+ is indeed Quicken's and Intuit's response to passkeys, then I'm pretty sure this Product Idea will not get any traction with the Dev Team. It's just my guess. It will be interesting to see what Quicken's response to this Product Idea will be if/when the number of votes gets to the needed 50 mark.
I recently suffered fraud in my bank accounts. It came in three waves, after each attack my bank closed the impacted accounts and gave me new ones. (1) The first appeared to be due to a leaked password, the bad guys got into my checking and credit card accounts and tried (but failed) to steal about $20k. I responded by changing all significant passwords (financial, personal data) to complex 15-character password-manager-generated passwords and activating 2FA wherever it was available. (2) They hit me again, the bad guys changed the 2FA phone number for authentication, and the bank fraud people felt they were reading my passwords on my PC, either by mirroring the display or a keystroke reader. I did a full computer reset that wiped the SSD clean, then reloaded Windows and apps, and began using passkeys whenever available, (3) They hit me again with false Venmo transactions, which suggested they knew my brand-new account number but could not get into the account. The fraud professionals advised they felt my phone was the entry point (I had bank account data in the bank's mobile app), and I got a new phone and phone number. Now it's been eight days with no further issues - we'll see how it goes.
Also, in attack #2 my computer's system software or hardware got damaged and it would not reload Windows after the SSD was wiped. I took it to a professional who kept it 3 days and finally was able to reload Windows 25H2. It failed again the first time Windows Update tried to run. I now have a new computer.
By the way, Microsoft maintains a log of successful and unsuccessful attempts to login to a Windows computer. This is available to you online for your account. I discovered that after the first attack. That log revealed the attackers were in Nigeria, and they apparently had gotten into my computer five weeks before making their first attack. Presumably that's when I got a dose of malware and they began collecting passwords and other data.
I'm bit embarrassed to say that I really looked into the details of passkeys until researching them for this thread and I also sort of thought of them as fancy passwords too.
I personally use RoboForm and it has supported passkeys for quite a while now, and I use them when they are available.
The biggest flaw I can see in this idea is that in most cases you can't select "passkey only". The password is still available for the hacker to use, but I guess the very fact that the password is never sent will minimize it becoming known through things like a key logger.
@Chris_QPW,
Correct for the 'most cases" as you said. But more and more FIs are going exclusive passkey. I have two FIs that have done that. No more passwords or any backdoor or backup options - it's only my finger print on my computer. I am sure there are other FIs that have eliminated passwords altogether and the trend will continue faster than we think.
One thing I need to research is the keylogger. Like in the case of @Ray Cosner . For example one question I'd like to know is: Are keyloggers able to spy on my VM activity as well? I am only guessing they could but if they don't, then a potential safe option would be to use a VM for our sensitive needs.
Update: based on my quick research and I could be wrong, a spyware keylogger on the host system cannot spy on the VM. It further says that Microsoft's built-in Hyper-V (type-1) is safer than other hypervisors such as VirtualBox and VMware (type-2).
I think you have this wrong.
Think about how you are accessing the VM. You are using the host's keyboard. Clearly if the keylogger is monitoring your keyboard on the host then it will see any password that is typed that then goes to the VM. What's more since they also hook the clipboard it can't go through there either without them seeing it. The keylogger can't get in between the communication between the host and the VM, but it doesn't have to because it grabbed what it needed before it left the host. The VM protects the host, but not the other way around. If the keylogger is on the VM, then it can see what is typed on the VM, but it can't see what is typed on the host.
This is really the whole point of the passkey. It neither goes through the keyboard driver or the clipboard that the malware is hooking into.
EDIT: the above applies to your display too.
This might be helpful to understand why a passkey is secure, when a password isn't.
Typing, copying and pasting, display are generic things that have legitimate reasons for allowing hooking into them.
Whereas a passkey lives in the known area of "security" with no reason to allow any kind of "hooking".