Live data from Hacker News

Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

fidoalliance.org

1–10 of 525 posts

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#3
Not a great thing to see the big three once again, driving the standards here. You should be worried.

But as long as the ridiculous SMS 2FA is removed or replaced by something better, then fine. But we'll see how this goes.

From the web side of this standard, this also tells me that Mozilla has no influence anywhere and will be the last ones to implement this standard in Firefox.

Oh dear.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#4
This passwordless signin process sounds neat, but will it increase Google’s power to lock people out of things? I don’t understand why Google doesn’t have an ombudsman - consumers have no recourse when Google locks them out, and it seems the consequences of Google locking you out are ever increasing. I think we’re going to need legislation to force Google to make a proper appeals process.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#5
I hope this cross device system will be cross platform, but I wouldn't be surprised if you could only choose between macOS/iOS, Chrome/Chrome, or Edge/Edge sync.

Funnily enough, a system for signing web authentication requests from a mobile device is far from new: I've been using https://krypt.co/ for years (though it's on the long road of sunsetting right now) and I hope that will last long enough for the new cross device standard to replace it.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#7

Does anyone here know what privacy/tracking issues are with this standard?

I haven't found any so far. Each account gets a new public/private key pair so accounts can't be traced back to each other. Usernames are optional and might even become a thing or the past, making username reuse less of an issue for linking accounts.

It all depends on the sync method provided. If synchronisation isn't end-to-end protected, you're handing Apple/Google/Microsoft the keys to the kingdom which is pretty bad.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#10

So their vision of the future is that to do anything online, one MUST have a phone (ahem, portable wiretap)? And they're going to be keeping my secrets for me, for my own good? I'm not sure I'm down with any of that.

I doubt they'll do away with tools like smart cards or Yubikeys any time soon. Laptops and modern computers also contains a TPM so you don't necessarily need to have a phone for secrets storage.

If push comes to shove, I'm sure someone will develop a lightweight Android emulation layer you can run in the cloud that pretends to be a phone enough that you can use it.

Post reply on HN