Live data from Hacker News

Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

fidoalliance.org

11–20 of 525 posts

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#11

Does anyone here know what privacy/tracking issues are with this standard?

FIDO2 privacy is actually pretty good and well thought out. There's a theoretical risk of a website sending authentication challenges for two different accounts and having both assertions signed by the same credential, basically correlating those accounts together, but this is unlikely to weaken collective privacy at scale.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#12
post #3

Not a great thing to see the big three once again, driving the standards here. You should be worried. But as long as the ridiculous SMS 2FA is removed or replaced by something better, then fine. But we'll see how this goes. From the web side of this standard, this also tells me that Mozilla has no influence anywhere and will be the last ones to implement this standard in Firefox. Oh dear.

Both FIDO and W3C are neutral places for this. Mozilla being a part of W3C and FIDO will have a say. This is just a PR stunt that the tech journalists ate up. They’ve been working together to make this for the last two years, it’s just an announcement to accelerate the work on it.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#14
I’m sure people way smarter than me have this figured out, from the Google post:

> When you sign into a website or app on your phone, you will simply unlock your phone — your account won’t need a password anymore.

> Instead, your phone will store a FIDO credential called a passkey which is used to unlock your online account. The passkey makes signing in far more secure, as it’s based on public key cryptography and is only shown to your online account when you unlock your phone

So if I was a dumb kid, I could login to my parents bank accounts (or more / worst) if my mom gave me her 4 digit phone password for games earlier?

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#16
I think this is really great news and am glad to see FIDO move forward as I think it greatly increases account security.

One aspect of FIDO that could still be troublesome is account recovery in case of inadvertent loss of passkey. OOB recovery with SMS or email is considered too weak and the main recommended alternatives are to maintain multiple authenticators (i.e. multiple copies of your passkeys), re-run onboarding processes for new users or just abandon the account.

It's going to be interesting to see how those alternatives play out in real world situations.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#17
Suggested edit of mission statement in the name of increased accuracy:

“The standards developed by the FIDO Alliance and World Wide Web Consortium and being led in practice by these innovative companies is the type of forward-leaning thinking that will ultimately make the American people easier to track online.

This will be done by linking all online activity to unique personal attributes, i.e. "their fingerprint or face, or a device PIN." It's basically another step towards the China model of total mass surveillance of the population.

[edit: all the justifications for this proposal - aren't they mostly solved by the use of password managers?]

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#18
post #14

I’m sure people way smarter than me have this figured out, from the Google post: > When you sign into a website or app on your phone, you will simply unlock your phone — your account won’t need a password anymore. > Instead, your phone will store a FIDO credential called a passkey which is used to unlock your online account. The passkey makes signing in far more secure, as it’s based on public key cryptography and is…

No, because it should be evident by now that a phone is a personal computer, not to be shared with other people.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#19
post #14

I’m sure people way smarter than me have this figured out, from the Google post: > When you sign into a website or app on your phone, you will simply unlock your phone — your account won’t need a password anymore. > Instead, your phone will store a FIDO credential called a passkey which is used to unlock your online account. The passkey makes signing in far more secure, as it’s based on public key cryptography and is…

Normal usage would require a reauthentication - i.e. FaceId or TouchId - to produce the passkey.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#20

So their vision of the future is that to do anything online, one MUST have a phone (ahem, portable wiretap)? And they're going to be keeping my secrets for me, for my own good? I'm not sure I'm down with any of that.

My vision of future authentication (shared by colleagues in security) is based in strong hardware credentials and additional layer-7 context about identity, device and location. Basically, more identification of you and your browser using cryptographically-guaranteed and immutable events. It is actually the deprecation of passwords altogether and generally moving the trust boundary away from the control of the user entirely. I also don't enjoy it, but it would solve a lot of current problems we see in information security.
Post reply on HN