Live data from Hacker News

Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

fidoalliance.org

31–40 of 525 posts

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#31
post #14

I’m sure people way smarter than me have this figured out, from the Google post: > When you sign into a website or app on your phone, you will simply unlock your phone — your account won’t need a password anymore. > Instead, your phone will store a FIDO credential called a passkey which is used to unlock your online account. The passkey makes signing in far more secure, as it’s based on public key cryptography and is…

[deleted]

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#32
post #14

I’m sure people way smarter than me have this figured out, from the Google post: > When you sign into a website or app on your phone, you will simply unlock your phone — your account won’t need a password anymore. > Instead, your phone will store a FIDO credential called a passkey which is used to unlock your online account. The passkey makes signing in far more secure, as it’s based on public key cryptography and is…

Normal usage would require a reauthentication - i.e. FaceId or TouchId - to produce the passkey.

Ah cool, the Google post made it seem a bit more automatic and instant.

> you will simply unlock your phone

Then I guess that really is no different from opening an app.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#33
post #21

Dumb question: why are biometrics being used to replace the password , shouldn't the biometric replace the username ?

A username (or email, same thing really) is required because there needs to be an identity to match a source of auth to.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#34

I think this is really great news and am glad to see FIDO move forward as I think it greatly increases account security. One aspect of FIDO that could still be troublesome is account recovery in case of inadvertent loss of passkey. OOB recovery with SMS or email is considered too weak and the main recommended alternatives are to maintain multiple authenticators (i.e. multiple copies of your passkeys), re-run onboardi…

Reading this announcement, the idea seems to be that FIDO keys will be synchronised across devices. That means you can lose your phone and still get access to your accounts from your desktop.

You might even be able to get access by simply logging in to your Microsoft/Apple/Google account on a new device if they implement this system stupidly enough.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#35
I've resisted switching to a hardware key because I know that I'm going to break it, and that seems like a huge pain in the ass. I really want to be able to make a couple of backup keys, or maybe put another way, I want to be able to put the private key on the device myself, I don't necessarily care that the key is generated on the device and never leaves the device. I don't care if that slightly reduces my security - I'm not protecting nuclear weapons, my threat model is not state actors trying to attack me, my threat model is me leaving my key in my pants pocket before putting it in the washing machine.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#36

This passwordless signin process sounds neat, but will it increase Google’s power to lock people out of things? I don’t understand why Google doesn’t have an ombudsman - consumers have no recourse when Google locks them out, and it seems the consequences of Google locking you out are ever increasing. I think we’re going to need legislation to force Google to make a proper appeals process.

At some point (unless you're an Android dev) you have to accept a bit of responsibility. If you use Gmail, Drive and Android and then decide to use Android as your preferred implementation of FIDO (when YubiKeys ect, exist) I struggle to see how if you're locked out it's not partially the consumer's fault.

You choose to use Google, and can attest to the fact it's not that difficult not to.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#37

This passwordless signin process sounds neat, but will it increase Google’s power to lock people out of things? I don’t understand why Google doesn’t have an ombudsman - consumers have no recourse when Google locks them out, and it seems the consequences of Google locking you out are ever increasing. I think we’re going to need legislation to force Google to make a proper appeals process.

Don't use Google Drive. Don't use Gmail. That solves half the horror stories already.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#38

I've resisted switching to a hardware key because I know that I'm going to break it, and that seems like a huge pain in the ass. I really want to be able to make a couple of backup keys, or maybe put another way, I want to be able to put the private key on the device myself, I don't necessarily care that the key is generated on the device and never leaves the device. I don't care if that slightly reduces my security…

You just register 2-3 keys. It's not so bad.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#39
post #27
post #21

Dumb question: why are biometrics being used to replace the password , shouldn't the biometric replace the username ?

Sounds to be like we're replacing the username and the password, i.e. something you know with username and your phone, i.e. something you have . It sounds like it's still a one factor authentication system, but different.

Follow-up dumb questions:

- so what happens if you don't have your phone at time of login?

- if I enroll on iPhone, is my identity forever tied to Apple or can it be migrated to Android if I ever wanted to change platforms?

- Can Apple/Google/Microsoft ever block/ban my account, preventing me from logging into my bank, etc that use FIDO login?

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#40
post #21

Dumb question: why are biometrics being used to replace the password , shouldn't the biometric replace the username ?

From a theoretical point of view or practical?

Username is simply an ID. Password is how we truly verify who the user is.

Bio-metrics are just convenient because they are unique and hard\impossible to replicate.

Post reply on HN