I’m sure people way smarter than me have this figured out, from the Google post: > When you sign into a website or app on your phone, you will simply unlock your phone — your account won’t need a password anymore. > Instead, your phone will store a FIDO credential called a passkey which is used to unlock your online account. The passkey makes signing in far more secure, as it’s based on public key cryptography and is…
Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
31–40 of 525 posts
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#32I’m sure people way smarter than me have this figured out, from the Google post: > When you sign into a website or app on your phone, you will simply unlock your phone — your account won’t need a password anymore. > Instead, your phone will store a FIDO credential called a passkey which is used to unlock your online account. The passkey makes signing in far more secure, as it’s based on public key cryptography and is…
Normal usage would require a reauthentication - i.e. FaceId or TouchId - to produce the passkey.
> you will simply unlock your phone
Then I guess that really is no different from opening an app.
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#33Dumb question: why are biometrics being used to replace the password , shouldn't the biometric replace the username ?
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#34I think this is really great news and am glad to see FIDO move forward as I think it greatly increases account security. One aspect of FIDO that could still be troublesome is account recovery in case of inadvertent loss of passkey. OOB recovery with SMS or email is considered too weak and the main recommended alternatives are to maintain multiple authenticators (i.e. multiple copies of your passkeys), re-run onboardi…
You might even be able to get access by simply logging in to your Microsoft/Apple/Google account on a new device if they implement this system stupidly enough.
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#35Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#36This passwordless signin process sounds neat, but will it increase Google’s power to lock people out of things? I don’t understand why Google doesn’t have an ombudsman - consumers have no recourse when Google locks them out, and it seems the consequences of Google locking you out are ever increasing. I think we’re going to need legislation to force Google to make a proper appeals process.
You choose to use Google, and can attest to the fact it's not that difficult not to.
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#37This passwordless signin process sounds neat, but will it increase Google’s power to lock people out of things? I don’t understand why Google doesn’t have an ombudsman - consumers have no recourse when Google locks them out, and it seems the consequences of Google locking you out are ever increasing. I think we’re going to need legislation to force Google to make a proper appeals process.
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#38I've resisted switching to a hardware key because I know that I'm going to break it, and that seems like a huge pain in the ass. I really want to be able to make a couple of backup keys, or maybe put another way, I want to be able to put the private key on the device myself, I don't necessarily care that the key is generated on the device and never leaves the device. I don't care if that slightly reduces my security…
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#39Dumb question: why are biometrics being used to replace the password , shouldn't the biometric replace the username ?
Sounds to be like we're replacing the username and the password, i.e. something you know with username and your phone, i.e. something you have . It sounds like it's still a one factor authentication system, but different.
- so what happens if you don't have your phone at time of login?
- if I enroll on iPhone, is my identity forever tied to Apple or can it be migrated to Android if I ever wanted to change platforms?
- Can Apple/Google/Microsoft ever block/ban my account, preventing me from logging into my bank, etc that use FIDO login?
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#40Dumb question: why are biometrics being used to replace the password , shouldn't the biometric replace the username ?
Username is simply an ID. Password is how we truly verify who the user is.
Bio-metrics are just convenient because they are unique and hard\impossible to replicate.