Live data from Hacker News

Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

fidoalliance.org

41–50 of 525 posts

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#41

I think this is really great news and am glad to see FIDO move forward as I think it greatly increases account security. One aspect of FIDO that could still be troublesome is account recovery in case of inadvertent loss of passkey. OOB recovery with SMS or email is considered too weak and the main recommended alternatives are to maintain multiple authenticators (i.e. multiple copies of your passkeys), re-run onboardi…

One aspect of FIDO that could still be troublesome is account recovery in case of inadvertent loss of passkey.

I think the idea is that passkeys are synced between devices, see e.g.:

https://developer.apple.com/videos/play/wwdc2021/10106/

I haven't look deeply into passkey enough yet, but aren't we replacing "what if I lose by device" by "what if company XYZ decides to nuke my access to my synchronized passkey"?

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#45

This passwordless signin process sounds neat, but will it increase Google’s power to lock people out of things? I don’t understand why Google doesn’t have an ombudsman - consumers have no recourse when Google locks them out, and it seems the consequences of Google locking you out are ever increasing. I think we’re going to need legislation to force Google to make a proper appeals process.

how FIDO has anything to do with google in particular? log in with google is not FIDO authentication...

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#46
post #21

Dumb question: why are biometrics being used to replace the password , shouldn't the biometric replace the username ?

Stunning question really. I imagine (absolute guess) it's because biometrics provide a 1-100% likelihood of a match, not a unique ID?

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#47
post #21

Dumb question: why are biometrics being used to replace the password , shouldn't the biometric replace the username ?

From a theoretical point of view or practical? Username is simply an ID. Password is how we truly verify who the user is. Bio-metrics are just convenient because they are unique and hard\impossible to replicate.

> Bio-metrics are just convenient because they are unique and hard\impossible to replicate.

But if your biometric is able to be faked, you can't change it like you can change a typical text based password. There's no "reset your password" equivalent for biometrics.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#48
post #21

Dumb question: why are biometrics being used to replace the password , shouldn't the biometric replace the username ?

I think, at the end of the day, there really isn't much of a difference between the two, for authentication. One is just a public part of who you are, and remains fairly static.

An argument for keeping the username separate is it is often used for identification. That is, you identify on this site as alberth. Not as any biometric scan. Even if you change which finger you want to use to authenticate, you'd still be alberth to everyone else here.

I think there are arguments on favor of letting you change a display name. Probably still would keep a name that is static. (What Twitter does?)

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#49
post #3

Not a great thing to see the big three once again, driving the standards here. You should be worried. But as long as the ridiculous SMS 2FA is removed or replaced by something better, then fine. But we'll see how this goes. From the web side of this standard, this also tells me that Mozilla has no influence anywhere and will be the last ones to implement this standard in Firefox. Oh dear.

[deleted]

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#50

I think this is really great news and am glad to see FIDO move forward as I think it greatly increases account security. One aspect of FIDO that could still be troublesome is account recovery in case of inadvertent loss of passkey. OOB recovery with SMS or email is considered too weak and the main recommended alternatives are to maintain multiple authenticators (i.e. multiple copies of your passkeys), re-run onboardi…

Reading this announcement, the idea seems to be that FIDO keys will be synchronised across devices. That means you can lose your phone and still get access to your accounts from your desktop. You might even be able to get access by simply logging in to your Microsoft/Apple/Google account on a new device if they implement this system stupidly enough.

Yes, these will be stored in cloud storage like iCloud Keychain. But I can go into my iCloud Keychain and delete individual passkeys - or I may have only one Apple device and then lose it. Or some malware clears out all of my iCloud Keychain.
Post reply on HN