Live data from Hacker News

Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

fidoalliance.org

81–90 of 525 posts

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#81

So their vision of the future is that to do anything online, one MUST have a phone (ahem, portable wiretap)? And they're going to be keeping my secrets for me, for my own good? I'm not sure I'm down with any of that.

It's literally the opposite. You "must" have a cryptographic device (a dongle) that is only doing that one thing, authentication. Doesn't have a built in radio (unless for NFC, if you want it), doesn't have any microphone or camera, doesn't store any data beyond what's needed to authenticate, doesn't communicate except to authenticate - bi-directionally, so phishing is no longer a thing, or at least it's a lot harder.

It's very hard to make a privacy case against FIDO. Practically speaking it's one of the best things that happened to privacy&security since the invention of asymmetric cryptography. The deployment of this tech reduces phishing effectiveness to near zero, or in many cases literally zero.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#82
post #73

Earlier quoted context omitted.

Oh gosh... your raw bio-metrics are never stored anywhere... The signal from the sensor is used as a "seed" to generate key using robust cryptography Different sensors will output different "data" based on the sensor type.

Let's ignore the part about biometrics being faked since this seems to be a point of contention. Isn't it a fair argument that secret keys should be mutable by the user? In the future, some unforeseen event COULD occur which compromises or otherwise renders the particular biometric unusable. Now what?

But they are... Firstly, with how it works. even if you use the same finger to generate hundreds of keys, they should all be different because we are using noise\randomness within the algorithm itself. different sensors will generate different outputs and therefore it is pointless to worry about the key used stolen.

I think what you want is secret keys completely detached from the user. we have that as well with hardware tokens.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#83

I don't trust Google or Apple to be my main authentication provider, or to manage syncing my private key. Their customer service is terrible and they are way too arbitrary on locking folks out. I would trust my bank (well, my credit union.) I can go see them in person if I need to and they take my lawyer seriously, they also take security seriously, they're properly regulated, and ultimately they're my main concern i…

This announcement isn't about that and neither provider is asking to sync your private key. In fact the opposite is true: with FIDO2, you're in much greater control of your account security because authentication creds are now on a hardware token versus as bearer credentials you type and an adversary can steal and replay. Many of us believe we're very good at protecting our passwords, but this isn't true in reality and FIDO2/U2F standards objectively make accounts more secure precisely because they remove humans from the equation.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#84
post #73

Earlier quoted context omitted.

Oh gosh... your raw bio-metrics are never stored anywhere... The signal from the sensor is used as a "seed" to generate key using robust cryptography Different sensors will output different "data" based on the sensor type.

Let's ignore the part about biometrics being faked since this seems to be a point of contention. Isn't it a fair argument that secret keys should be mutable by the user? In the future, some unforeseen event COULD occur which compromises or otherwise renders the particular biometric unusable. Now what?

Let me follow up and say. why do people go nuts over biometrics?

Password based biometrics is the last place I would look at for biometric compromise.

We leave biometric traces everywhere, all the time. do you cover your face and wear gloves in public? hmmmm...

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#85

I don't trust Google or Apple to be my main authentication provider, or to manage syncing my private key. Their customer service is terrible and they are way too arbitrary on locking folks out. I would trust my bank (well, my credit union.) I can go see them in person if I need to and they take my lawyer seriously, they also take security seriously, they're properly regulated, and ultimately they're my main concern i…

In the Netherlands the banks provide the iDIN system, so you can authenticate on more sites with the bank provided logins. Each bank has a slightly different system often using bank card and bank card readers and ways to authenticate through authorised banking app on individual mobile phones.

- https://www.idin.nl/en/about-idin/

- https://nl.wikipedia.org/wiki/IDIN - (Use translate function in browser to read as there is no English version

And besides that we have also a government provided login system which can also even work with your ID card. But mostly works with government systems and health insurance companies.

- https://en.wikipedia.org/wiki/DigiD

- https://www.digid.nl/en

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#86
post #39
post #27

Earlier quoted context omitted.

Sounds to be like we're replacing the username and the password, i.e. something you know with username and your phone, i.e. something you have . It sounds like it's still a one factor authentication system, but different.

Follow-up dumb questions: - so what happens if you don't have your phone at time of login? - if I enroll on iPhone, is my identity forever tied to Apple or can it be migrated to Android if I ever wanted to change platforms? - Can Apple/Google/Microsoft ever block/ban my account, preventing me from logging into my bank, etc that use FIDO login?

If you don't have your phone, you can't log in. SMS 2FA has the same problem.

You technically should be able to migrate from one provider to another, it remains to be seen how easy Apple and Google will make the process.

That last one is a great question that I don't know the answer to.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#87

Earlier quoted context omitted.

Oh gosh... your raw bio-metrics are never stored anywhere... The signal from the sensor is used as a "seed" to generate key using robust cryptography Different sensors will output different "data" based on the sensor type.

> your raw bio-metrics are never stored anywhere... Unless you have a drivers license in California where they require inked versions of your biometrics.

That's governments for you(btw not only CA but other places as well) I would definitely be more worried about that than my biometrics on my phone.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#88
post #77
post #55

The weakest link in security is always going to be humans. Account compromise is is more often a human problem than a technological one (spamming requests, password reuse, simple passwords, (spear) phishing, direct social engineering, etc). If I'm understanding correctly, they're aiming to reduce multi-factor auth back down to a single factor that's "easier" than passwords. Easier to use. Easier to social engineer a…

There's a frequent misconception that hardware keys are no better than, say, a TOTP seed on a secure element of your phone. The core practical difference between a hardware key and that TOTP code on a secure element is the hardware key, when registered with a domain, is programmed with the domain name in it. Lookalike domains - or anything besides the exact domain you registered the key with - fail to 2FA because the…

Absolutely right - put another way: the responsibility of the user is reduced from "be absolutely certain that you're entering your credentials to the web site that you think you're authenticating at" to "provide consent to authenticate".

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#90

So their vision of the future is that to do anything online, one MUST have a phone (ahem, portable wiretap)? And they're going to be keeping my secrets for me, for my own good? I'm not sure I'm down with any of that.

My vision of future authentication (shared by colleagues in security) is based in strong hardware credentials and additional layer-7 context about identity, device and location. Basically, more identification of you and your browser using cryptographically-guaranteed and immutable events. It is actually the deprecation of passwords altogether and generally moving the trust boundary away from the control of the user e…

[deleted]
Post reply on HN