Live data from Hacker News

Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

fidoalliance.org

111–120 of 525 posts

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#111

Earlier quoted context omitted.

It's literally the opposite. You "must" have a cryptographic device (a dongle) that is only doing that one thing, authentication. Doesn't have a built in radio (unless for NFC, if you want it), doesn't have any microphone or camera, doesn't store any data beyond what's needed to authenticate, doesn't communicate except to authenticate - bi-directionally, so phishing is no longer a thing, or at least it's a lot harder…

> It's very hard to make a privacy case against FIDO. With username and password, I have full control over my privacy in a very easy to understand fashion: If I randomly generate them I know I cannot be tracked (as long as I ensure my browser doesn't allow it by other means). With those keys I have a opaque piece of hardware which transfers an opaque set of data to each website I use and I have NO idea what data that…

How about using one of the open hardware + open software security keys?

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#112

Earlier quoted context omitted.

Except it kind of is - the way I read this is "Apple/Google will turn your phone into a hardware FIDO token, but will use iCloud/whatever to reduce the huge painpoint of having more than one hardware token and keeping them all in sync" I really love the idea of FIDO and making sure that my authenticator only authenticates to sites that I've approved, but having multiple keys right now is a huge pain, but I'm not exci…

Your average user is more concerned about losing their password than they are about authenticator sovereignty. Moving towards cryptographic primitives for auth versus shared secrets is a net benefit versus current state. > but having multiple keys right now is a huge pain, but I'm not excited about "just sign up for Apple and that pain goes away" because I sure as hell don't trust Apple not to cause me pain in the fu…

> Your average user is more concerned about losing their password than they are about authenticator sovereignty

Right up to the point when they’re locked out from their Google, iCloud or Facebook accounts with little recourse or appeal. And then they discover it’s not just Google, a whole host of other services don’t work.

And it does happen, and I for one don’t want to wait for legislation to mitigate this blatant attempt at yet more centralisation.

Better to not centralise in the first place.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#113

I like the idea, but not sure about the implementation. What happens when there is an outage at Google or Apple? What happens when I lose/get stolen/break/change my cell phone? What happens if I do not have/want a cell phone?

> What happens if I do not have/want a cell phone?

WebAuthn works with hardware tokens, so something like a Yubikey will also work.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#114

I like the idea, but not sure about the implementation. What happens when there is an outage at Google or Apple? What happens when I lose/get stolen/break/change my cell phone? What happens if I do not have/want a cell phone?

The FIDO Standard talked about here includes regular security keys, so, if you don't want to use passkey, you can get a physical security key; and while I imagine the push for passwordless will be large, I doubt they'll completely remove passwords anytime soon.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#116

Played with the Yubikeys a couple of days ago. Rather nice thingies that are very easy to lose somewhere.

It's reasonably safe to leave them connected to the devices you regularly authenticate from, unless your threat model includes an adversary willing to use physical attacks.

Unless you have some way of authenticating all of your hardware with the key, taking it with you still leaves plenty of options for a physical attacker.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#117

This passwordless signin process sounds neat, but will it increase Google’s power to lock people out of things? I don’t understand why Google doesn’t have an ombudsman - consumers have no recourse when Google locks them out, and it seems the consequences of Google locking you out are ever increasing. I think we’re going to need legislation to force Google to make a proper appeals process.

Google's power to lock people out of their website is already here with Oauth2.

This standard is unrelated; it works by having the browser/device itself sync the virtual security keys[0], much in the same way they sync passwords currently. That's the only thing changing here, giving people the choice (and encouraging them) to sign in via "what you have" instead of "what you know", but along with that they want to alleviate the UX concerns of people not being ready to carry around a separate physical security key.

0: https://developer.apple.com/documentation/authenticationserv...

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#118

Earlier quoted context omitted.

Your average user is more concerned about losing their password than they are about authenticator sovereignty. Moving towards cryptographic primitives for auth versus shared secrets is a net benefit versus current state. > but having multiple keys right now is a huge pain, but I'm not excited about "just sign up for Apple and that pain goes away" because I sure as hell don't trust Apple not to cause me pain in the fu…

> Your average user is more concerned about losing their password than they are about authenticator sovereignty Right up to the point when they’re locked out from their Google, iCloud or Facebook accounts with little recourse or appeal. And then they discover it’s not just Google, a whole host of other services don’t work. And it does happen, and I for one don’t want to wait for legislation to mitigate this blatant a…

Many authenticator apps allow you to extract and back up the private key yourself, with no involvement of any 3rd party. But it's a totally optional workflow and you're never asked for that private key while authenticating, so the mass phishing and spear-phishing attacks seen with passwords are still infeasible.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#119
post #39

Earlier quoted context omitted.

Follow-up dumb questions: - so what happens if you don't have your phone at time of login? - if I enroll on iPhone, is my identity forever tied to Apple or can it be migrated to Android if I ever wanted to change platforms? - Can Apple/Google/Microsoft ever block/ban my account, preventing me from logging into my bank, etc that use FIDO login?

If you don't have your phone, you can't log in. SMS 2FA has the same problem. You technically should be able to migrate from one provider to another, it remains to be seen how easy Apple and Google will make the process. That last one is a great question that I don't know the answer to.

> You technically should be able to migrate from one provider to another, it remains to be seen how easy Apple and Google will make the process.

On a UX level, the transfer to another syncing security key "provider" is going to be interesting, if they even do that at all - I kind of doubt they'll have a "transfer your iCloud passkeys to your Chrome password manager" and they'll instead say "go to each service and enroll a new security key via your new syncing key manager". On a technical level, I wholly imagine there'll be a tool that pulls iCloud Passkeys[0] via the MacOS Keychain application and then inserts them into your new key manager.

0: https://developer.apple.com/documentation/authenticationserv...

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#120

I don't trust Google or Apple to be my main authentication provider, or to manage syncing my private key. Their customer service is terrible and they are way too arbitrary on locking folks out. I would trust my bank (well, my credit union.) I can go see them in person if I need to and they take my lawyer seriously, they also take security seriously, they're properly regulated, and ultimately they're my main concern i…

> Their customer service is terrible

Let me add my recent experience in the bucket. Few days ago I upgraded my legacy Workspace account to a business account. (I was in a time crunch; couldn't evaluate alternatives.) I enter my debit card details in the checkout and got a generic error message asking me to "try again later." Thought there was something wrong with their service and tried the next day. Same error. After some 15 minutes of searching forums, turns out debit card is not supported in my country on account of SMS based TOTP, which doesn't work for subscription services. (If they could mention it in the haystack of their help pages, why can't they say that right when I signup?)

Anyway, more searching led to an alternative. There's an option to request invoiced billing where I would get a monthly bill & pay - debit card works here. Clicking that option took me to form. Filled it, got a call from a sales guy few hours later. Sadly, he had no clue about my problem, despite being from my country. On top of that he told me he's from a different team and don't deal with sales queries (WTF. Then why did he call me?). Told me he'd email me some options and, at that point I wasn't hopeful. Thought he would send me some stuff I had already seen on their forums. On seeing the said email, my disappointment sank even lower. The generic mail had absolutely nothing to do with my issue and the help urls were totally unrelated.

I just ended up using my friend's credit card to complete the transaction. I'm seriously considering moving elsewhere.

Is product management this pathetic at Google? I'm sure if you went for a PM interview they'd judge you nine ways to Sunday. For what? Everything Google does seems like it's built by three robots in a trench coat collaborating unsuccessfully with other robots in trench coats.

Post reply on HN