Live data from Hacker News

Passkeys.io – A Passkey Authentication Demo

passkeys.io

11–20 of 121 posts

Re: Passkeys.io – A Passkey Authentication Demo

#12

I guess I’m not understanding passkeys. On my iPhone it’s asking generating a QR code to scan with another device. Is this assuming another device already has credentials? What if this is my only device?

You can also save it to your phone, you only need to scan another QR code if you want to save it on another device

Re: Passkeys.io – A Passkey Authentication Demo

#13

I guess I’m not understanding passkeys. On my iPhone it’s asking generating a QR code to scan with another device. Is this assuming another device already has credentials? What if this is my only device?

In the specific case of Apple, your PassKey is stored in iCloud, and so can be retrieved from any Apple device you are signed into.

Without this kind of cloud sync, you need at least two devices, or you will be locked out if you lose or break one.

Re: Passkeys.io – A Passkey Authentication Demo

#14

I guess I’m not understanding passkeys. On my iPhone it’s asking generating a QR code to scan with another device. Is this assuming another device already has credentials? What if this is my only device?

Do you use fingerprints to unlock your device? The page asked me to identify via fingerprints

Re: Passkeys.io – A Passkey Authentication Demo

#15

Very nice, a good step towards the future. Just tried on multi-device scenario with android and my mac and that worked fine. I'm wondering though, how the biometric data gets associated with my email address.

From what I remember, your biometric data shouldn't get associated at all. Your hardware uses your biometrics to unlock the onboard enclave / vault and then the process asking can obtain or create what it needs once unlocked. If you don't have biometrics enabled it would resort to your phone password/pin.

Don't take my word for it though!

Re: Passkeys.io – A Passkey Authentication Demo

#16
When signing up on a Windows machine with Firefox it doesn't let me use Yubikey but prompts for a Windows Hello PIN instead. Canceling the dialog doesn't go to the next available method (like it normally does) but just retries once again, after a second cancellation it just gives up. I'd say this makes this whole thing completely unusable, because under no circumstances would I ever want to use a machine-bound authenticator (unless that's the only option I physically have). I really cannot think of any reason, it won't give me any extra security and it will make things needlessly complicated in event of device loss.

To make it worse, when I'm trying to sign in, it prompts me for my Yubikey PIN, and not Windows Hello PIN. Basically, multiple token support is badly messed up.

Re: Passkeys.io – A Passkey Authentication Demo

#17
post #12

I guess I’m not understanding passkeys. On my iPhone it’s asking generating a QR code to scan with another device. Is this assuming another device already has credentials? What if this is my only device?

You can also save it to your phone, you only need to scan another QR code if you want to save it on another device

I’m given a prompt to either use another device or an external key. Those are the only two choices. Or am I supposed to create via email first and that’s what I’m missing?

Re: Passkeys.io – A Passkey Authentication Demo

#18
post #6

> passkeys are way more secure and are easier to use than both passwords and all current 2-factor authentication methods Perhaps I'm naive, but how are passkeys "way more secure" than "all current 2-factor authentication methods"? Don't many security keys (e.g. Yubikey) also require that you are in possession of the physical yubikey? I'm using that as a 2-factor authentication method. Why is a passkey more secure? Up…

One question : will the signature generated on a brand new device still conform to the requirements, if I end up losing all my devices? What if I'm signing in on a random public device?

Re: Passkeys.io – A Passkey Authentication Demo

#20
I'm a bit confused with WebAuthn/Passkeys/Fido

If I have a single hardware key/tpm/yubikey/iphone/etc - can you create multiple users on one site? And can they tell that you're the same user? Or are you now locked to just a single user for your phone/macbook/yubikey/whatnot?

Also if multiple services colluded (or integrated with say GA) - can they (or at least GA) all tell that you're using the same hardware key across services?

Unless I'm missing something this sounds like very bad news for user privacy

Post reply on HN