Live data from Hacker News

Passkeys.io – A Passkey Authentication Demo

passkeys.io

21–30 of 121 posts

Re: Passkeys.io – A Passkey Authentication Demo

#21
post #12

Earlier quoted context omitted.

You can also save it to your phone, you only need to scan another QR code if you want to save it on another device

I’m given a prompt to either use another device or an external key. Those are the only two choices. Or am I supposed to create via email first and that’s what I’m missing?

You have to create first.

Re: Passkeys.io – A Passkey Authentication Demo

#23

When signing up on a Windows machine with Firefox it doesn't let me use Yubikey but prompts for a Windows Hello PIN instead. Canceling the dialog doesn't go to the next available method (like it normally does) but just retries once again, after a second cancellation it just gives up. I'd say this makes this whole thing completely unusable, because under no circumstances would I ever want to use a machine-bound authen…

Using a physical key in Windows now requires you to enter the pin to unlock your Yubikey (or set a pin) before you can use it to register.

This is an issue we've run into a lot at $work where users will forget their FIDO2 pin cause its only used during registration, and never after that, and when they reset the pin it destroys all their previous known 2FA (which is expected).

This is a new requirement from Microsoft.

Re: Passkeys.io – A Passkey Authentication Demo

#24

Any idea how are Password Managers, such as 1Password/Bitwarden/Keepass, thinking of integrating or competing or co-living with Passkeys? I can live with something like 1Password but my wife and kids will be more suited and happier with Passkeys.

Bitwarden already support regular WebAuthn for 2FA[0] to log in. They have an active request for Passkey support[1]. It seems like they want to include these inside of their own service too, as the storage provider.

[0] https://bitwarden.com/help/setup-two-step-login-fido/

[1] https://community.bitwarden.com/t/unlock-bitwarden-with-2fa-...

Re: Passkeys.io – A Passkey Authentication Demo

#25

I'm a bit confused with WebAuthn/Passkeys/Fido If I have a single hardware key/tpm/yubikey/iphone/etc - can you create multiple users on one site? And can they tell that you're the same user? Or are you now locked to just a single user for your phone/macbook/yubikey/whatnot? Also if multiple services colluded (or integrated with say GA) - can they (or at least GA) all tell that you're using the same hardware key acro…

It supports multiple user names. From what I've seen in screenshots it shows a picker to select the account you want if there are multiple applicable.

Re: Passkeys.io – A Passkey Authentication Demo

#26
post #6

> passkeys are way more secure and are easier to use than both passwords and all current 2-factor authentication methods Perhaps I'm naive, but how are passkeys "way more secure" than "all current 2-factor authentication methods"? Don't many security keys (e.g. Yubikey) also require that you are in possession of the physical yubikey? I'm using that as a 2-factor authentication method. Why is a passkey more secure? Up…

By the latest definition, Security Keys also store passkeys.

Re: Passkeys.io – A Passkey Authentication Demo

#27
post #9

The demo is just using OTP sent to my email, which essentially makes my email a password manager, and now a much higher value target.

Your email is already both the password and 2fa reset for the vast majority of services... including things like bank accounts.

Email access is basically total access.

Re: Passkeys.io – A Passkey Authentication Demo

#28

When signing up on a Windows machine with Firefox it doesn't let me use Yubikey but prompts for a Windows Hello PIN instead. Canceling the dialog doesn't go to the next available method (like it normally does) but just retries once again, after a second cancellation it just gives up. I'd say this makes this whole thing completely unusable, because under no circumstances would I ever want to use a machine-bound authen…

Using a physical key in Windows now requires you to enter the pin to unlock your Yubikey (or set a pin) before you can use it to register. This is an issue we've run into a lot at $work where users will forget their FIDO2 pin cause its only used during registration, and never after that, and when they reset the pin it destroys all their previous known 2FA (which is expected). This is a new requirement from Microsoft.

I'm aware about this requirement, and it makes sense. Obviously, I want the authenticator device protected, so I must know the device PIN or password to unlock it.

It's exactly the same for Windows Hello built-in authenticator, they require a PIN (or face, or whatever other means you have configured) for the computer itself. Same for iPhones, you need a PIN or password to unlock it. It's merely a matter of frequency (phones and laptops are unlocked daily, Yubikeys - depends on the individual), and if use of hardware tokens is prohibited (or even discouraged) from the very beginning they'll never have a chance and the world would go the path of least resistance once again.

I'm curious if resetting a PIN or password on Windows or macOS or iPhone OS would retain the Passkey identities. I suspect it would...

Re: Passkeys.io – A Passkey Authentication Demo

#29
post #27
post #9

The demo is just using OTP sent to my email, which essentially makes my email a password manager, and now a much higher value target.

Your email is already both the password and 2fa reset for the vast majority of services... including things like bank accounts. Email access is basically total access.

That's a good point. It's annoying to have to check email for a code for each login though, compared to 1Password autofill w/password and TOTP.

Re: Passkeys.io – A Passkey Authentication Demo

#30

Any idea how are Password Managers, such as 1Password/Bitwarden/Keepass, thinking of integrating or competing or co-living with Passkeys? I can live with something like 1Password but my wife and kids will be more suited and happier with Passkeys.

If I understand what I've read correctly, 1Password nightlies already have support for webauthn, but it's certainly not something they advertise as ready for general usage.

https://blog.1password.com/1password-is-joining-the-fido-all...

Post reply on HN