Live data from Hacker News

The transition from logins to cryptographic passkeys is getting messy

wired.com

51–60 of 154 posts

Re: The transition from logins to cryptographic passkeys is getting messy

#51

Doesn't this just mean handing over authentication keys to proprietary systems? I couldn't find a single open source hardware FIDO L2 implementation. Looking at the specification, is it even possible for an open source implementation to gain L3+ certification?

To the people designing this it is a feature, not a bug.

Authenticator certification is inherently incompatible with open source, so you are forced to use a proprietary implementation.

Re: The transition from logins to cryptographic passkeys is getting messy

#52
post #29

Oh, what could go wrong! Why is there no discussion on users losing their private keys? Ask all those cryptocurrency users who lost their private keys. Now don't tell that there are crypto wallets/vaults that manage private keys; there are many ways key can be lost even when using wallets/vaults. We engineers live in a different world, disconnected from the regular users who have no clue what public-private keys are!

A web password is effectively a private secret, that can be used, for example, to derive a ECC keypair, but this secret is passed around in plain text between your device and the target site or service. It might be encrypted on the wire, but it must be known by both.

So any system that replaces web auth passwords is, worst case, just as bad as a password from a key-ownership perspective. Such a system also has the potential to be much better than a password, for example your auth secret is only entered on a secure keyboard (thumb reader, etc.) and used locally on a device you own, which then handles all auth tasks.

Re: The transition from logins to cryptographic passkeys is getting messy

#53
post #15

Just give me password auth back. I work in a lab that requires fingerprint login (TrustKey FIDO keys) with no fallback. Every 6-8 weeks I need to have my keys reset with new prints, which is a process that involves meeting a member of the security team in a room for 20 minutes so my key and the backup key (kept in a safe by the firm) can both be reset. Everyday, without fail, I sit there like a chimp taking on averag…

Oh how I wish we could get password auth back everywhere. We're working towards 6FA, they have to know your backup email address, your phone number, your location, your device, your security question.

At some point security is a trade-off with convenience, I have a randomly generated >20 characters password that I use only for gmail but right now I'm in the hospital and they won't accept it because I'm not on my usual device and I didn't activate 2FA ... because it's exactly the kind of problem I wanted to avoid.

I know users reuse passwords, I don't, let me use my god damn password.

And my password vault is on my google drive ... someone come euthanize me please.

Re: The transition from logins to cryptographic passkeys is getting messy

#54
post #38

Earlier quoted context omitted.

> The biggest threat almost all users face is in the form of remote attackers I'm not sure what users you interact with most on a regular basis, but for a pretty significant portion of the population, the most likely threats to their online (and offline) safety are jealous boyfriends/spouses/parents

Actually a valid point, but if you're gonna be that condescending about someone not considering that part of the population you should have something better than weasel words to argue how big it is.

You certainly have to consider your situation. If you live alone or with someone you trust (who you want to have access to your accounts if something happens to you), writing down passwords on paper and sticking that in a drawer or in some book on a bookshelf somewhere is likely pretty reasonable. Maybe have them backed up in an encrypted file in the cloud someplace as well.

Live in a house with a bunch of other people out of school? Extended family some of which you don't get along with in and out of the house a lot? Certainly for work stuff in an office. Probably not so much. The risk may not be that great in absolute terms but I'd absolutely think twice.

Re: The transition from logins to cryptographic passkeys is getting messy

#55
post #29

Oh, what could go wrong! Why is there no discussion on users losing their private keys? Ask all those cryptocurrency users who lost their private keys. Now don't tell that there are crypto wallets/vaults that manage private keys; there are many ways key can be lost even when using wallets/vaults. We engineers live in a different world, disconnected from the regular users who have no clue what public-private keys are!

I am in IT but not this side and I must admit I do not grok this move... At all. I don't understand the risk to Benefit story. It seems (possibly incorrectly) to put all my eggs into one basket - whether phone (which annoys the heck out of me as it is NOT my primary device) or some cloudy account I'm supposed to trust with my life. It also seems to impose geographical dependencies (I want to check my email at my friend's but my phone is at home which is precisely why I want to use their computer etc). It also seems to bring terrifying consequences of losing some ethereal items nobody (regular) understands how to safekeep.

I feel like I'm an old grouch who wants things to stay the same... And that's kinda the case :-)

Re: The transition from logins to cryptographic passkeys is getting messy

#56
The root issue here is that most people do not know how identities based on public/private keys work. So the stuff about using bluetooth and and QR codes is just a pointless and meaningless ritual. If anything goes wrong the user will have no idea about what they should do to resolve that issue. They won't know what they have to do to prevent things from going wrong.

The modern cryptography that this stuff is based on was invented only 40 years ago. There is as of yet no useful cultural context to base systems on. You can't expect people to be able to use concepts that don't really exist yet.

Re: The transition from logins to cryptographic passkeys is getting messy

#57

I can't wait for companies to use secure passkeys and still force me to use SMS 2FA with no option to disable it.

Microsoft "consumer" (live.com, etc) accounts are like this. They have a whole set of advanced, secure options like security keys, TOTP, etc but they force you to have either an email or SMS recovery option configured :(

Google on the other hand, do this correctly. You can configure a consumer Google account to only have secure options listed.

Re: The transition from logins to cryptographic passkeys is getting messy

#58
post #29

Oh, what could go wrong! Why is there no discussion on users losing their private keys? Ask all those cryptocurrency users who lost their private keys. Now don't tell that there are crypto wallets/vaults that manage private keys; there are many ways key can be lost even when using wallets/vaults. We engineers live in a different world, disconnected from the regular users who have no clue what public-private keys are!

I am in IT but not this side and I must admit I do not grok this move... At all. I don't understand the risk to Benefit story. It seems (possibly incorrectly) to put all my eggs into one basket - whether phone (which annoys the heck out of me as it is NOT my primary device) or some cloudy account I'm supposed to trust with my life. It also seems to impose geographical dependencies (I want to check my email at my frie…

The device is not mandated to be a phone. A hardware passkey is also an option. You carry the keys to your home everywhere, don’t you? And you take good care of them? Why would carrying a webauthn-compliant hardware key be any different?

Re: The transition from logins to cryptographic passkeys is getting messy

#59

Earlier quoted context omitted.

I am in IT but not this side and I must admit I do not grok this move... At all. I don't understand the risk to Benefit story. It seems (possibly incorrectly) to put all my eggs into one basket - whether phone (which annoys the heck out of me as it is NOT my primary device) or some cloudy account I'm supposed to trust with my life. It also seems to impose geographical dependencies (I want to check my email at my frie…

The device is not mandated to be a phone. A hardware passkey is also an option. You carry the keys to your home everywhere, don’t you? And you take good care of them? Why would carrying a webauthn-compliant hardware key be any different?

If I lose the keys to my house, I break the window, enter the house and change the lock. If I use my digital keys, It's over.

Re: The transition from logins to cryptographic passkeys is getting messy

#60

Earlier quoted context omitted.

I am in IT but not this side and I must admit I do not grok this move... At all. I don't understand the risk to Benefit story. It seems (possibly incorrectly) to put all my eggs into one basket - whether phone (which annoys the heck out of me as it is NOT my primary device) or some cloudy account I'm supposed to trust with my life. It also seems to impose geographical dependencies (I want to check my email at my frie…

The device is not mandated to be a phone. A hardware passkey is also an option. You carry the keys to your home everywhere, don’t you? And you take good care of them? Why would carrying a webauthn-compliant hardware key be any different?

If you lose your keys, you can replace them pretty easily. The mental model for doing so is pretty simple and doesn't require contacting tens or hundreds of websites.

I'm pretty skeptical that passkeys are going to yield much benefit. Websites will still have to maintain a "recovery" flow for the reason above and this is already the weakest link a lot of the time.

Post reply on HN