Earlier quoted context omitted.
A web password is effectively a private secret, that can be used, for example, to derive a ECC keypair, but this secret is passed around in plain text between your device and the target site or service. It might be encrypted on the wire, but it must be known by both. So any system that replaces web auth passwords is, worst case, just as bad as a password from a key-ownership perspective. Such a system also has the po…
The question is how do you recover it when you lose it? For a password I just click the “I forgot my password” link, I get an email with a link to click, and my account is recovered within minutes. I have recovered 15 year old accounts this way. If you can’t do that with passkeys, then the system is doomed to failure because people lose their credentials and devices all the time .
The transition from logins to cryptographic passkeys is getting messy
71–80 of 154 posts
Re: The transition from logins to cryptographic passkeys is getting messy
#72Earlier quoted context omitted.
The device is not mandated to be a phone. A hardware passkey is also an option. You carry the keys to your home everywhere, don’t you? And you take good care of them? Why would carrying a webauthn-compliant hardware key be any different?
If I lose the keys to my house, I break the window, enter the house and change the lock. If I use my digital keys, It's over.
Re: The transition from logins to cryptographic passkeys is getting messy
#73Earlier quoted context omitted.
I am in IT but not this side and I must admit I do not grok this move... At all. I don't understand the risk to Benefit story. It seems (possibly incorrectly) to put all my eggs into one basket - whether phone (which annoys the heck out of me as it is NOT my primary device) or some cloudy account I'm supposed to trust with my life. It also seems to impose geographical dependencies (I want to check my email at my frie…
The device is not mandated to be a phone. A hardware passkey is also an option. You carry the keys to your home everywhere, don’t you? And you take good care of them? Why would carrying a webauthn-compliant hardware key be any different?
Perhaps most people do. There's also quite a few people that lose those keys - perhaps through neglect or being stupid, perhaps through an accident or getting mugged.
Note that of those unfortunate people that lose their keys, very, very few of them lose their house and everything in it as well - there's many paths to normally quick recovery that would need to be replicated digitally.
Re: The transition from logins to cryptographic passkeys is getting messy
#74Earlier quoted context omitted.
Any time I use shellac as a wood finish, I get a layer of shellac on top of all my fingers. There’s no way the fingerprint scanning would work after that.
happily for you, you have the problem AND the solution! next time, (besides using gloves for once) drop a blob of shellac on a shallow container with flexible sides (silicone or any flimsy bottle cap). After a few hours, take off gloves and thumbprint for several minutes with very light pressure on the blob of shellac. after another few hours, tie some nylon ties to the side of the container and tighten every now and…
Re: The transition from logins to cryptographic passkeys is getting messy
#75Earlier quoted context omitted.
If I lose the keys to my house, I break the window, enter the house and change the lock. If I use my digital keys, It's over.
How many times have lost your house keys and needed to break the window and change the lock?
Once at my first home, where I climbed in through the bathroom window (this was a PITA - it was some 12 feet off the ground and just barely big enough to get through.
Once at my current home, where I just used the porch door that I literally never lock.
----
And I'm actually pretty good about not losing my things. But over a 20 year span, I would have been permanently locked out of digital accounts 4 times if you want to play this game.
For me, that's a complete non-starter. So recovery flows will HAVE to exist. At that point, we're right back to where we are now, where I'm much less worried that someone is going to crack the salt+hash of my password, and I'm much more worried that someone will call customer support and pretend to be me.
Re: The transition from logins to cryptographic passkeys is getting messy
#76Earlier quoted context omitted.
The standard mantra for physical key-based 2FA has always been "register two keys and keep one in a safe", which seems doable for important accounts (like banks and government stuff) but no way am I going to get a key out of my safe when I want to order a replacement part on JoesDiscountDishwasherParts.biz. I really wish there was a way to register your backup key through your primary key. Luckily, FIDO2 can fix a lo…
Wait - the way this works is you have a backup key, if you lose your primary you replace it using your backup. NB this is only needed when you move to a new device with a new secure enclave too, so at no point is this pizza situation likely.
Re: The transition from logins to cryptographic passkeys is getting messy
#77I can't wait for companies to use secure passkeys and still force me to use SMS 2FA with no option to disable it.
Microsoft "consumer" (live.com, etc) accounts are like this. They have a whole set of advanced, secure options like security keys, TOTP, etc but they force you to have either an email or SMS recovery option configured :( Google on the other hand, do this correctly. You can configure a consumer Google account to only have secure options listed.
Are you sure about that? I couldn't activate 2FA in my Google account for years because they didn't enable the option without giving a phone number first. Based on my HN experience, many users gave their phone number from the get go and therefore didn't notice that they couldn't activate 2FA without it.
Re: The transition from logins to cryptographic passkeys is getting messy
#78Earlier quoted context omitted.
How many times have lost your house keys and needed to break the window and change the lock?
Twice in college, where I needed to have a roommate let me in. Once at my first home, where I climbed in through the bathroom window (this was a PITA - it was some 12 feet off the ground and just barely big enough to get through. Once at my current home, where I just used the porch door that I literally never lock. ---- And I'm actually pretty good about not losing my things. But over a 20 year span, I would have bee…
But all of these digital techniques also allow multiple keys and / or key recovery.
Re: The transition from logins to cryptographic passkeys is getting messy
#79Oh, what could go wrong! Why is there no discussion on users losing their private keys? Ask all those cryptocurrency users who lost their private keys. Now don't tell that there are crypto wallets/vaults that manage private keys; there are many ways key can be lost even when using wallets/vaults. We engineers live in a different world, disconnected from the regular users who have no clue what public-private keys are!
I am in IT but not this side and I must admit I do not grok this move... At all. I don't understand the risk to Benefit story. It seems (possibly incorrectly) to put all my eggs into one basket - whether phone (which annoys the heck out of me as it is NOT my primary device) or some cloudy account I'm supposed to trust with my life. It also seems to impose geographical dependencies (I want to check my email at my frie…
It does seem like it. The things you mention aren't drawbacks of this technology, and this is par for the course for whenever I see discourse on WebAuthn. People just mention random fears that they have, the vast majority of which aren't true.
Re: The transition from logins to cryptographic passkeys is getting messy
#80Earlier quoted context omitted.
The device is not mandated to be a phone. A hardware passkey is also an option. You carry the keys to your home everywhere, don’t you? And you take good care of them? Why would carrying a webauthn-compliant hardware key be any different?
> You carry the keys to your home everywhere, don’t you? Perhaps most people do. There's also quite a few people that lose those keys - perhaps through neglect or being stupid, perhaps through an accident or getting mugged. Note that of those unfortunate people that lose their keys, very, very few of them lose their house and everything in it as well - there's many paths to normally quick recovery that would need to…
What's the issue here, people can't export backups of the passkeys?