Live data from Hacker News

The transition from logins to cryptographic passkeys is getting messy

wired.com

81–90 of 154 posts

Re: The transition from logins to cryptographic passkeys is getting messy

#81

Earlier quoted context omitted.

The device is not mandated to be a phone. A hardware passkey is also an option. You carry the keys to your home everywhere, don’t you? And you take good care of them? Why would carrying a webauthn-compliant hardware key be any different?

If you lose your keys, you can replace them pretty easily. The mental model for doing so is pretty simple and doesn't require contacting tens or hundreds of websites. I'm pretty skeptical that passkeys are going to yield much benefit. Websites will still have to maintain a "recovery" flow for the reason above and this is already the weakest link a lot of the time.

Maybe think of the "recovery" flow as authentication itself and the passkey as a cache of the most recent valid check. Put you passkey manager under the same umbrella as your "recovery", or sync you passkeys through another service you trust.

Under this model, new authentication pretty much should always leaves a paper trail, while passkey login, could be more like the "remember me" cookie from the old days.

Sorry for the tangent, but has anyone ever heard anything about cross-device cookie synchronization?

Re: The transition from logins to cryptographic passkeys is getting messy

#82
post #78

Earlier quoted context omitted.

Twice in college, where I needed to have a roommate let me in. Once at my first home, where I climbed in through the bathroom window (this was a PITA - it was some 12 feet off the ground and just barely big enough to get through. Once at my current home, where I just used the porch door that I literally never lock. ---- And I'm actually pretty good about not losing my things. But over a 20 year span, I would have bee…

Wow. You are definitely many standard deviations from the norm! But all of these digital techniques also allow multiple keys and / or key recovery.

Nah, I think you might be. Most people I know have locked themselves out once or twice.

Re: The transition from logins to cryptographic passkeys is getting messy

#83

Earlier quoted context omitted.

> You carry the keys to your home everywhere, don’t you? Perhaps most people do. There's also quite a few people that lose those keys - perhaps through neglect or being stupid, perhaps through an accident or getting mugged. Note that of those unfortunate people that lose their keys, very, very few of them lose their house and everything in it as well - there's many paths to normally quick recovery that would need to…

I guess it's tricky because at work, a central secret store with permissions and some kind of audit trail is a good idea. At home some cloud backup / syncing should be done, but I don't think that replaces local backups and everything. What's the issue here, people can't export backups of the passkeys?

> What's the issue here, people can't export backups of the passkeys?

Quite the opposite. You can, and are always advised to, have a second key as backup that you can keep in a secure location. So in the same way as you don't lose your home if you lose your home's keys, you don't lose your digital access if you have a backup passkey. There is a slight difference between the two scenarios as in the case of your home, you wouldn't lose it regardless of whether you have a backup key or not. But since you can easily have a backup passkey the difference is very small.

Re: The transition from logins to cryptographic passkeys is getting messy

#84
post #78

Earlier quoted context omitted.

Twice in college, where I needed to have a roommate let me in. Once at my first home, where I climbed in through the bathroom window (this was a PITA - it was some 12 feet off the ground and just barely big enough to get through. Once at my current home, where I just used the porch door that I literally never lock. ---- And I'm actually pretty good about not losing my things. But over a 20 year span, I would have bee…

Wow. You are definitely many standard deviations from the norm! But all of these digital techniques also allow multiple keys and / or key recovery.

> You are definitely many standard deviations from the norm!

[citation needed]

Re: The transition from logins to cryptographic passkeys is getting messy

#85
post #59

Earlier quoted context omitted.

The device is not mandated to be a phone. A hardware passkey is also an option. You carry the keys to your home everywhere, don’t you? And you take good care of them? Why would carrying a webauthn-compliant hardware key be any different?

If I lose the keys to my house, I break the window, enter the house and change the lock. If I use my digital keys, It's over.

That's why you're always advised to have a backup passkey.

Re: The transition from logins to cryptographic passkeys is getting messy

#86

Earlier quoted context omitted.

> whichever software vault you're using Do consumers perceive a significant difference between "login with Facebook" and "login with LastPass"? In both cases I'm delegating my security credentials to a cloud service I have limitted influence over.

Passkeys don't require any cloud provider.

[flagged]

Re: The transition from logins to cryptographic passkeys is getting messy

#87
post #29

Oh, what could go wrong! Why is there no discussion on users losing their private keys? Ask all those cryptocurrency users who lost their private keys. Now don't tell that there are crypto wallets/vaults that manage private keys; there are many ways key can be lost even when using wallets/vaults. We engineers live in a different world, disconnected from the regular users who have no clue what public-private keys are!

One. Hundred. Percent.

I have always maintained that 3rd party password managers were a bad idea because now you've got three parties heavily involved instead of two.

For most, this is that but worse -- you have essentially have three parties, and the least savvy is the one with the most to lose (maybe the ONLY one with something to lose) -- and is now the one with even less understanding and control.

Across the board, getting rid of passwords is a stupid idea. I get that what we have now isn't great, but this is way worse; I am certain this fails repeatedly and badly, unless we do the thing we haven't yet done, which is real cost/penalty/liability for the 3rd parties who get it wrong.

Re: The transition from logins to cryptographic passkeys is getting messy

#88

Earlier quoted context omitted.

The device is not mandated to be a phone. A hardware passkey is also an option. You carry the keys to your home everywhere, don’t you? And you take good care of them? Why would carrying a webauthn-compliant hardware key be any different?

If you lose your keys, you can replace them pretty easily. The mental model for doing so is pretty simple and doesn't require contacting tens or hundreds of websites. I'm pretty skeptical that passkeys are going to yield much benefit. Websites will still have to maintain a "recovery" flow for the reason above and this is already the weakest link a lot of the time.

In its core, WebAuthn is a way for a site to say "I want to authenticate" and the browser/device to say "OK, here are my credentials".

Nothing is stopping you from generating a private key from a password that you have in your head, and using that to authenticate to every site.

Obviously, if that password gets stolen, the thief can get into any of your accounts, but that's a choice you have to make. WebAuthn doesn't mandate a specific way of storing credentials.

Re: The transition from logins to cryptographic passkeys is getting messy

#89
post #83

Earlier quoted context omitted.

I guess it's tricky because at work, a central secret store with permissions and some kind of audit trail is a good idea. At home some cloud backup / syncing should be done, but I don't think that replaces local backups and everything. What's the issue here, people can't export backups of the passkeys?

> What's the issue here, people can't export backups of the passkeys? Quite the opposite. You can, and are always advised to, have a second key as backup that you can keep in a secure location. So in the same way as you don't lose your home if you lose your home's keys, you don't lose your digital access if you have a backup passkey. There is a slight difference between the two scenarios as in the case of your home,…

The difference is that normal people don't have 50-200 houses and don't have to toy with the main/backup keys for every single one of those + each time they add a new "house", which may be often.

Re: The transition from logins to cryptographic passkeys is getting messy

#90

Earlier quoted context omitted.

I am in IT but not this side and I must admit I do not grok this move... At all. I don't understand the risk to Benefit story. It seems (possibly incorrectly) to put all my eggs into one basket - whether phone (which annoys the heck out of me as it is NOT my primary device) or some cloudy account I'm supposed to trust with my life. It also seems to impose geographical dependencies (I want to check my email at my frie…

The device is not mandated to be a phone. A hardware passkey is also an option. You carry the keys to your home everywhere, don’t you? And you take good care of them? Why would carrying a webauthn-compliant hardware key be any different?

i have a bunch of copies of my house key, including one at a neighbors house and one in a realtor-style lockbox in my back yard. If I somehow lose all of them, I can still call a locksmith who can re-key my locks for maybe $300ish. There is no conceivable circumstance in which losing my key(s), no matter how badly I mess up, even if I only had one copy and threw it in the ocean in a fit of rage, will permanently deny me entrance to my home.

So... it does not seem like a very good analogy?

Post reply on HN