Earlier quoted context omitted.
> And just a daily reminder that biometrics are usernames, they are not passwords. I think you should stop giving out this daily reminder. This meme has outlived its usefulness. Using face id to unlock a local key store to enable my device to sign a signed challenge from a site I want to log into with the private key stored on my device is not a 'username' in any meaningful sense. The problem is, the metaphor about p…
> If my non-technical parents said they were migrating all their accounts to passkeys, I would be very pleased. I wouldn't be worried about their inability to change their biometrics My 76 yr old dad can't do it. His phone is some shitty android trash that when he's setting up his biometrics, he shakes a bit, and it never stores the finger data correctly. I have to hold his finger and his phone at the same time to ev…
Passkeys: The beginning of the end of the password
101–110 of 1001 posts
Re: Passkeys: The beginning of the end of the password
#102To put it another way, it's not really any more secure than passwords.
Sure, there's a lower risk of password breaches, but if you're the target audience for passkeys, you probably also use a password manager with unique passwords per site (even if that manager is the one built into your browser and synced across your devices).
Re: Passkeys: The beginning of the end of the password
#103What happens if you lose all your hardware factors (eg if you have a home fire)? Are you just locked out of all your accounts with this approach?
Not if the Passkey was synced (ex: you used iCloud keychain). If the passkey was not synced, then I would have to assume it would be the same if you lost a physical hardware key.
Re: Passkeys: The beginning of the end of the password
#104Earlier quoted context omitted.
Not if the Passkey was synced (ex: you used iCloud keychain). If the passkey was not synced, then I would have to assume it would be the same if you lost a physical hardware key.
How do you access iCloud without your passkey?
Re: Passkeys: The beginning of the end of the password
#105Earlier quoted context omitted.
Also tangible and understandable is a registry of users who have access to your accounts, that allows you to grant and revoke access (at possibly different levels), without having to reset all your own credentials. I've got to quit commenting, but humans are undeniably the weakest link in security. While I understand the perceptions and even share some of the concerns expressed in this thread about the loss of contro…
> It's a few extra steps up front, but once it's working, it's so much easier. It's a few extra steps per site . Every time you get a new device you need to go back to every site you've ever visited and update the credentials. It is maybe feasible for a few important accounts but it doesn't scale. Whatever solution we have needs to be syncable and able to be exported to a safe once and continue to be usable by new si…
The device's hardware security facilities are there to protect the keystore. They aren't /the/ keystore.
Find a key manager. iCloud Keychain, Microsoft Authenticator, Bitwarden, something. Use that. Concerns about migrating devices dissolve away.
Re: Passkeys: The beginning of the end of the password
#106Earlier quoted context omitted.
> The only use-case for biometrics is deanonymization, sold to you under the auspices of security, primarily used for corporate surveillance. Please provide evidence that biometric data has ever been extracted from a major platform (IE Apple/enclave). Absence of evidence != evidence of absence, I know, but you’re selling it as the only use case so surely you have proof.
> Please provide evidence that biometric data has ever been extracted from a major platform Why extract it from a platform when it can be extracted easily from the person? Imagine your password was written on every surface you touched (fingerprint) or is prominently displayed on your social media accounts (face).
If the algorithm is not known, it’s only a matter of time it’d be leaked or reverse engineered. And then suddenly there’d be a massive, difficult to fix security breach. Just like the breaches that we have now, with voice based authentication.
Can someone explain, how this can be mitigated?
Re: Passkeys: The beginning of the end of the password
#107Earlier quoted context omitted.
> The only use-case for biometrics is deanonymization, sold to you under the auspices of security, primarily used for corporate surveillance. Please provide evidence that biometric data has ever been extracted from a major platform (IE Apple/enclave). Absence of evidence != evidence of absence, I know, but you’re selling it as the only use case so surely you have proof.
> Please provide evidence that biometric data has ever been extracted from a major platform Why extract it from a platform when it can be extracted easily from the person? Imagine your password was written on every surface you touched (fingerprint) or is prominently displayed on your social media accounts (face).
Everything you’ve described can be done whether or not I use biometric to sign into a device, or even own a device?
Re: Passkeys: The beginning of the end of the password
#108I am not a cryptographer: why would a 6-digit screen lock PIN with this system be any safer than a 6-digit numeric password on the web (i.e. not very)?
Re: Passkeys: The beginning of the end of the password
#109Earlier quoted context omitted.
[flagged]
To avoid being a propagandized lemming you have to have a basic understanding of what is happening... passkeys aren't tied to Google or to any other specific provider. Note that this announcement is just about Google supporting logging to with passkeys to their platform. But you don't have to have anything to do with Google to use passkeys with other sites/apps that support them.
It would be a totally different situation if customers were actually interested in a particular solution. Otherwise, it's all astroturfing and nothing can really change that.
Also it's always a good tone to put a disclaimer, e.g. "Googler".
Re: Passkeys: The beginning of the end of the password
#110In comparison to those, Google’s support seems better. It worked, was transparent about what was going on, and gave me the option to create the key on either the device I was using or another one if I wanted. The one hitch was that when I already had a 2FA key on the same platform authenticator, it just said I already had a registered key on this device and didn’t do anything. I would have expected some sort of upgrade flow for people who previously registered their devices for 2FA, or at least to more directly tell me to delete the existing security key on the device (which is what I did, and which worked).