Live data from Hacker News

Passkeys: The beginning of the end of the password

blog.google

241–250 of 1001 posts

Re: Passkeys: The beginning of the end of the password

#241
post #135

WebAuthN is great, but I can't help but feel that Passkeys are actually a step backwards. At least on iOS, there is no way of preventing them from being synced to iCloud, which is the opposite of what I want for high-stakes credentials like bank accounts or government e-signatures. I've tried to raise [1] a related issue (i.e. the inability for relying parties to opt out of credential syncing, if not an explicit requ…

Personally I don't want to be dependent on a third party like Google or Apple for my identity. That's never going to be acceptable. If they just accept normal Yubikeys (and multiple at a time for redundancy) that'd work for me but this passkey stuff where the vendor gets to decide things and I don't fully own my credentials is just wrong IMO. I wonder if there's a fully self hosted passkeys option? I'm also opposed t…

> I wonder if there's a fully self hosted passkeys option?

If external authenticators work for you, physical keys (like Yubikey, Solokey etc.) are arguably self-hosted!

For on-device passkeys, at least Android is preparing an API for this [1]. I hope that iOS will follow at some point, as well as Firefox (which unfortunately has been quite slow to adopt all aspects of WebAuthN).

> I'm also opposed to attestation. With TOTP I can use any app I want and back up my keys however I like.

In principle I agree, but some service providers like banks are legally liable for fraud losses (at least in some jurisdictions). I'd say they do have a legitimate interest of being able to verify which authenticators they trust.

Of course, it's being already exploited in a pretty much expected way: My government offers a (free to end-users, tax paid) e-signature solution. They support, among other authentication methods, FIDO – but only a very specific authenticator, of which the e-signature service provider is the exclusive reseller in the country...

[1] https://developers.google.com/identity/passkeys/supported-en...

Re: Passkeys: The beginning of the end of the password

#242
I’m a Linux user. I don’t have an android/iOS/macOS/Windows machine.

Is there a solution? Is this being used to push Linux users off the internet? Can I just fire up emulated Android and be ok?

Am I screwed? Googling indicates I am, indeed, screwed. Pretty concerned about this future.

Re: Passkeys: The beginning of the end of the password

#243
post #210
post #98

I enabled passkey and literally nothing changed. Signed out and back in again several times.

Yeah, it's not doing anything for me either

Doesn't work here either. But I'm on Firefox on Linux, both of which are not yet supported as per the docs.

Firefox might get it around version 120: https://connect.mozilla.org/t5/ideas/support-webauthn-passke...

Re: Passkeys: The beginning of the end of the password

#245

The advantages are very poorly explained in the article. Last time I read about this, you could use your phone or a FIDO key to authenticate. Like if the phone was close to the computer you could aithenticate the same way you can unlock your computer with your watch. So either this new technology is so advanced lesser minds don’t understand it or it jus adds a more cumbersome authentication method instead of password…

My takeaway is that this is infinitly more secure for those do not care about security - the "password1234" crowd, actually their account may even be secure from them logging in from now on -, for the rest it is about the same, but different.

Re: Passkeys: The beginning of the end of the password

#246
post #5

How is this more secure? They say "with a fingerprint, a face scan or a screen lock PIN", but basically all phones let you fall back to PINs if you dont want to do face or fingerprints. Pins are flat out not secure - typically just 4 digits. Yeah its probably better than 80% of people having "password123", but it seems strictly worse than a password + password manager? Or at least just having proper 2FA.

Being tied to a device, it defeats the most serious threats of phishing and weak passwords, for which attacks can be mounted on a global scale.

2FA via SMS is still vulnerable. 2FA with an app like Google Authenticator or VIPAccess is more secure because it is tied to a device.

Re: Passkeys: The beginning of the end of the password

#248
post #241

Earlier quoted context omitted.

Personally I don't want to be dependent on a third party like Google or Apple for my identity. That's never going to be acceptable. If they just accept normal Yubikeys (and multiple at a time for redundancy) that'd work for me but this passkey stuff where the vendor gets to decide things and I don't fully own my credentials is just wrong IMO. I wonder if there's a fully self hosted passkeys option? I'm also opposed t…

> I wonder if there's a fully self hosted passkeys option? If external authenticators work for you, physical keys (like Yubikey, Solokey etc.) are arguably self-hosted! For on-device passkeys, at least Android is preparing an API for this [1]. I hope that iOS will follow at some point, as well as Firefox (which unfortunately has been quite slow to adopt all aspects of WebAuthN). > I'm also opposed to attestation. Wit…

> If external authenticators work for you, physical keys (like Yubikey, Solokey etc.) are arguably self-hosted!

Yes. And this is what I do with all my personal stuff (though I use the GPG mode on the yubikey, not Fido2). But, because a passkey can be backed up, websites targeting mainly passkeys will be likely to offer only a single authenticator to be enrolled. Of course with hardware authenticators that is not going to work. Lose that one and you're screwed. This is why multi-authenticator support is so important.

> For on-device passkeys, at least Android is preparing an API for this

Thanks, I'll have a look at that. I'd want it on the PC too though (BSD). But anyway, hopefully it will come. I never really looked at it, as for now the website acceptance part is still so low that it didn't matter anyway. For the ones I use regularly, only Office 365 supports it. I'm not interested in the old FIDO MFA mode, only full passwordless will do.

> Firefox (which unfortunately has been quite slow to adopt all aspects of WebAuthN).

Yes, this is really a PITA now. They really don't seem to give a ***, they only offer CTAP2 (full FIDO2 + PIN) mode on Windows. Still not working on Mac, Linux, BSD... It's been in this sorry state for years now.

> In principle I agree, but some service providers like banks are legally liable for fraud losses (at least in some jurisdictions). I'd say they do have a legitimate interest of being able to verify which authenticators they trust.

Banks here already use their own authenticators which they provide anyway, but yeah that's a point. Many other sites shouldn't be able to make such decisions though, IMO.

PS: I'm not sure why you are being downvoted, I really appreciated your insightful comment. Especially about the Android option I wasn't aware of.

Re: Passkeys: The beginning of the end of the password

#249
post #142

Earlier quoted context omitted.

How is this different than a password manager with encrypted cloud backup? Your recourse if someone breaks passkeys is legal, not technical. Security must be a balance with functionality, and this is a huge improvement over passwords. (Tangentially, it would be great if we got cryptographic digital identity cards like Estonia has for signatures but that’s more of a long term goal) Cloud sync (encrypted!) is important…

The difference is that I can choose my password manager on iOS (and thereby pick my desired security level for password synchronization or opt out of it completely), but not my Passkey synchronization backend: iOS forces these to be stored in iCloud Keychain. (Passkeys are unavailable without iCloud Keychain [1]!) Ideally, there would be a per-passkey UI option to opt out of synchronization at creation time. > Securi…

Okay so use a YubiKey?

I must be missing something but I do not get all this hand-wringing. Don’t like the passkey options from Google or Apple? Fine! Use the hardware authenticator you absolutely already have if you’re the kind of person who has these sorts of objections.

Post reply on HN