Live data from Hacker News

Passkeys: The beginning of the end of the password

blog.google

391–400 of 1001 posts

Re: Passkeys: The beginning of the end of the password

#391
post #385
post #357

Earlier quoted context omitted.

You need to click on the link that is in the post: https://blog.google/technology/safety-security/one-step-clos... > Instead, your phone will store a FIDO credential called a passkey which is used to unlock your online account. The passkey makes signing in far more secure, as it’s based on public key cryptography and is only shown to your online account when you unlock your phone. It looks like a token stored on your…

Well, guess it won't work for me. Rooted phone and prone to boot loops and hard resets whenever i get curious with some stuff. Every authenticator stored in the phone can't be recovered when you install a new ROM (google tries to send the authorization pop up to the previous version of the phone and, of course, it'll never get there) Guess that's the price i pay for using the hardware in a slightly different way than…

> Rooted phone and prone to boot loops and hard resets

> using the hardware in a slightly different way

Honestly I wouldn’t classify turning a daily driver device into a semi-brick (if it boot loops and has to be hard reset regularly…) as “slightly different”. If you want to experiment that’s fine, but why would you subject your daily driver to that? Or, why not just have a phone for stable use / real world stuff, and a phone for everything else?

To put it bluntly: you’re wildly out of touch with reality for most people. 99% of people who have a phone — even those people who install custom ROMs on their daily driver — either plan around having to deal with this stuff or have an escape hatch. Most people refuse to tolerate such an experience.

Re: Passkeys: The beginning of the end of the password

#392
post #357

Earlier quoted context omitted.

You need to click on the link that is in the post: https://blog.google/technology/safety-security/one-step-clos... > Instead, your phone will store a FIDO credential called a passkey which is used to unlock your online account. The passkey makes signing in far more secure, as it’s based on public key cryptography and is only shown to your online account when you unlock your phone. It looks like a token stored on your…

Why not call it a private key then, we've been handling those since the 70's. They don't need to be rebranded, they need to be taught in high school with the same words we've always used to talk about them.

[deleted]

Re: Passkeys: The beginning of the end of the password

#393
post #186

Earlier quoted context omitted.

> If Google/Amazon/Apple/Meta/whoever locks your account out, you now lose access everywhere. Fortunately, both iOS and Android also support "detachable passkeys" a.k.a. Yubikey and co. ("roaming authenticators" in WebAuthN/FIDO parlance). Unfortunately, only Android is planning to offer [1] a first-party Passkey provider API, because that's what I'll probably be using 99% of the time (finding my external authenticat…

> Fortunately, both iOS and Android also support "detachable passkeys" a.k.a. Yubikey and co That’s good to know. Although my concern would be, that’s really good for people who use YubiKeys, but regular people won’t, and they can then get bitten by account lockouts. Is there something regular users can do to use Passkeys (let’s say they use Google) and have some recourse if Google locks them out? Also, what happens…

Right now, the identity of an account is tied to knowledge of the email address and the password. Something you know. If you forget the password, you need access to the email account.

With passkeys,the identity of the account is tied to either a BIGTECH account, or to physical devices.

If BIGTECH locks you out or you lose access to all your physcial Yubikeys at the same time, you will never access the account tied to the passkeys again.

Re: Passkeys: The beginning of the end of the password

#394
post #357

Earlier quoted context omitted.

You need to click on the link that is in the post: https://blog.google/technology/safety-security/one-step-clos... > Instead, your phone will store a FIDO credential called a passkey which is used to unlock your online account. The passkey makes signing in far more secure, as it’s based on public key cryptography and is only shown to your online account when you unlock your phone. It looks like a token stored on your…

So it's like a private key but you can't access or manage it, as it's owned by Google/Apple/Microsoft? How convenient!

Not sure if you’re being sarcastic, but that really is convenient.

Re: Passkeys: The beginning of the end of the password

#395
They still haven't solved the portability problem, there still is no way to use a Passkey without interacting with a proprietary device or hardware, it's still pretty transparently going to enable vendor lock-in. This technology is harmful.

"But it's early days, portability is coming."

Google/Microsoft have been saying this for ages, and it hasn't happened yet. And there's no effort being made to mandate portability as part of the spec, so even if the companies ever actually get around to allowing cross-ecosystem sharing, there are still going to be implementations that don't support portability. And honestly at this point I feel like it is an "if" not a when because Google and Microsoft and Apple are not talking about this being early days, they are encouraging people to switch over right now. So if you launch a feature and you encourage people to start using it for everyday logins, and it doesn't support cross-ecosystem export/import, then it doesn't seem like that's a priority or a blocking issue.

"But 1Password will support this"

No, 1Password is looking to support cross-device syncing, it's not allowing you to move out of the 1Password ecosystem. It's just tying to the 1Password account instead of the hardware.

"But cross-ecosystem syncing would enable phishing"

We crossed that bridge. If you can sync passkeys between devices (and every major player is going to allow that), then there are phishing risks. iCloud accounts can be hacked. Your 1Password account can be compromised. It's not for the sake of security that Apple allows syncing keys across devices but not to other ecosystems.

"Just use a Yubikey"

That's still proprietary hardware and the recovery process that people advocate for with Yubikeys is ridiculous and unworkable. I'm supposed to have 2 keys that I keep in sync and store in different places. I have enough trouble synchronizing Org-mode files between computers, that is not a feasible way to manage account logins.

I refuse to get excited for or advocate for a technology that at this point is just transparently about vendor lock-in, no matter how many times that advocates say it's not. Every time I look into this I wonder if something has changed, but last I checked FIDO alliance is not looking to standardize portability, they're just leaving it up to individual companies. Well, what that means is that maybe if you're lucky you'll be able to sync keys from Microsoft to Apple and vice-versa. You won't be able to sync those keys to a Linux computer (Chrome's implementation of login doesn't even work on Linux without a hardware key, you literally can't use that computer to log-in without a separate non-Linux device).

We should reject this. Passwords have real problems and a key-based authentication system would be a major improvement. It stinks that it's being run this way. And it stinks that advocates for Passkey are trying to argue that it's Open when there's not a single non-proprietary implementation on the entire market. It honestly feels deceptive to me, I have no trust in the FIDO alliance right now. There's been basically no visible progress on this, and every time the issue gets raised, somebody shows up to say that we just need to wait longer. Well... now it's launching. And surprise, we need to wait longer.

Re: Passkeys: The beginning of the end of the password

#396
post #394

Earlier quoted context omitted.

So it's like a private key but you can't access or manage it, as it's owned by Google/Apple/Microsoft? How convenient!

Not sure if you’re being sarcastic, but that really is convenient.

Until it's not and they decide you shouldn't exist anymore.

Re: Passkeys: The beginning of the end of the password

#397
post #357

Earlier quoted context omitted.

You need to click on the link that is in the post: https://blog.google/technology/safety-security/one-step-clos... > Instead, your phone will store a FIDO credential called a passkey which is used to unlock your online account. The passkey makes signing in far more secure, as it’s based on public key cryptography and is only shown to your online account when you unlock your phone. It looks like a token stored on your…

So it's like a private key but you can't access or manage it, as it's owned by Google/Apple/Microsoft? How convenient!

My reaction as well. From Google's FAQ:

> Passkeys created on Android are backed up and synced with Android devices that are signed in to the same Google Account, in the same way as passwords are backed up to the password manager.

I don't like this. Time will tell if Google's implementation will be open source, and if third parties can hook into the OS level integration. I certainly don't like the lack of emphasis on interoperability from the get go.

I do not like this future.

Re: Passkeys: The beginning of the end of the password

#398
post #241

Earlier quoted context omitted.

Personally I don't want to be dependent on a third party like Google or Apple for my identity. That's never going to be acceptable. If they just accept normal Yubikeys (and multiple at a time for redundancy) that'd work for me but this passkey stuff where the vendor gets to decide things and I don't fully own my credentials is just wrong IMO. I wonder if there's a fully self hosted passkeys option? I'm also opposed t…

> I wonder if there's a fully self hosted passkeys option? If external authenticators work for you, physical keys (like Yubikey, Solokey etc.) are arguably self-hosted! For on-device passkeys, at least Android is preparing an API for this [1]. I hope that iOS will follow at some point, as well as Firefox (which unfortunately has been quite slow to adopt all aspects of WebAuthN). > I'm also opposed to attestation. Wit…

> In principle I agree, but some service providers like banks are legally liable for fraud losses (at least in some jurisdictions). I'd say they do have a legitimate interest of being able to verify which authenticators they trust.

I have yet to see a bank use login restrictions to make itself more secure. I've been trying to get my bank to offer actual 2FA for years, and their response is that they moved from offering SMS/Email codes to only offering SMS codes.

A bank should not have control over what authenticator app I'm using. Their authenticator apps that they do have are terrible and my security would be improved if I could just use a simple 2FA app. In practice, this is just a way to make it so that DeGoogled devices, Linux devices, etc... won't be able to interact with normal services because they're "less secure". And the companies saying that will be the same ones asking me for authentication over the phone via my mother's maiden name. They don't need this, they're not technically qualified enough to have this level of control over what devices I use.

I honestly don't think attestation should have been part of the spec at all. There is an extremely narrow range of instances where knowing what client/hardware/OS someone is using is justifiable, and in almost all of those instances you should probably be directly controlling the hardware itself (providing a phone for your employees, installing a kernel module, etc...)

And there's nothing official to discourage companies from using attestation other than some vague "but don't do this if you don't need to" language. It's a bad idea that will be used to restrict people's control over their own devices that they own.

At least today these services all offer websites so I can still log on and use them without installing an app. But with attestation we're moving towards a future where you won't be able to log into your bank unless you own a "supported" Android device or an iPhone, and rooting those devices will mean that you don't have access to online banking services all of the sudden.

Re: Passkeys: The beginning of the end of the password

#399
post #391
post #385

Earlier quoted context omitted.

Well, guess it won't work for me. Rooted phone and prone to boot loops and hard resets whenever i get curious with some stuff. Every authenticator stored in the phone can't be recovered when you install a new ROM (google tries to send the authorization pop up to the previous version of the phone and, of course, it'll never get there) Guess that's the price i pay for using the hardware in a slightly different way than…

> Rooted phone and prone to boot loops and hard resets > using the hardware in a slightly different way Honestly I wouldn’t classify turning a daily driver device into a semi-brick (if it boot loops and has to be hard reset regularly…) as “slightly different”. If you want to experiment that’s fine, but why would you subject your daily driver to that? Or, why not just have a phone for stable use / real world stuff, an…

Ok, i wasn't specific enough, that's on me.

My previous phone was a Xiaomi. Part of the reason they're cheaper than competitors with similar hardware is because that thing is filled to the brim with useless ads, extra tracking way beyond just crash analytics for the manufacturer and the regular google stuff and even some useless "phone booster" app embedded in the settings.

After waiting the two weeks so Xiaomi would allow me to unlock the bootloader (which is bullshit, by the way), i installed LineageOS.

The problem is that the regular updates with security patches sometimes would cause a boot loop. Some times is something as simple as a system file becoming read only, sometimes no thread on XDA developers could guide me to the right solution, and then i just do a factory reset and start over.

But aside from flashing lineage and an ad blocker, my usage is the same as anyone else: answer calls, use messaging apps, browse the web, play games and edit some documents when i'm far away from my PC.

My current phone is a motorola, though, and while i think the official ROM is pretty disappointing (too many pop ups nagging me to sign up to motorola or check motorola apps), as long as i can flash magisk and an ad blocker, i'm a happy person.

Re: Passkeys: The beginning of the end of the password

#400
post #294

The paragraph in the section, "What are passkeys?" tells me that they: are new, are easier, let me use biometrics, and are resistant to attacks. But, it doesn't tell me what passkeys actually are. Compare passkeys to traditional authentication factors. What's a password? A secret word or phrase that only you know. What are biometrics? Parts of your body that can help uniquely identify you, like your fingerprint or re…

It’s a password that Google controls so when they incorrectly ban you from their services you lose access to literally everything. Or if you drop your phone in a lake you’re out of luck too.

Banning has nothing to do with it.

You use passkeys as a preferred login method.

If you do not have your passkey, you can tap "Try Another Way" and use your password as usual.

Post reply on HN