Live data from Hacker News

Tailscale doesn't want your password

tailscale.com

21–30 of 316 posts

Re: Tailscale doesn't want your password

#21
post #14
post #4

Earlier quoted context omitted.

When you use passkeys with either Apple's iCloud Keychain or Google Password Manager, the key material is end-to-end encrypted. Law enforcement cannot get your passkeys through these two big tech companies.

e2e encryption is one forced update away from being plain text.

I trust big tech companies more than I trust startups or smaller tech companies. I have faith that neither Apple nor Google would do that.

This is a personal belief based on chatting with Apple and Google employees. You don't have to agree.

Re: Tailscale doesn't want your password

#22
My work uses Microsoft SSO for everything. Passkeys aren't enabled though. And management won't enable them on Azure AD. Instead, they enable the tried and tested and ultra secure method of SMS based 2FA with a password. (This is sarcasm.) The alternative is the Microsoft authenticator app with its associated risk of approval fatigue. I have already had several malicious login attempts. Fortunately I'm attuned enough to decline them.

The only way I'll get passkey logins for my work account is if Microsoft force it as a 2FA method for enterprise. I won't hold my breath.

Re: Tailscale doesn't want your password

#23

Earlier quoted context omitted.

This is a great point. And to respond to the other part of the parent comment about storing "all their credentials with one of the large tech companies" — you don’t even need to do that, if you don’t want to. Apple just extended their Credential Provider API such that passkeys can now be synced using external providers, meaning password manager apps can save and offer passkeys on iOS, iPadOS, and macOS. So you can ch…

You guys conveniently ignores the fact that Apple and Google are still the gatekeepers in that scenario.

How so

Re: Tailscale doesn't want your password

#24

I don’t understand why someone would want to store all their credentials with one of the large tech companies. It seems like this makes it really easy for law enforcement to grab access to all accounts easily.

Passkeys are WebAuthn under the hood; they don't store your credentials with a large company any more than using a hardware token stores your credentials with Yubikey. Apple does some additional trickery to synchronize credentials between devices, but they get away with this because their devices have contained dedicated silicon for sensitive data management for years[1]. They have some user-facing documentation on h…

Apple can synchronize the passkey between devices. As far as I understand I cannot. So I don't really understand how this can be said to be a hardware security token. It seems pretty clear that it is as far as I am concerned, but that Apple has nothing constraining them from copying my passkeys. Which seems like the worst of both worlds.

Re: Tailscale doesn't want your password

#25

Earlier quoted context omitted.

This is a great point. And to respond to the other part of the parent comment about storing "all their credentials with one of the large tech companies" — you don’t even need to do that, if you don’t want to. Apple just extended their Credential Provider API such that passkeys can now be synced using external providers, meaning password manager apps can save and offer passkeys on iOS, iPadOS, and macOS. So you can ch…

You guys conveniently ignores the fact that Apple and Google are still the gatekeepers in that scenario.

Yes you need to trust your operating system developer to some extent. If your threat model includes not trusting the company that writes the source code to your OS…don’t use computers I guess?

Re: Tailscale doesn't want your password

#26
post #4

I don’t understand why someone would want to store all their credentials with one of the large tech companies. It seems like this makes it really easy for law enforcement to grab access to all accounts easily.

When you use passkeys with either Apple's iCloud Keychain or Google Password Manager, the key material is end-to-end encrypted. Law enforcement cannot get your passkeys through these two big tech companies.

For apple, yes. but as i understand it, your passkeys are not synced or stored in google password manager, they are only stored on device and never synced through or stored on google servers.

Re: Tailscale doesn't want your password

#29

Like many round trips we have made, I suspect in the year 2035, we’ll look back and say to ourselves: “Yeah, password was super based. Just copy paste it in the box and you’re logged in. Can store it anywhere, even in a notebook. Safekeep it by printing them. No need for HyperBigTechCorp. Portable. Those gray beards had it right the whole time.” Can we please stop the bandwagon for a moment and inquire about the down…

How do you bootstrap it? You get robbed at gunpoint by some ruffians and they take your wallet, cellphone, keys, and laptop. Hopefully they can't get into your accounts, but never mind that, how do you get back in to everything?

Re: Tailscale doesn't want your password

#30
I haven't yet looked into the inner mechanics of passkeys, and the link only talks about the first login. What is the experience like when a user wants to log in from a different system? They press the "Login with Passkey" button on Device 2, and then...?
Post reply on HN