Live data from Hacker News

Tailscale doesn't want your password

tailscale.com

51–60 of 316 posts

Re: Tailscale doesn't want your password

#51
post #33

[flagged]

I'm pretty sure passkeys are just a rebranded version of virtual WebauthN tokens. So while passkey secrets can be synced (unlike U2F physical tokens) they can also be implemented as being backed by a physical token (think Yubikey) that never goes om the cloud.

There is theory and there is practice. What grandparent comment says is the likely outcome in practice

Re: Tailscale doesn't want your password

#52
post #22

My work uses Microsoft SSO for everything. Passkeys aren't enabled though. And management won't enable them on Azure AD. Instead, they enable the tried and tested and ultra secure method of SMS based 2FA with a password. (This is sarcasm.) The alternative is the Microsoft authenticator app with its associated risk of approval fatigue. I have already had several malicious login attempts. Fortunately I'm attuned enough…

> My work uses Microsoft SSO for everything. Passkeys aren't enabled though. And management won't enable them on Azure AD.

I don't think they're actually available on AzureAD. That thing tends to lag like crazy in actual security features. FIDO support is relatively newish. IIRC it was generally available around the end of 2022. Only recently, you no longer have to register a phone number for password reset (which is different from login, mind (SSPR)).

> they enable the tried and tested and ultra secure method of SMS based 2FA with a password

This isn't actually that much worse than the MS recommended way of using their crappy authenticator. They even allow passwordless sign-in with that thing! The prompt doesn't tell you anything useful apart from "login with ?". Now, at least, they prompt you for a number you see on screen. It doesn't help with phishing, but at least you know the request comes from what you're doing, not someone else, since it also tended to drop any request if another one was pending.

Re: Tailscale doesn't want your password

#53
post #22

My work uses Microsoft SSO for everything. Passkeys aren't enabled though. And management won't enable them on Azure AD. Instead, they enable the tried and tested and ultra secure method of SMS based 2FA with a password. (This is sarcasm.) The alternative is the Microsoft authenticator app with its associated risk of approval fatigue. I have already had several malicious login attempts. Fortunately I'm attuned enough…

> I have already had several malicious login attempts Doesn't that mean they know your username and password? How does that happen so easily.

The line you quoted doesn't mean they know the password. But this one does:

> Fortunately I'm attuned enough to decline them.

There is only something to decline if they know your password.

Re: Tailscale doesn't want your password

#55
post #22

My work uses Microsoft SSO for everything. Passkeys aren't enabled though. And management won't enable them on Azure AD. Instead, they enable the tried and tested and ultra secure method of SMS based 2FA with a password. (This is sarcasm.) The alternative is the Microsoft authenticator app with its associated risk of approval fatigue. I have already had several malicious login attempts. Fortunately I'm attuned enough…

> I have already had several malicious login attempts Doesn't that mean they know your username and password? How does that happen so easily.

The last time I used Microsoft Authenticator (which was quite a few years ago), I noticed it would send me a request regardless of whether the correct password was entered or not. I suppose this is one of those "security by obscurity" type measures where they don't want to reveal whether the password was correct or not before MFAing. However, this results in non-stop requests because every few hours someone somewhere in the world attempts to penetrate my MS account.

This became so tiresome that I disabled MFA. Here's a hot take: if your MFA solution fatigues people to the point they disable MFA, you have a problem.

Also, I'm wondering if the OP might be referring to passwordless "Approve this login request" notifications rather than plain old MFA, where someone just needs to enter your email address and hope you approve the login request. Not sure if MS does this, but I know other apps that do.

Re: Tailscale doesn't want your password

#56

Earlier quoted context omitted.

> I have already had several malicious login attempts Doesn't that mean they know your username and password? How does that happen so easily.

They said login attempt, not successful login. So no.

Since they talked about the authenticator app, it depends on how it's set up. You can enable it for passwordless logins, so you'd get the prompt for knowing the account name.

Re: Tailscale doesn't want your password

#57

I don’t understand why someone would want to store all their credentials with one of the large tech companies. It seems like this makes it really easy for law enforcement to grab access to all accounts easily.

As a law abiding citizen, my willingness to put in extra effort to avoid law enforcement is pretty low.

Re: Tailscale doesn't want your password

#58
post #30

I haven't yet looked into the inner mechanics of passkeys, and the link only talks about the first login. What is the experience like when a user wants to log in from a different system? They press the "Login with Passkey" button on Device 2, and then...?

It presents a qr code you can scan with the other device. You can try it on https://passkeys.io

Very cool. Thanks.

Re: Tailscale doesn't want your password

#59
post #22

My work uses Microsoft SSO for everything. Passkeys aren't enabled though. And management won't enable them on Azure AD. Instead, they enable the tried and tested and ultra secure method of SMS based 2FA with a password. (This is sarcasm.) The alternative is the Microsoft authenticator app with its associated risk of approval fatigue. I have already had several malicious login attempts. Fortunately I'm attuned enough…

> My work uses Microsoft SSO for everything. Passkeys aren't enabled though. And management won't enable them on Azure AD. I don't think they're actually available on AzureAD. That thing tends to lag like crazy in actual security features. FIDO support is relatively newish. IIRC it was generally available around the end of 2022. Only recently, you no longer have to register a phone number for password reset (which is…

Oh right, thanks for clarifying that.

Re: Tailscale doesn't want your password

#60

Apple Slightly off topic: did Apple just make it super easy for law enforcement to unlock your phone & passkeys as part of iOS 17? > ”Apple ID. Securely sign in to your iPhone using a nearby device or any email address or phone number listed in your account.” https://www.apple.com/ios/ios-17-preview/

What the heck? SMS as a second factor was considered bad practice ten years ago. Allowing it to be used as the only factor to access your entire Apple ID is absolute negligence as SIM-swapping is still and forever will be trivial. I'm genuinely shocked. Engineers at Apple must have been screaming into their pillows at night as they watched some incompetent BA ignore all advice and force this through.
Post reply on HN