Live data from Hacker News

Tailscale doesn't want your password

tailscale.com

181–190 of 316 posts

Re: Tailscale doesn't want your password

#182

Earlier quoted context omitted.

I've spent about 10 minutes Googling, and I'm still not sure how I backup and restore passkeys. I use a password manager with a full backup of the vault, so the answer to most of the parent's question would be solved by getting the vault back from backup. Except: - passkeys are not yet supported by my password manager, so I'd have to wait for a while - can I move Safari's passkeys to my password managers afterwards,…

I don't know about Windows, but if you see the example your Mac is putting it in your keychain app, which is usely available on other devices that are connected to your Apple account. Also if you install a new macbook. Most likely also on your iphone. If you have an Android phone that will be a lot less smoot

I had the impression that Apple stores and syncs them for you, but at no point will give you the option to actually backup or restore (have a copy of the info under your management). Let's say I need to move a credential from my account to my wife's, I guess it's probably not allowed. Or god forbid I change Apple IDs.

Re: Tailscale doesn't want your password

#183

Earlier quoted context omitted.

It's way simpler than you think. You reset your passkey the same way you'd reset your password. So, how do you reset your password when you forget it? Well, it depends. Some apps/sites just send you a password reset email. Apps/sites like those would reset your passkey the same way: they'd send you a passkey reset email, you'd click the link in the email, and they'd let you regenerate your passkey then and there. Som…

I've spent about 10 minutes Googling, and I'm still not sure how I backup and restore passkeys. I use a password manager with a full backup of the vault, so the answer to most of the parent's question would be solved by getting the vault back from backup. Except: - passkeys are not yet supported by my password manager, so I'd have to wait for a while - can I move Safari's passkeys to my password managers afterwards,…

You can set up as many as you want, so just register your phone as one and your PC as other. Eg. using Windows Hello. If you loose or compromise one device, you just delete it as a passkey - rest is still working. If you loose all of them at the same time somehow, there's usually fall back to password or some kind of reset process.

Re: Tailscale doesn't want your password

#184
post #118

Earlier quoted context omitted.

This is indistinguishable from the "I don't trust my computer" threat model. Apple could also surreptitiously scrape your screen or copy your processes' memory.

The difference is the effort it takes. Deactivating E2E is just a flag.

There is no need to mess with the E2E, the client installed on your machine is downloaded form their servers, they can just copy the data when it is decrypted locally.

I does not make sense to use a proprietary internet connected application on your machine and worry that that the servers might be nefarious.

Re: Tailscale doesn't want your password

#185

Earlier quoted context omitted.

> I have already had several malicious login attempts Doesn't that mean they know your username and password? How does that happen so easily.

The last time I used Microsoft Authenticator (which was quite a few years ago), I noticed it would send me a request regardless of whether the correct password was entered or not. I suppose this is one of those "security by obscurity" type measures where they don't want to reveal whether the password was correct or not before MFAing. However, this results in non-stop requests because every few hours someone somewhere…

MS still has not solved the notification fatigue but now the SSO gives you a 2 digit number you need to insert in the app.

This solves the problem of accepting the wrong login by mistake

Re: Tailscale doesn't want your password

#186
post #173

Earlier quoted context omitted.

> Obviously, there are some necessary assumptions made, about security of the passkey implementation, DNS security and so on. Basically you need to trust more vendors of security solutions than before, isn't it? Plus you cannot access your accounts from any random device without an intricate security setup that eats at your time and messes with the device. As in you cannot borrow your friend's laptop for 5 min to che…

I knew I should've explained myself in more detail. Sorry. >Basically you need to trust more vendors of security solutions than before Yes and no. You may have to trust the vendor of your hardware key, or you can get one that has open source firmware, like NitroKey. Regarding the number of trusted parties - it depends. To have a account that use passwords, you must trust them to handle your password well. You can mit…

> In general, no. Assuming they run a reasonably recent version of Chrome and Windows/Linux/Android* (I don't have apple so idk), it will work driverlessly.

What will work driverlessly? The generating of new keys that still will take an hour?

Also excuse me, but did you just say Chrome? I should send Google my browsing so I can use passkeys?

Edit: forgot to mention their AI bans with no appeal process. Do you really want your sole login means in there?

Re: Tailscale doesn't want your password

#188
post #169
post #106

Good. I get they don't want to be responsible for keeping user credentials. But requiring permission from a big tech company to manage or access your own networks boggles my mind and made me not use it. Now if only they supported this for setting up the entire account too, as opposed to additional users only. I hope that's coming.

I'm guessing you are talking about signing up with them? If I understood the docs correctly, it looks like they allow signing up with custom oidc provider. May be worth looking into it if your only concern with their service is delegating access via big tech.

Yeah absolutely - I think this is a relatively recent change for them. The only thing stopping me from doing that is that 1) setting up an OIDC server for personal use is a lot of work I don't necessarily want to do, especially if it's just for Tailscale 2) this announcement suggests they may be working a full passkey setup, which would make that work useless.

Re: Tailscale doesn't want your password

#189

Earlier quoted context omitted.

It's way simpler than you think. You reset your passkey the same way you'd reset your password. So, how do you reset your password when you forget it? Well, it depends. Some apps/sites just send you a password reset email. Apps/sites like those would reset your passkey the same way: they'd send you a passkey reset email, you'd click the link in the email, and they'd let you regenerate your passkey then and there. Som…

I've spent about 10 minutes Googling, and I'm still not sure how I backup and restore passkeys. I use a password manager with a full backup of the vault, so the answer to most of the parent's question would be solved by getting the vault back from backup. Except: - passkeys are not yet supported by my password manager, so I'd have to wait for a while - can I move Safari's passkeys to my password managers afterwards,…

> I've spent about 10 minutes Googling, and I'm still not sure how I backup and restore passkeys.

In the Apple ecosystem your passkey is / can be sent to your iCloud Keychain, which you can restore when you can a replacement device (and keep using on non-lost/stolen devices):

* https://support.apple.com/en-ca/guide/iphone/iph82d6721b2/io...

* https://www.google.com/search?q=apple+passkey+icloud

Re: Tailscale doesn't want your password

#190
post #176

Earlier quoted context omitted.

> The passkey people won’t give you a straightforward answer because you won’t like the answer. Well, then this culture needs to be condemned strongly.

Why? Security isn't an opinion, it's a science and art. It doesn't care about what you think of it. Perfect security leaves no room for user friendliness. The most secure system allows no users to use it. Only by reducing security do you gain user friendliness. The most user friendly (as in, triviality of use) system requires no security. The art comes in when trying to create more usability whilst giving up less sec…

[deleted]
Post reply on HN