Live data from Hacker News

Tailscale doesn't want your password

tailscale.com

241–250 of 316 posts

Re: Tailscale doesn't want your password

#242

Earlier quoted context omitted.

Thank you. It is disheartening that so many HN readers would rather imagine how passkeys work, and freak out at their own imaginings, than just learn the real thing.

Yep, that's what frustrates me as well, especially for a technology that will be a massive gift to both security and usability.

Have a look around this thread. Lots of smart people having difficulties figuring out how this works. This is a bad sign. It shouldn't be this hard to figure out the basics.

Re: Tailscale doesn't want your password

#243

Earlier quoted context omitted.

Yep, that's what frustrates me as well, especially for a technology that will be a massive gift to both security and usability.

Have a look around this thread. Lots of smart people having difficulties figuring out how this works. This is a bad sign. It shouldn't be this hard to figure out the basics.

I don't see people having trouble grasping the technical specifics, I see a lot of people having knee-jerk reactions and reacting to their own assumptions of how Passkeys work.

Re: Tailscale doesn't want your password

#244

Earlier quoted context omitted.

You can do this with Passkeys. You can write your Passkey down on a post-it, or memorize it and cross the border with it, or anything you want. This thread has urged me to write a post clarifying some of the misconceptions I always see: https://www.stavros.io/posts/clearing-up-some-passkeys-misco...

Thank you. It is disheartening that so many HN readers would rather imagine how passkeys work, and freak out at their own imaginings, than just learn the real thing.

Somewhat fair criticism, but also somewhat unfair. A lot of us are trying to read up and understand, and so we post questions in forums like these with knowledgeable folks, in hopes to enhance our understanding and reduce our concern.

One counter point though is that... if there is a new lifesaving technology, and even the somewhat IT literate / somewhat geeky / folks who WANT to understand it, are struggling... it may not be as simple and easy and safe. If I ask "how do I backup my passwords", I'll have 10 million folks answer "use a password manager, backup the file". When I ask similar questions with passkeys, the breadth,inconsistency and complexity of answers is as insightful as it is worrisome.

Re: Tailscale doesn't want your password

#245

Earlier quoted context omitted.

Have a look around this thread. Lots of smart people having difficulties figuring out how this works. This is a bad sign. It shouldn't be this hard to figure out the basics.

I don't see people having trouble grasping the technical specifics, I see a lot of people having knee-jerk reactions and reacting to their own assumptions of how Passkeys work.

Because you are a) not explaining as well as you seem to believe and b) reacting with hostility and snobbery when you are called out on that fact.

Re: Tailscale doesn't want your password

#246
post #113

The comments are full of statements regarding security capabilities for passkeys. But there is no public specification that even defines requirements for the exchange of passkeys between devices. Google and Apple make statements on their websites regarding the security, but all of it is practically unverifiable. Please note that end-to-end encryption is useless, if you are not controlling all the endpoints. Sites of…

It is telling to me that the passkey spec has provisions for attestation which will allow lock-in by providers and lock-out by websites based on your provider, but questions of backup, account restore and interoperability between providers receive some hand-wavy "the market will figure it out" response.

Re: Tailscale doesn't want your password

#247

Earlier quoted context omitted.

That was helpful but there's a difference between "possible" and "feasible in practice for the vast majority of users". Eg, you can theoretically develop your own passkey device as you say, but that doesn't mean most people can . I'm not sure I really prefer passkeys less than passwords but I do think some of the "misconceptions" aren't really misconceptions, but realistic concerns about what happens in practice. It…

But you don't need most people to develop their own Passkey device any more than you need most people to make a phone. A company will make it, vote with your wallet and buy the one that suits you. I'm looking forward to BitWarden supporting Passkeys, for example, as that's my preferred way of using them.

If I have an iPhone, Mac, Windows PC, and Android Tablet I want to know and talk about what I can do with Passkeys, not what could theoretically be done. After all, I'm not looking at Passkeys for an academic exercise. I'm actually looking to see how feasible it is for me to use Passkeys to replace my passwords today.

If that means "install BitWarden on all of your devices. The devices will work with it and you can backup/export your key locally" that's fantastic, I'd love to see a guide on how to get that going on all of my devices. However, if that means "according to the standards, something like a BitWarden could do what you want it to do, if they built it, allowed export, and the devices all allowed integration. Alternatively, you replace your devices with ones that do." then I really don't care what the theory says could be done, Passkeys cannot actually replace my use of passwords at the moment.

Re: Tailscale doesn't want your password

#248

Earlier quoted context omitted.

But you don't need most people to develop their own Passkey device any more than you need most people to make a phone. A company will make it, vote with your wallet and buy the one that suits you. I'm looking forward to BitWarden supporting Passkeys, for example, as that's my preferred way of using them.

If I have an iPhone, Mac, Windows PC, and Android Tablet I want to know and talk about what I can do with Passkeys, not what could theoretically be done. After all, I'm not looking at Passkeys for an academic exercise. I'm actually looking to see how feasible it is for me to use Passkeys to replace my passwords today. If that means "install BitWarden on all of your devices. The devices will work with it and you can b…

That's up to you, but "that isn't possible yet with this two-month-old technology" is very different from "that isn't possible".

Re: Tailscale doesn't want your password

#249

Earlier quoted context omitted.

This will vary depending the provider, but you could think of passkeys getting synced between devices in much the same way that saved passwords get synced. Apparently Google's implementation stores an encrypted backup of the passkeys in your Google account [1]: > A single passkey identifies a particular user account on some online service. A user has different passkeys for different services. The user's operating sys…

> So, if you use Google to store passwords or passkeys, it would be a good idea to save backup codes for your Google account somewhere safe. (Like you should do anyway.) Alternatively, if you're locked out of your Google account, these passkeys are also dead as the encryption keys are bound to the account. And passkey reset through email for instance would also probably out of question if it was your primary email ac…

Yes, if your threat model is "what if Google locks me out?" Then you won't want to rely on a Google passkey as your only way of logging into a website.

Ideally, websites will support multiple passkeys per account. I think having both Google and Apple passkeys would be sufficient since I think I would be unlikely to be locked out of both.

Apparently Tailscale doesn't have multiple passkeys per account, but they recommend creating a backup admin account, and you could use a different kind of passkey for it.

Re: Tailscale doesn't want your password

#250

Earlier quoted context omitted.

If I have an iPhone, Mac, Windows PC, and Android Tablet I want to know and talk about what I can do with Passkeys, not what could theoretically be done. After all, I'm not looking at Passkeys for an academic exercise. I'm actually looking to see how feasible it is for me to use Passkeys to replace my passwords today. If that means "install BitWarden on all of your devices. The devices will work with it and you can b…

That's up to you, but "that isn't possible yet with this two-month-old technology" is very different from "that isn't possible".

Well, that's my point. People are referring to what is possible today but your "misconceptions" are responses to what could be possible in the future.
Post reply on HN