Live data from Hacker News

Tailscale doesn't want your password

tailscale.com

281–290 of 316 posts

Re: Tailscale doesn't want your password

#281

Earlier quoted context omitted.

You mean the industry nobody can leave because there's no way to live modern life without a bank account and they know it?

Exactly! :-) Companies aren't willing to lose customers at scale, but they aren't doing anything for the customers if they won't lose them anyway. For most services, most customers except for some diehard ideologists would just bend over and begrudgingly go with the attested option. And a company won't bother using engineer's time if it's only a few people. So minimum-value random internet blog is probably not going…

The issue, though, is attestation doesn't really do much for the site either. It's not like the bank wants to enable attestation because it's somehow more secure. It's only useful in cases where a company wants to say "we only want you to use Yubikeys because that's what HR has approved", not so much for sites mandating what their customers should use.

This is a bit like worrying that sites will block 1password and only allow LastPass. Why would they, even if they could?

Re: Tailscale doesn't want your password

#282

Earlier quoted context omitted.

Again. No system that I know about provides those properties today, so your "use one" advice is, unfortunately, impossible at the moment. Well, without having that rite I've already mentioned a few times (which violates the "convenience" property). It's an open standard that everyone are building siloed systems on. It's exactly as you have said - I'm not locked in to any single company, but if I have devices or progr…

I don't think that's the case. Yes, you'll have to wait a little while, but it's not like many sites support this today anyway. Very soon, most password managers will support it (KeePass does today, AFAIK), and then you can use your password manager as your Passkeys provider on all your devices.

> KeePass does today

Not yet: https://github.com/keepassxreboot/keepassxc/issues/8214 (and https://github.com/keepassxreboot/keepassxc/pull/8825)

And even if they will, they're at mercy of e.g. Apple letting anyone to replace iCloud Keychain with a third-party password manager. Which is also not possible yet. Probably the same for Android, although I'm not sure what's the situation there today. (But whatever it is, I would say that "well, don't use Apple/Google devices" is not an option for many in the current duopoly.)

All this can be solved, but the issue that is is not - today. So, today, I'm voicing my discontent.

> and then you can use your password manager as your Passkeys provider on all your devices

In an ideal world - yes. Sadly, I can't do this today with passwords, even though the world had spend many decades on trying to make things as seamless as possible. Over last year I've had to manually open a password manager on one device and type a password on another more than a few times.

The most obvious example is logging in to a streaming service on a smart TV - one step away from the normal conditions (scan-QR-code-on-my-phone flow not working) and typing password is the only option. Netflix is gonna love passkeys so users will possibly have slightly harder time logging in on others' devices ;-) BTW, sharing passkeys is also not exactly a solved issue - yet (even though some vendors made some promises).

Then, there's a case of accessing from untrusted devices (say, a net cafe). Theoretically, Passkeys should be a drastically superior solution to passwords - I would be able to plug in a security key, and it won't leak the keys, so even if a machine has a keylogger or network sniffer I'm still fine. In practice, however, enrolling a physical security key (Yubikey, Nitrokey, Solo) requires having it physically available, so it's always going to be inconvenient - and this is not changing until the standard extends or changes. Worse for multiple keys (I have four so every Webauthn sign-up is a pain in the ass). Because I'm most certainly not installing my password^W passkey manager on some untrusted machine.

Re: Tailscale doesn't want your password

#283
post #208

Earlier quoted context omitted.

> It sounds to me like passkeys are a simpler and more secure approach that apply within the existing context that requires unique complex passwords for every account. It does not to me. It requires complicated cryptography/tools. Passwords are just directly usable information that are much easier to reason about and work with. I can ask a question about passwords and I can figure out the answer or soltuion for mysel…

Most of your comment seems to be "I'd rather stay with an extremely insecure authentication scheme to avoid learning anything new".

Yes, valuing simple and thus very robust things that you can have full control over is somehow something that can just have the explanation you've given, and nothing else. :)

Re: Tailscale doesn't want your password

#284

Earlier quoted context omitted.

Exactly! :-) Companies aren't willing to lose customers at scale, but they aren't doing anything for the customers if they won't lose them anyway. For most services, most customers except for some diehard ideologists would just bend over and begrudgingly go with the attested option. And a company won't bother using engineer's time if it's only a few people. So minimum-value random internet blog is probably not going…

The issue, though, is attestation doesn't really do much for the site either. It's not like the bank wants to enable attestation because it's somehow more secure. It's only useful in cases where a company wants to say "we only want you to use Yubikeys because that's what HR has approved", not so much for sites mandating what their customers should use. This is a bit like worrying that sites will block 1password and o…

> Why would they, even if they could?

Because people are not always rational? Or because non-technical people (and technical people too, just less often) don't always make good technical decisions?

I can totally imagine a case where non-techie Joe starts a small shop, wants a website, sees an ad for a cheap hosting for non-techies, one-click installs Wordpress, goes to settings and ticks the checkboxes because "require secure devices" sounds secure. Or some other reason - people do weird things all the time, I can't count how many times I've looked at someone's server or website (including my own, especially after some time passes) and wondered why something is weird or plain wrong.

You're probably right, though. Attestation is very unlikely to be an issue, if Passkey implementations that don't have it will be popular enough to matter soon enough. And given that 1Password is spearheading it and Apple doesn't have it either - this is probably going to be true.

Attestation could become a real issue only if vast majority of available implementations by the time sites will start to adopt Passkeys will all provide it. Then site owners could make those mistakes and not even realize them. But that's not what seems to be happening so I'm sure attestation won't be a big deal.

Re: Tailscale doesn't want your password

#285
post #283

Earlier quoted context omitted.

Most of your comment seems to be "I'd rather stay with an extremely insecure authentication scheme to avoid learning anything new".

Yes, valuing simple and thus very robust things that you can have full control over is somehow something that can just have the explanation you've given, and nothing else. :)

Passwords are definitely simple and robust. Unfortunately, they aren't secure, a property we generally want in our authentication methods.

Re: Tailscale doesn't want your password

#286
post #173

Earlier quoted context omitted.

> Obviously, there are some necessary assumptions made, about security of the passkey implementation, DNS security and so on. Basically you need to trust more vendors of security solutions than before, isn't it? Plus you cannot access your accounts from any random device without an intricate security setup that eats at your time and messes with the device. As in you cannot borrow your friend's laptop for 5 min to che…

I knew I should've explained myself in more detail. Sorry. >Basically you need to trust more vendors of security solutions than before Yes and no. You may have to trust the vendor of your hardware key, or you can get one that has open source firmware, like NitroKey. Regarding the number of trusted parties - it depends. To have a account that use passwords, you must trust them to handle your password well. You can mit…

You say "even non-existant DNSSEC" here, but, as a reminder: virtually none of the most popular/important/commercial/whatever-ranking-you-like zones on the Internet are signed. DNSSEC signing is not the norm.

Re: Tailscale doesn't want your password

#287
post #283

Earlier quoted context omitted.

Yes, valuing simple and thus very robust things that you can have full control over is somehow something that can just have the explanation you've given, and nothing else. :)

Passwords are definitely simple and robust. Unfortunately, they aren't secure, a property we generally want in our authentication methods.

> ...unique passwords per account...

Re: Tailscale doesn't want your password

#288

Earlier quoted context omitted.

While I do agree that thread is different, it'd make sense to reply to that thread about it instead of this one.

I don't think it is different. I mostly see people dismissing Passkeys as a technology because of X or Y thing that "they don't do", when that's either a mistaken assumption, or something they don't do right now .

Mistaken assumptions, sure. What "mostly" people do maybe, it depends on those conversations. What Passkeys might do in the future is irrelevant to whether it makes sense for people to be dismissing them now, though, and confusing/frustrating to read about in these kinds of threads (maybe not other threads).

Today, you can seamlessly sync your passwords, export them, and utilize auto-fill integration across the aforementioned devices. Not "it could be possible based on the design if the manufacturers and apps wanted to do it", it is possible.

Today, it is not possible to do the same on those devices using Passkeys. That's not the same as claiming "it's guaranteed to forever be impossible because of the inherent design of Passkeys" and reading every conversation as such could well be the source of why the misconceptions seem so common. There is little to no guarantee from any of these manufacturers it will ever be possible either, so predicating the conclusion on that possibility of change definitely occuring isn't sensible. Again, not because the Passkey spec can't, the devices/implementations may just not want to. Remember, the spec doesn't require devices and implementations allow it to happen, it just accommodates for the possibility.

If implementations available for people to actually use change in the future, so will the dismissals. In the meantime, the dismissals of what's not possible are not misconceptions just because it's possible it may change down the line. It still remains impossible right now, even though I'm hopeful it will become possible in the future.

And again, sure - other threads probably have a lot of flat mistakes or different claims. But, if I wanted to discuss what other threads are saying, I wouldn't be reading and replying in this one.

Re: Tailscale doesn't want your password

#289
post #287

Earlier quoted context omitted.

Passwords are definitely simple and robust. Unfortunately, they aren't secure, a property we generally want in our authentication methods.

> ...unique passwords per account...

Still not secure enough, sadly. They can be captured, leaked, stolen, phished, etc, and that's if you use them correctly.
Post reply on HN