Live data from Hacker News

Passkeys will come at a cost

fy.blackhats.net.au

221–230 of 600 posts

Re: Passkeys will come at a cost

#221
post #213

Earlier quoted context omitted.

I can see how remote enrollment makes it easier for a user to share a key in a way they shouldn't, but not all that much easier. What other weaknesses will be introduced?

The ability to do auto-enrolment would break the per-site uniqueness of credentials (which makes them pretty strongly phishing resistant under most sane threat models where the browser isn't totally compromised) Right now, the public key from one token is unique to that site (and specifically your registration attempt with the site, so you can have multiple unlinkable accounts using the one FIDO2 key). If you could d…

> would break the per-site uniqueness of credentials

It wouldn't break things as I've described it. Each device would have a handful of pre-negotiated single-use public keys for the other device it could enroll with.

I tend to think there's no blockers and I just invented a better+obvious flow.

Re: Passkeys will come at a cost

#222
post #27

Is it even a good idea to use physical security keys as passkeys in the first place? Passkeys are meant to be a password _replacement_, and for that you probably want the 2-factor properties afforded by phones or desktops which usually require "something you know" or "something you are" to unlock in addition to the "something you have" afforded by physically possessing them. IMO physical security keys are better left…

> Passkeys are meant to be a password _replacement_,

No. Passkeys parasitize on FIDO2 U2F standard, that was developed to be (as the name implies) the second factor. Resident keys are meant for on-device 2FA with PIN, a functional replacement of smart cards.

Someone (Apple maybe) thought it’s a good idea to consider WebAuthn being good enough to be the only authentication factor (no resident keys, no hardware bond, keys are roamed via iCloud) but TouchID/FaceID protected on device. And they branded them as passkeys.

> and for that you probably want the 2-factor properties afforded by phones or desktops which usually require "something you know" or "something you are" to unlock in addition to the "something you have" afforded by physically possessing them.

You don’t. 2FA is not a goal on itself. The goal is to have user authentication that is protected from phishing, brute force and credential stuffing, and also not as hard to implement as smart cards.

FIDO2 does that. The problem with Apple’s, Google’s or Microsoft’s implementations is not that they are less secure on a protocol level between the authenticating site and the user’s device, that’s exactly the same protocol. The problem is that the site has now to trust user’s personal account in one of these platforms and that the user did the right thing and also the platforms will always be doing the right thing - e.g., they will handle attacks on user’s personal account properly.

Re: Passkeys will come at a cost

#223
post #102
post #72

Earlier quoted context omitted.

Passkeys are unphishable and can't meaningfully leak credentials in the case of a hack, nor can they be reused by design. For "important sites where security matters" they are literally better in every way than a password, it doesn't matter how weak or strong. You can use a pure software solution, and soon probably even your existing password manager, to handle them. Again, you should think of them as replacing passw…

> Passkeys are unphishable and can't meaningfully leak credentials in the case of a hack, nor can they be reused by design. Let's assume a "passkey device emulator" written in software; quite realistic IMHO for someone to use, considering the cost of hardware authentication devices (phones, YubiKey etc.) If someone using such emulator gets hacked and has their passkey emulator data stolen, is there anything preventin…

If the device is exploited, they can also install a keylogger and steal regular passwords.

I think this would be where hardware based authentication via TPM or similar would be useful. This would allow the device to be taken over and the private key material would still be safe.

Re: Passkeys will come at a cost

#224
> A frequent question here is if non resident keys are less secure than resident ones. Credential ID's as key wrapped keys are secure since they are encrypted with aes128 and hmaced.

This is incorrect. The strategy for how handles represent a public/private keypair is security-key specific. For example, Yubikeys shipped before firmware 4.4 used a different algorithm, and Solo keys use a third.

Platforms may also ignore requests for non-resident credentials, and return a handle reference to a resident one instead.

Re: Passkeys will come at a cost

#225

Since Apple didn't actually define it, this left a void for our thought leaders to answer that question for users hungry to know "what indeed is a passkey?". I have always understood that Apple defined a Passkey to be a key pair that is synced through iCloud Keychain. Even their WWDC 2021 presentation distinguishes passkeys to be different than security keys because they are "always with you" (the device sync aspect)…

passkeys are really defined by the FIDO Alliance

Based on FIDO standards, passkeys are a replacement for passwords that provide faster, easier, and more secure sign-ins to websites and apps across a user’s devices. Unlike passwords, passkeys are always strong and phishing-resistant.

[1] https://fidoalliance.org/passkeys/

Re: Passkeys will come at a cost

#226

Earlier quoted context omitted.

*her, but correct. I don't think a compromised device, and thus access to local data and potentially your password manager, is such an unusual situation, but at that point it is true you do have bigger things to worry about. A device like a computer is also far more likely to get compromised then a phone. that all said its fairly easy to remember a 20-30 length unique password if you use a passphrase and only have a…

> *her, but correct. Sorry. > I don't think a compromised device, and thus access to local data and potentially your password manager, is such an unusual situation Right, but what I meant is that it's unusual to have unique passwords for each service *and* have them memorized/not stored anywhere (well, sufficiently long and unique that if an attacker knows a few of them, it doesn't help him guess the others). That's…

> That's not what the vast majority of people do

and thats fine, but some of us do for the sites that are important, and that is better then storing something in a password manager weather it be passkey or password.

> For example, both of the banks I use (in two different countries) only allow a fixed size 6 digit numeric password. Somewhat strict password length requirements are not very unusual.

that is a problem with the banks, mine is happy with my 30+ one and has MFA. Banks that can't even support a decent password are unlikely to support passkey anytime soon

> way underestimating how fast you can crack passwords nowadays if the service uses password hashing algorithms that are still commonly used

if the provider (bank) is compromised and salted passwords leaked it doesn't matter, they have already compromised the bank and your account. And i still do not think you can quickly crack a password such as "This15aVERY!!securepasswordEH?!!?"? i could be wrong here

> if you can memorize it long-term, it means you don't have enough entropy, and if you have enough entropy, it means you can't memorize it long-term

not talking about bitcoin seeds here, just accounts.

like i'm not arguing against passkeys just that they have the inherent flaw of existing on a device/somewhere vs something that doesn't.

Re: Passkeys will come at a cost

#227

Earlier quoted context omitted.

> IMHO, the IT systems desperately need to approach human behaviour by working in analogous ways with the real world. Since I'm involved with IT systems I don't struggle most of the time but people who are not that tech savvy are having hard time figuring out daily stuff I'm pretty much the website key master for everyone in my family. Since nobody else is "in computers" they really don't have a clue about what thing…

> The security community really needs to get a grip and start designing systems that are compatible with the extremely low-tech-interest population if we even have a hope of securing systems. If I knew what the solution was I'd be rich. Most of that population seems to do fine managing house keys, car keys, locker keys, etc.

There is nothing to remember except to bring the damn keys. Once they're in your pocket, you're done.

Re: Passkeys will come at a cost

#229
post #27

Is it even a good idea to use physical security keys as passkeys in the first place? Passkeys are meant to be a password _replacement_, and for that you probably want the 2-factor properties afforded by phones or desktops which usually require "something you know" or "something you are" to unlock in addition to the "something you have" afforded by physically possessing them. IMO physical security keys are better left…

Passkeys combat phishing and sell mobile devices that have secure enclaves, tho the mobile operating software is apparently syncing the master key between devices enrolled in the same subscriber account. However, during MOST urban assaults, phone theft/damage is among the first thing to happen. It’s why all of this phone-as-token crud combined with FaceID are bad ideas that put convenience above security. The government should be pushing everyone into a federal SSO so that this is not needed and so they don’t need to worry so much about encryption.

Re: Passkeys will come at a cost

#230

Earlier quoted context omitted.

> The security community really needs to get a grip and start designing systems that are compatible with the extremely low-tech-interest population if we even have a hope of securing systems. If I knew what the solution was I'd be rich. Most of that population seems to do fine managing house keys, car keys, locker keys, etc.

There is nothing to remember except to bring the damn keys. Once they're in your pocket, you're done.

Yeah, except physical devices get lost, stolen or damaged. So there needs to be some accounts recovery procedure/alternative auth mechanisms.
Post reply on HN