Live data from Hacker News

Passkeys will come at a cost

fy.blackhats.net.au

271–280 of 600 posts

Re: Passkeys will come at a cost

#271
post #222

Earlier quoted context omitted.

> Passkeys are meant to be a password _replacement_, No. Passkeys parasitize on FIDO2 U2F standard, that was developed to be (as the name implies) the second factor. Resident keys are meant for on-device 2FA with PIN, a functional replacement of smart cards. Someone (Apple maybe) thought it’s a good idea to consider WebAuthn being good enough to be the only authentication factor (no resident keys, no hardware bond, k…

Microsoft Live allows me to sign in to live.com with nothing else but my Yubico Security Key. That's right, I don't even need to know my username; I just plug in the key and touch it and I'm logged in. And when I write "I" you should read "anyone who has physical possession of this key". I think that's astonishingly bad opsec for a Big Tech cloud service. If I were a sane person, I would deregister that key as a FIDO…

> And when I write "I" you should read "anyone who has physical possession of this key".

Add a PIN or password to the key and now anyone who has physical possession of the key will need to know your secret in order to use it.

Yubikeys, for example, will wipe their credentials after 8 wrong password attempts.

Re: Passkeys will come at a cost

#272
post #254

Earlier quoted context omitted.

Microsoft Live allows me to sign in to live.com with nothing else but my Yubico Security Key. That's right, I don't even need to know my username; I just plug in the key and touch it and I'm logged in. And when I write "I" you should read "anyone who has physical possession of this key". I think that's astonishingly bad opsec for a Big Tech cloud service. If I were a sane person, I would deregister that key as a FIDO…

Yes, that’s resident (or “discoverable”) keys the article author is talking about. You don’t have to do it this way. I configured my Yubikeys to be the second factor and not to use resident keys. It’s possible, although I don’t know if Microsoft allows users to roll back from “passwordless” and discoverable keys. I want to state it explicitly: FIDO as technology allows either. It’s particular platform choice to go wi…

> It’s possible, although I don’t know if Microsoft allows users to roll back from “passwordless” and discoverable keys.

I don't know about Microsoft specifically, but it's possible to register the same FIDO2-capable security key with a service as both a passkey and a U2F token.

Re: Passkeys will come at a cost

#273
Until it's possible to physically link a passkey to a device like a yubikey I see no security "benefit" to giving single permissioned access to credentials to large tech companies. It's a single point of failure even worse than trusting a password management company like OnePassword etc.

I'm still holding out for a self hosted or federated version of passkeys, potentially similar to how more complex forms of crypto custody exist - similar to multi party computing (MPC).

Re: Passkeys will come at a cost

#274
post #254

Earlier quoted context omitted.

Yes, that’s resident (or “discoverable”) keys the article author is talking about. You don’t have to do it this way. I configured my Yubikeys to be the second factor and not to use resident keys. It’s possible, although I don’t know if Microsoft allows users to roll back from “passwordless” and discoverable keys. I want to state it explicitly: FIDO as technology allows either. It’s particular platform choice to go wi…

> Yes, that’s resident (or “discoverable”) keys the article author is talking about. No, I said I'm using a Yubico Security Key. This is not a Yubikey. This key has no storage. How can it possibly store resident keys? The YubiKey Manager app can't even connect to this key. It's very basic, it has no TOTP slots, it has no configuration, it only does FIDO2. How would resident keys get in there in the first place? The a…

You can use the Yubico Authenticator app's WebAuthn feature on the desktop to see resident credentials on their Security Key product, same thing with Chrome/Chromium's security key settings pane.

Re: Passkeys will come at a cost

#275

Earlier quoted context omitted.

When I use a Yubikey for passwordless authentication (FIDO2), it challenges me for a PIN before asking me to touch the device. If I give it too many incorrect PINs, the Yubikey locks up and requires a device reset, which invalidates all previous registrations to use that key for authentication. It doesn't seem like a big deal if someone steals my hardware token. https://support.yubico.com/hc/en-us/articles/4402836718…

It means though that your secure hardware token has a reliable way where the secrets all self-destruct. That someone can easily do if they get even brief hardware access. For people who have a problem keeping sufficient backups (almost everyone on earth) this seems like a horrific blocker, a show stopper for this entire intiative. I personally think these things absolutely should be able to be exported & backed up se…

Yubico has said that they're working on a standard to export passkeys and that future products will have that feature once the standard is decided upon.

Re: Passkeys will come at a cost

#276

Earlier quoted context omitted.

> I personally think these things absolutely should be able to be exported & backed up separately. I agree. The usual response is that you don't need to do this because you can have multiple hardware keys that authenticate to the same services, so you can store one as a backup. But managing that sounds like a real pain in the butt to me (honestly, the entire passkey system sounds like a real pain in the butt to me --…

It'd be awesome if you could ask to enroll a variety of other devices all at once, without having them on hand. Requiring ongoing physical access to your crucial backups to do any account enrollment or changes seems like a way to make sure you have your crucial backup way too close to potential disasters. Ideally I wanty backup keys many states away from me. But then I can enroll them! But it feels like there could b…

> It'd be awesome if you could ask to enroll a variety of other devices all at once, without having them on hand.

This is one of the feature goals Yubico said they want to implement.

Re: Passkeys will come at a cost

#277

Earlier quoted context omitted.

> The security community really needs to get a grip and start designing systems that are compatible with the extremely low-tech-interest population if we even have a hope of securing systems. If I knew what the solution was I'd be rich. Most of that population seems to do fine managing house keys, car keys, locker keys, etc.

True but online accounts are usually in the dozens for most people so thats definitely more of a burden. Also, its a mental load while physical keys carry the "password" physically.

Which is the magic of UAF: you have one key that opens all the computing doors.

Re: Passkeys will come at a cost

#278
post #27

Is it even a good idea to use physical security keys as passkeys in the first place? Passkeys are meant to be a password _replacement_, and for that you probably want the 2-factor properties afforded by phones or desktops which usually require "something you know" or "something you are" to unlock in addition to the "something you have" afforded by physically possessing them. IMO physical security keys are better left…

Which is why the author mentioned using a pin or biometrics to unlock the hardware security device.

Re: Passkeys will come at a cost

#279
post #192

Earlier quoted context omitted.

> The security community really needs to get a grip and start designing systems that are compatible with the extremely low-tech-interest population if we even have a hope of securing systems. If I knew what the solution was I'd be rich. Most of that population seems to do fine managing house keys, car keys, locker keys, etc.

> Most of that population seems to do fine managing house keys, car keys, locker keys, etc. I’m gonna have to disagree with you there. People are constantly losing their keys prolly about as much as people reuse the same password for multiple services.

> People are constantly losing their keys prolly about as much as people reuse the same password for multiple services.

But when they lose their keys, they have a pretty clear mental model of the security risk and how to mitigate it.

Re: Passkeys will come at a cost

#280

Earlier quoted context omitted.

There is nothing to remember except to bring the damn keys. Once they're in your pocket, you're done.

Yeah, except physical devices get lost, stolen or damaged. So there needs to be some accounts recovery procedure/alternative auth mechanisms.

...and there are, and they're remarkably similar to what you do with Yubikeys: you have extra keys, and when you lose one, you uses the other to get in, and then you invalidate the old keys (although in the physical world, this means getting a new lock and a new set of keys, instead of just getting one new key and removing the lost key as a valid key).
Post reply on HN