Live data from Hacker News

Passkeys will come at a cost

fy.blackhats.net.au

331–340 of 600 posts

Re: Passkeys will come at a cost

#332
post #95
post #91

Earlier quoted context omitted.

This is a terrible idea though. I had the misfortune of getting into a cycling accident which broke my phone display (completely lost display output and touch input), and it meant I lost access to all my OTP 2FAs for a couple of days (which is actually kind of scary). I was able to fix it myself by getting parts and going through an ifixit guide (right to repair anyone? ;-), after which I promptly exported my 2FA see…

Maybe I'm getting tinfoil-y here, but I think the horribleness is the point: consider how eager Apple in particular is to get people fully enmeshed in their services ecosystem. You're a lot less likely to try to roll your own backup, or otherwise exit the walled garden, if doing so means your entire auth story is irredeemably fucked. The thing that strikes me about this whole story is that during a lot of the initial…

Tin foil — third parties can be passkey providers: https://blog.1password.com/apple-passkey-api-wwdc/

Re: Passkeys will come at a cost

#333
post #235

This is a bit unrelated to the harder crypto stuff but my mom called me freaking out she couldn’t get into her gmail. It turns out Google auto registered her new android phone with a passkey and made that the default Google login with a confusing passkey based interface (expecting her to know to click the second option to login via password or understand wtf a passkey is was too much IMO). It turns out when it said “…

Exactly, I'm seriously considering taking my business off google's ecosystem because of the unwanted "we've sent a notification to your phone" confirmation requirement. I could understand if they did that if I suddenly tried to login from the other side of the world, or let's say I always use Linux and suddenly my browser identifies as windows etc. But if you're running a privacy focused browsers (ungoogled chromium)…

> But if you're running a privacy focused browsers

I'm sorry but I was with you until here. if you're going to run a privacy enhanced browser and then complain that it has a privacy enhancing features which result in providers being more cautious because you have privacy enhancing features, then I'm not sure how to help you. I run anti-google adware on my main browsing identity but when sites give me shit I just turn if off and reload.

Re: Passkeys will come at a cost

#334
post #91
post #48

Earlier quoted context omitted.

I'm pretty sure the goal here is to turn your phone into your passkey, _and nothing else_. Everything written in that article makes sense if you keep that in mind.

This is a terrible idea though. I had the misfortune of getting into a cycling accident which broke my phone display (completely lost display output and touch input), and it meant I lost access to all my OTP 2FAs for a couple of days (which is actually kind of scary). I was able to fix it myself by getting parts and going through an ifixit guide (right to repair anyone? ;-), after which I promptly exported my 2FA see…

WARNING SATIRE ;=)

> I had the misfortune of getting into a cycling accident which broke my phone display

oh do not worry we got you

our new phone backup program did back up that important secret of yours

I know you disabled the backups because you didn't trust us but because people lost access to our services we just enabled it anyway and it can no longer be disabled.

yes we know that after syncing TOTP secrets in plain text no one trusts us but how else do you get access to your secrets again after you lose your phone, or have you forgotten that it was also your only access to the 2FA of your google account?

now you can just go to your internet provider and get a copy of the secrets they wired tapped for you for only 5 99€ as you agreed to in the fine prints of you latest phone contract

it's easy don't worry, so easy that even that new police man which always gets everything wrong was able to get your passkeys last week. Why? Uh. idk. he had a judge signed letter something about impersonating you so that they can trick and jail someone called Tom who annoys them due to his ani-corruption protests. Hm, I think hat same Tom you labeled as "best friend" in your address book. But don't worry he will never blame you for it. I mean he died a day after you last saw him a half a year ago and the person you have been speaking with was just a hacker who used his passport to get his passkeys from us. AI voice and video generation has come quite far hasn't it.

Re: Passkeys will come at a cost

#336
post #263

Earlier quoted context omitted.

> Losing your 2nd factor shouldn't block you from accessing your accounts indefinitely. You’re absolutely right and also you don’t have to worry. Everyone who operate auth of any sort will be forced on day one to have reasonable recovery. Nobody is gonna lock customers out because you lost their super-secret private key. In practice, it goes back to email recovery for 98% of services. This will remain true with passk…

> Nobody is gonna lock customers out because you lost their super-secret private key. https://www.nytimes.com/2022/08/21/technology/google-surveil...

To be fair I said “customers”.

Re: Passkeys will come at a cost

#337

Earlier quoted context omitted.

Exactly, I'm seriously considering taking my business off google's ecosystem because of the unwanted "we've sent a notification to your phone" confirmation requirement. I could understand if they did that if I suddenly tried to login from the other side of the world, or let's say I always use Linux and suddenly my browser identifies as windows etc. But if you're running a privacy focused browsers (ungoogled chromium)…

>Then the whole "answer some questions" dance starts. Google literally does provide you with backup codes that they tell you to keep offline available, which is pretty common practice for any 2FA scheme.

What? I've never been given backup codes, nor any notification that such a thing even existed.

Re: Passkeys will come at a cost

#340
post #192

Earlier quoted context omitted.

> Most of that population seems to do fine managing house keys, car keys, locker keys, etc. I’m gonna have to disagree with you there. People are constantly losing their keys prolly about as much as people reuse the same password for multiple services.

> People are constantly losing their keys prolly about as much as people reuse the same password for multiple services. But when they lose their keys, they have a pretty clear mental model of the security risk and how to mitigate it.

What happens when you lose your passkey?
Post reply on HN