Live data from Hacker News

Passkeys will come at a cost

fy.blackhats.net.au

341–350 of 600 posts

Re: Passkeys will come at a cost

#341
post #235

This is a bit unrelated to the harder crypto stuff but my mom called me freaking out she couldn’t get into her gmail. It turns out Google auto registered her new android phone with a passkey and made that the default Google login with a confusing passkey based interface (expecting her to know to click the second option to login via password or understand wtf a passkey is was too much IMO). It turns out when it said “…

Exactly, I'm seriously considering taking my business off google's ecosystem because of the unwanted "we've sent a notification to your phone" confirmation requirement. I could understand if they did that if I suddenly tried to login from the other side of the world, or let's say I always use Linux and suddenly my browser identifies as windows etc. But if you're running a privacy focused browsers (ungoogled chromium)…

I swear the phone as 2FA is a setting you can actually turn off buried in the account settings

Re: Passkeys will come at a cost

#342
post #91
post #48

Earlier quoted context omitted.

I'm pretty sure the goal here is to turn your phone into your passkey, _and nothing else_. Everything written in that article makes sense if you keep that in mind.

This is a terrible idea though. I had the misfortune of getting into a cycling accident which broke my phone display (completely lost display output and touch input), and it meant I lost access to all my OTP 2FAs for a couple of days (which is actually kind of scary). I was able to fix it myself by getting parts and going through an ifixit guide (right to repair anyone? ;-), after which I promptly exported my 2FA see…

Yes, KeePass (and KeepassX and KeePassXC) support generating 2FA codes, but it is generally not a good idea to store those alongside your passwords, as if you do those aren't a 2nd factor anymore. You can mitigate the issue by having an encrypted db only for 2FA codes, but I would still advise having those in a completely separate app anyway.

Re: Passkeys will come at a cost

#343
post #54

Earlier quoted context omitted.

`rk=required` means your hardware is required to store each and every derived key, not just the master key, all in the service of you not needing to remember your username anymore. Current security keys can handle a couple dozen derived keys at most, _if_ they can handle any at all. This flies in the face of previous promises where 'every key can handle an unlimited amount of accounts'. In my eyes, this looks like a…

As someone who doesn't and won't ever have a mobile phone, I can't comprehend why things are going in this direction.

Well, 1984 and Fahrenheit 451 were warnings of the world we are slowly heading towards.

Re: Passkeys will come at a cost

#344
post #218

For context, we run a YC-backed passwordless company, and have rolled passwordless out at major organizations. While I think passkeys will definitely be the answer for consumer passwordless, I'm not sure this is quite reflected in the enterprise yet. Passkeys are wonderful for consumer use, because they're meant to enable your own ability to break glass, by backing up the credential to other devices. You can do this…

>Passkeys are wonderful for consumer use, because they're meant to enable your own ability to break glass, by backing up the credential to other devices. You can do this via iCloud (by default) or via things like Airdrop.

What happens when Google or Apple decided to ban you for mistake due to anti-bot or anti-fraud detection or whatever ever nonsense?

Re: Passkeys will come at a cost

#345

> The problem is that security keys with their finite storage and lack of credential management will fill up rapidly. In my password manager I have more than 150 stored passwords. If all of these were to become resident keys I would need to buy at least 5 yubikeys to store all the accounts How it is possible that THIS is the problem in 2023? Storage is cheap, tiny, and capacious. I feel like I’m reading an article fr…

You can't just drop in a generic storage IC which are cheap and plentiful.

You need one with a certain degree of verified _good_ encryption mechanisms built in. You do not want it ever communicating with the processor in plain text if you are selling a security device.

Re: Passkeys will come at a cost

#346
post #263

Earlier quoted context omitted.

> Losing your 2nd factor shouldn't block you from accessing your accounts indefinitely. You’re absolutely right and also you don’t have to worry. Everyone who operate auth of any sort will be forced on day one to have reasonable recovery. Nobody is gonna lock customers out because you lost their super-secret private key. In practice, it goes back to email recovery for 98% of services. This will remain true with passk…

>I’m also a little worried about public computers, shared devices, borrowing etc. Not everyone has a personal $1000 phone. This whole “my own device” assumption is a first world bias, and the experts should know better. Exactly. That's why I'm in favour of SMS based auth for really important services like banking and government services. Your phone got broken/lost? Most providers offer replacement sims immediately or…

> I saw mentions that SMS is insecure, but I never heard about a credible remote attack that didn't include provider cooperation or taking over your phone.

Technically correct, but how likely those attacks are seems to depend on the country. While I'm not aware of this being an issue in any EU country, sim swapping is a common thereat at least in the USA. Yes, American providers really need to improve the security of their procedures, but this means that in the current situation the security of any authentication flow based on SMS heavily depends on which country the user is located.

Re: Passkeys will come at a cost

#347
post #268

Earlier quoted context omitted.

I believe the primary point is that WebAuthn is being pushed to use a "passkey" model where each site creates a credential that consumes storage. Displayable site and user account names, a user record handle, and the private key all take up storage, along with a few other items. A mobile phone could store 10 thousand passkeys without breaking a sweat. Modern hardware keys might only be able to store 25 total in avail…

The discoverability argument is somewhat weak because your browser already stores and probably prefills the username. About not revealing whether an account exists: A site could always reveal a set number of potentially fake handles. So say a user has two handles registered, and the set number is ten. If the account exists, the two real handles will be in the list, alongside eight fake ones. If the account doesn't ex…

How wouldn’t one of them be the one you’re looking for? I.e. still revealing an account’s existence

Re: Passkeys will come at a cost

#348
post #2

That's a rather uncharitable take on the situation. I'll propose an alternative: If you want to take advantage of the new auth standard that will eliminate weak passwords and password reuse (thereby preventing 99% of casual account break-ins), you'll have to spend $30 to upgrade off the legacy yubikey you've been coasting on since 2013.

Well no, because a brand new yubikey 5 has the same limit

Re: Passkeys will come at a cost

#349

Earlier quoted context omitted.

Exactly, I'm seriously considering taking my business off google's ecosystem because of the unwanted "we've sent a notification to your phone" confirmation requirement. I could understand if they did that if I suddenly tried to login from the other side of the world, or let's say I always use Linux and suddenly my browser identifies as windows etc. But if you're running a privacy focused browsers (ungoogled chromium)…

After I deleted my personal google accounts, I was left with work google accounts I would have to maintain. I have been bitten by this problem more than once, resulting in: - losing some accounts forever - losing temporarily access to accounts, preventing me to work for some time - forcing me to go through recovery procedures with tedious docs and hostile UI, wasting my work time I eventually found a trick: buy 3 yub…

Somewhat unrelated, but I got one of those Google Titan fobs. The one time I needed it to work - authenticating from a new-to-me- computer - it just... didn't work. I plugged it in and... nothing. No popups, no reaction at all. Thought it was broken, but it worked back on another computer when I tried it later. No idea how that this future is supposed to be better. Perhaps titans are just duds? A couple yubikey-focused friends have used theirs for years, but I wonder if they only talk up their successes, and don't mention the failures?

Re: Passkeys will come at a cost

#350
post #235

This is a bit unrelated to the harder crypto stuff but my mom called me freaking out she couldn’t get into her gmail. It turns out Google auto registered her new android phone with a passkey and made that the default Google login with a confusing passkey based interface (expecting her to know to click the second option to login via password or understand wtf a passkey is was too much IMO). It turns out when it said “…

This sent me over the edge. It forced the realization that Google does not make decisions based on users. I know, I know, obvious - but even though I "knew" that, it had not clicked that obviously they would make decisions BAD for users. Google makes money from advertisers. They provide just enough service to users that does not send them away. And just enough to keep competitors at bay. As long as users don't leave they don't really care -they don't have to care.

This is the way it is. If we want something different we need services not paid for by advertisers. (And no. While google exploits users one way, apple does another. Picking your poison is not a choice).

Post reply on HN