Live data from Hacker News

Passkeys will come at a cost

fy.blackhats.net.au

511–520 of 600 posts

Re: Passkeys will come at a cost

#514

Earlier quoted context omitted.

I have the same problem with Google 2FA. "We sent a notification to your S21". No, I'm holding my S21 in my hand, unlocked. About 1/3 of the time, there's no notification. Or it takes five minutes to arrive. This is only one of many problems I've had with Google recently. I went from haphazardly trying to avoid their products for privacy reasons to now putting max effort into minimizing my Google usage because everyt…

> Hell, I'm an anti-Google evangelist now. Welcome to the club. I still have a gmail I use for some family and old friends, and there's a lot of history there, but I generally avoid using it unless it's a throwaway now. And... when dealing with clients, I suggest alternatives to GA, google maps, etc. Occasionally they override me, but I'm helping to get alternatives out there. 12-15 years ago, I was using google pay/…

> alternatives to GA, google maps

The problem is, as a small brick and mortar business, there is no alternative to Google Maps. I mean, sure. Technically alternatives exist. But if your customers don't use them, they are meaningless.

Of course we are listed on OpenStreetMap. But my guess is that since we opened, the number of customers we got that way rounds to zero.

Meanwhile, we get delisted from Google Maps and our revenue instantly drops about 70% (we are in a tourist area). It sucks. There's nothing we can do about it except make frustrated posts like this.

Re: Passkeys will come at a cost

#515

Earlier quoted context omitted.

True but online accounts are usually in the dozens for most people so thats definitely more of a burden. Also, its a mental load while physical keys carry the "password" physically.

I have hundreds in my password manager.

99 percent of people dont use password managers

Re: Passkeys will come at a cost

#516

Earlier quoted context omitted.

The problem is you don’t actually know these keys do or do not work until you need them to. This is not a trivial failure mode for many systems.

The same is true for physical keys for cars, houses, lockers, etc., which is why people have an intuition to test out keys to make sure that they work.

Most people aren't going to do that for the standby keys. And while they test out the real keys, they mostly don't go from working to not working because someone did a garbage collection/unused keys pass or failed to update some field or deleted something on a server.

Re: Passkeys will come at a cost

#517

Earlier quoted context omitted.

Somewhat unrelated, but I got one of those Google Titan fobs. The one time I needed it to work - authenticating from a new-to-me- computer - it just... didn't work. I plugged it in and... nothing. No popups, no reaction at all. Thought it was broken, but it worked back on another computer when I tried it later. No idea how that this future is supposed to be better. Perhaps titans are just duds? A couple yubikey-focus…

Yukibey based workflow are finicky. Sometimes, I need to try several times and reload the page or unplug/plug back for it to work. Sometimes, I need to switch key. It's like arch linux. Everybody tells there is never a problem with it, because, well, geeks lie. Doesn't mean it's not useful. I have a part of the article "Why not tell people to "simply" use pyenv, poetry or anaconda" ( https://www.bitecode.dev/p/why-no…

I use Yubikeys (on my Arch Linux machines..) - only problem I've had was soft-bricking one by entering the wrong password (GPG passphrase) more than my max. (Ironically while setting up another as a spare - with a different password, then mixed them up.)

Re: Passkeys will come at a cost

#518

Earlier quoted context omitted.

You can use the Yubico Authenticator app's WebAuthn feature on the desktop to see resident credentials on their Security Key product, same thing with Chrome/Chromium's security key settings pane.

Nope. I have Windows Yubico Authenticator v5.1.0, and with the Security Key plugged in, all screens blank. In Chrome 114.0.5735.199 on Windows 10 Pro, there is no "security key settings pane". The closest thing available is "Privacy and Security -> Security -> Manage phones (control which phones you use as security keys.)" However, in terms of resident credentials, I thank the GP and I stand corrected, because Yubico…

So I just tried this with a blue Yubico Security Key with 5.4.3 firmware using Yubico Authenticator 6.2.0 on Linux, and I was successfully able to manage my resident credentials using the Authenticator after setting a PIN and saving a resident credential via https://webauthn.io.

I'd check your firmware versions, update your Authenticator, ensure you have a PIN set and ensure you're correctly saving a resident key on your device when registering with a service.

For Chrome, a visit to chrome://settings/securityKeys[1] should do it, but I just tried it in a Windows VM and it is not present in the menu, while it is present on Linux and macOS.

[1] https://chromium.googlesource.com/chromium/src/+/HEAD/device...

Re: Passkeys will come at a cost

#519

Earlier quoted context omitted.

> small fraction of visitors This site won't work on Windows 7 / Chrome 69 as it only supports TLS 1.3 [1]. I believe 5% of the web can't connect [2]. But the text on the site is for technically minded people and the content includes commands you should run and security configuration. Tampering of the content could be quite harmful. [1] https://www.ssllabs.com/ssltest/analyze.html?d=fy.blackhats.... [2] https://caniu…

Tampering with the contents is quite unlikely. And anyone visiting a security site as a technically minded person probably has javascript disabled initially. Requiring HTTPS only for this is like requiring people wear bulletproof vests to visit your backyard BBQ. There is no doubt they are "safer". But it's also pretty silly.

> Tampering with the contents is quite unlikely

No, it was shockingly common for ISPs and public WiFi to modify sites. And many did inject malicious scripts or redirect users to malicious sites in order to monetize.

Post reply on HN