Lauren Weinstein is sounding the alarm on passkeys which is flawed and that it would make a huge headache for a lot of people especilly normal folks. https://mastodon.laurenweinstein.org/@lauren/111103819626952... https://mastodon.laurenweinstein.org/@lauren/111211366080459...
This debate is frustrating because it lacks data — it's full of opinions about which risk is worse than which other. To compare the risks and benefits, we need to know how often people actually re-use passwords, use 2FA, rely solely on their phone screen lock for access to all their accounts, use biometrics, need account recovery, and so on. That data is the only way to settle the debate (and would allow each person…
Passkeys are now enabled by default for Google users
631–640 of 684 posts
Re: Passkeys are now enabled by default for Google users
#632Earlier quoted context omitted.
I see the 1Password social team is still around downvoting people who speak their minds.
What are your objections with 1Password?
Re: Passkeys are now enabled by default for Google users
#633Earlier quoted context omitted.
How can a user, right now, take control + ownership of backing up their own pass keys, without iCloud or Google? This is a privilege I currently enjoy right now, and one I am not really eager to give up.
It depends on your web browser. Just see what happens here https://webauthn.io/ Firefox on Desktop tells me to "touch my security key". Not sure how that works. Firefox Android gives me a few hardware options to store my passkey to. Chrome Desktop asks me to enable Bluetooth. Chrome Android asks which Google Account to use.
Re: Passkeys are now enabled by default for Google users
#634As others have pointed out, cryptographic authentication is very hard to bootstrap if you simply loose your device. Just last month my missus cracked the glass of her iPhone. Apple repaired it under AppleCare, which is great… except … that they didn’t tell her that the “glass repair” entails them replacing the guts of the phone and wiping it in the process. Apple iPhone backups don’t contain cryptographic secrets lik…
Re: Passkeys are now enabled by default for Google users
#635Earlier quoted context omitted.
I do follow this. Unfortunately, it leaves out one glaring flaw: you can’t register a Passkey you don’t physically have. I use four: an Apple Passkey, a YubiKey I keep on me, a YubiKey at home, and a YubiKey in the bank. When I sign up for a service, I need to register all four of them. Not only is this generally a bit of a pain in the ass, but it also means I have to remember to go fetch the one in the bank vault pe…
> I have to remember to go fetch the one in the bank vault periodically I feel you, but I don't think Average Joe's threat model requires keeping a Yubikey in a safe deposit box (this is besides the issue that safe deposit boxes are less safe than you think: https://www.nytimes.com/2019/07/19/business/safe-deposit-box... ). A cloud-based passkey (like 1Password) is fine as the off-site backup key for most people.
You're probably right, but this is still new enough that I'm nervous to rely on that. If 1Password has a data-corruption incident and you don't have other passkeys, there goes your digital identity. 1Password (or Apple Keychain) plus two YubiKeys is almost certainly fine. But that does still now run into the pain of registering multiple passkeys.
To be completely honest, I sometimes wonder if it's borderline malpractice that sites allow registering only a single Passkey. Registration processes should fundamentally require you to onboard two of them at a minimum, and encourage three. Or maybe I'm just becoming curmudgeonly as I get older. But I do worry that the current state of things—while absolutely on the right track—is going to be an unfolding disaster for non-savvy early adopters.
Re: Passkeys are now enabled by default for Google users
#636Earlier quoted context omitted.
I can make a personal backup of a password. A fragile piece of hardware can fail me for a variety of reasons outside my control(lost or suddenly breaks). I have had a (Google) phone suddenly die in my hands without any prompting. With a password I was able to transition to a new device without incident. If my passkey was locked to that device, I might have found myself locked out of my digital identity.
> A fragile piece of hardware can fail me for a variety of reasons outside my control(lost or suddenly breaks). But you can use multiple devices... How is "a password written down and stored somewhere" better than a separate device used for backup purposes? Hell, get three devices, go nuts.
Let’s not forget the providers who do not offer the ability to enroll multiple devices. Last I heard, AWS would only let you put a single authenticator on your account.
Re: Passkeys are now enabled by default for Google users
#637Earlier quoted context omitted.
> more secure "more secure" is a completely meaningless statement, I wish this usage would die already (in general). You need to talk about security in the face of a very specific threat, then you can say solution A is better than solution B against threat T1, worse for T2 and about a wash for T3 and so on. Security is not a linear scale from 0-100 where you can say "more secure". There are many different criteria an…
The most problematic and the most probable security risk I have relating to logins is losing access. It for example took a week to restore access to my Apple account after I had forgotten to update my phone number there. Since this is the greatest security problem, I would hope all the vendors trying to improve security would focus on that.
Exactly. Unrecoverable secrets tied to closed hardware solve for the scenario where your most important criteria is that no attacker be able to ever access your account, even at the expense of yourself possibly losing access to it forever.
Does this solve a problem anyone actually has for consumer accounts? No.
That threat model makes sense for highly classified information where it is preferable to lose the information forever than have an attacker get it. Other than that, it's not a reasonable threat model to optimize for.
Re: Passkeys are now enabled by default for Google users
#638Earlier quoted context omitted.
> more secure "more secure" is a completely meaningless statement, I wish this usage would die already (in general). You need to talk about security in the face of a very specific threat, then you can say solution A is better than solution B against threat T1, worse for T2 and about a wash for T3 and so on. Security is not a linear scale from 0-100 where you can say "more secure". There are many different criteria an…
Threat #1: Credential theft from server breaches Threat #2: User creates a weak credential Threat #3: User reuses a credential (uses same credential across multiple services) Threat #4: Phishing Attackers use huge password dumps compiled from multiple server breaches, and then try them against other services. Relying on a combination of the fruits of their labor from all four threats, attackers successfully compromis…
Password managers don't solve #4. But you left out the huge one, losing access to the account. Which for most people is a larger risk than all the others put together.
For just about every person and account, the near-zero chance of getting personally spearphished is much less relevant than the risk of complete loss of access.
Re: Passkeys are now enabled by default for Google users
#639Earlier quoted context omitted.
It’s so rare that I use anything other than the 1Password Chrome extension that I couldn’t really tell you! The main app seems.. fine? But like I say, I hardly use it, so I probably wouldn’t notice details like you mention. Do you have a different workflow where you use the main app a lot?
I keep a lot (including images) in the main app as an ecrypted shared resource for IDs and various other secure info. If I suddenly need my insurance card I can quickly grab it out of the app rather than rummage through the (unencrypted) icloud or dropbox filesystem on ios. And I can cut/past text out of the images. I also use it for logging into apps, dragging credentials into remote machines over ssh etc. With 1pas…
Re: Passkeys are now enabled by default for Google users
#640Earlier quoted context omitted.
I can make a personal backup of a password. A fragile piece of hardware can fail me for a variety of reasons outside my control(lost or suddenly breaks). I have had a (Google) phone suddenly die in my hands without any prompting. With a password I was able to transition to a new device without incident. If my passkey was locked to that device, I might have found myself locked out of my digital identity.
> A fragile piece of hardware can fail me for a variety of reasons outside my control(lost or suddenly breaks). But you can use multiple devices... How is "a password written down and stored somewhere" better than a separate device used for backup purposes? Hell, get three devices, go nuts.
With passkeys you have to buy multiple phones, sign each of them into every one of your accounts, then keep them physically distributed (no cloud storage for phones). And to make sure they still work you have to periodically manually go and interact with the phones physically, even the one you stored in a bank vault. You also have to do this if you sign up for a new service.
Not to mention the inevitable services that don't allow multiple passkeys.