Live data from Hacker News

Passkeys: A shattered dream

fy.blackhats.net.au

11–20 of 789 posts

Re: Passkeys: A shattered dream

#11
post #6

Honestly, I think a big part of the problem is that passkeys have been tied to hardware devices and they don't have to be. A passkey is just a public key credential, and it can easily be provided by software as well as by hardware. You would still get many of the benefits (better UX, automatically secure, prevents phishing) and the overall customer experience could be a lot better. Imagine if passkeys could be saved,…

I have my passkeys in bitwarden.

Re: Passkeys: A shattered dream

#12
Passkeys are pretty useless for me. At first I was somewhat hyped, but it seems that everyone just ignores them. Chrome does not support them. I set it up on mac, today I tried to login to icloud using passkey, but it just didn't work. Few websites implemented them, but overwhelming majority of websites don't.

So, yeah, useless technology for now. Passwords and TOTPs are the way.

Re: Passkeys: A shattered dream

#13
post #8
post #3

Oof, the Passkeys ecosystem is incredibly complex. Even as someone that deals with it day in and day out at $CURRENT_CO, it can be a headache. As an exercise from a developer's perspective, try creating a chart of every device type (mobile, desktop etc), browser, and Passkeys platform provider (Apple, Microsoft etc). Then fill out how each behaves across each combination, it is a nightmare! I'm hopeful that we'll see…

Definitely this. I think the worst aspect of Passkeys is that the noble goals (public key crypto! unphisability!) seem to somewhat unavoidably wipe out one of the--in hindsight--really valuable aspects of passwords-in-a-password-manager: That you can always just copy them out, put them in a different password manager, or write them on a post-it. That said, I think this is a byproduct of the design space being complex…

I've been using Passkeys saved in 1Password, I thought that gave me the power to transfer them, but I just looked and apparently the export feature of 1P doesn't allow exporting the Passkeys, it just tells you you need to create new ones in your new password manager, so that's pretty crappy...

Re: Passkeys: A shattered dream

#15
post #10
post #2

I use iCloud's Passkeys extensively and have never had saved Passkeys "wiped out". I am not disputing that data loss bugs can happen, but three times for one user sounds pretty weird given the maturity of the ecosystem. The most obvious explanations seem to me to be: a) Apple loses data (presumably not just Passkeys, but also photos, passwords, and other highly noticeable stuff) all the time, and I've been lucky for…

Agreed. I'm not so sure that some of the iCloud data loss bugs people talk about are actual data loss bugs. I've had a few issues over the years. Firstly I spent weeks chasing down what I thought was a data loss bug in iCloud. After much effort I managed to reproduce it. Turned out it was an issue with TeXshop rather than iCloud. Secondly, the one time I had a photo lost, it wasn't lost. I just couldn't find it in th…

To be clear, I don't work for Apple. :) And I'm not discounting that there are usage patterns that might lead to persistent bad experiences (like your example with Numbers).

But the implication that Keychain just kind of forgets saved Passkeys once in a while seems alarmist and probably unfounded.

Re: Passkeys: A shattered dream

#16

Passkeys are pretty useless for me. At first I was somewhat hyped, but it seems that everyone just ignores them. Chrome does not support them. I set it up on mac, today I tried to login to icloud using passkey, but it just didn't work. Few websites implemented them, but overwhelming majority of websites don't. So, yeah, useless technology for now. Passwords and TOTPs are the way.

Chrome supports passkeys

Re: Passkeys: A shattered dream

#17
I still use Keepass (well MacPass) and naively "cache" what I use regularly in Keychain because I completely distrust anyone else handling the keys to my castle. Whenever I get a Passkeys notification it's an irritation as I don't actually see what the supposed benefits of this are and I'm not really interested in changing how I work. Just feels like I'm being dragged into something complex I will never be able to escape.

Re: Passkeys: A shattered dream

#18
post #3

Oof, the Passkeys ecosystem is incredibly complex. Even as someone that deals with it day in and day out at $CURRENT_CO, it can be a headache. As an exercise from a developer's perspective, try creating a chart of every device type (mobile, desktop etc), browser, and Passkeys platform provider (Apple, Microsoft etc). Then fill out how each behaves across each combination, it is a nightmare! I'm hopeful that we'll see…

I am exploring this now, actually got 2 students doing their thesis on this. It's very complicated and unnecessarily so.

My conclusion so far is that it's a promising technology, but no way as mature as I'd like it to be. Unfortunately we are stuck with emails and passwords for the foreseeable future, at least as a back-up mechanism for credentials recovery, which, funnily, makes the whole thing pretty much pointless.

Re: Passkeys: A shattered dream

#19

Is the author suggesting he’s not traveling to the US out of security concerns? Is that really a thing?

Apparently... of course, the threat of "mass casualty violence and terrorist attacks" is real, but you're probably still more likely to die in a plane crash while getting to the US (or in a car accident while there) than in a shooting or terrorist attack. And if you insist on only travelling to countries that have a lower level of violent crime than Australia, you probably won't get around much (https://worldpopulationreview.com/country-rankings/violent-c...)...

Re: Passkeys: A shattered dream

#20
post #15
post #10

Earlier quoted context omitted.

Agreed. I'm not so sure that some of the iCloud data loss bugs people talk about are actual data loss bugs. I've had a few issues over the years. Firstly I spent weeks chasing down what I thought was a data loss bug in iCloud. After much effort I managed to reproduce it. Turned out it was an issue with TeXshop rather than iCloud. Secondly, the one time I had a photo lost, it wasn't lost. I just couldn't find it in th…

To be clear, I don't work for Apple. :) And I'm not discounting that there are usage patterns that might lead to persistent bad experiences (like your example with Numbers). But the implication that Keychain just kind of forgets saved Passkeys once in a while seems alarmist and probably unfounded.

Yeah exactly. It is possible that some expiry or provider specific bug may lead to revocation? I am not sure how it works entirely.

I will say that there are some very well known backup and restore issues with keychain however so I keep anything critical in MacPass as the primary copy.

Post reply on HN