Live data from Hacker News

Passkeys: A shattered dream

fy.blackhats.net.au

21–30 of 789 posts

Re: Passkeys: A shattered dream

#21
The biggest issue with passkeys is that I just can't trust the companies offering them. They are locked into the platform for reasons that are ostensibly security but often indistinguishable from platform lock-in. If you make a passkey on an Apple device as far as I can tell it will never leave that device, ever, and there is no way to change this. Of course this means you can never be phished for your credentials but if Apple decides to delete your key or you want to leave your iPhone behind, what are you supposed to do?

Re: Passkeys: A shattered dream

#22

Is the author suggesting he’s not traveling to the US out of security concerns? Is that really a thing?

Yes, there are plenty of people who avoid travelling to the US

I know that, but I didn’t think it was because of security. I don’t think of the US as particularly dangerous, but maybe my perception is wrong…

Re: Passkeys: A shattered dream

#23
post #19

Is the author suggesting he’s not traveling to the US out of security concerns? Is that really a thing?

Apparently... of course, the threat of "mass casualty violence and terrorist attacks" is real, but you're probably still more likely to die in a plane crash while getting to the US (or in a car accident while there) than in a shooting or terrorist attack. And if you insist on only travelling to countries that have a lower level of violent crime than Australia, you probably won't get around much ( https://worldpopulat…

Oops, you forgot the other 2 travel advisories the author quoted in that part:

- "Violent crime is more common in the US than in Australia"

- "Medical costs in the US are extremely high. You may need to pay up-front for medical assistance"

I think some Americans don't realize that, outside of America, many people don't ever consider the risk of gun violence in their day-to-day lives, or owing thousands of dollars for visiting a hospital.

Re: Passkeys: A shattered dream

#25

Is the author suggesting he’s not traveling to the US out of security concerns? Is that really a thing?

Indeed, the author is not alone. It may be subjective but there are worries one needs to reconcile when planning a trip to the US (both for work as well as private trips). It’s often that we choose another destination or “can we find a way to make this remotely”.

Re: Passkeys: A shattered dream

#26

The biggest issue with passkeys is that I just can't trust the companies offering them. They are locked into the platform for reasons that are ostensibly security but often indistinguishable from platform lock-in. If you make a passkey on an Apple device as far as I can tell it will never leave that device, ever, and there is no way to change this. Of course this means you can never be phished for your credentials bu…

This is why services need to support multiple passkeys per user just like they should support multiple 2FA methods...

Re: Passkeys: A shattered dream

#27
This is quite concerning, because I've recently started a project that uses webauthn-rs. I want to minimise spam on the project while I don't want to collect PII like emails for login.

I wonder if it means that the author will stop working on the library after their next release, and more importantly, if the UX is going to be horrible with people unable to log in and other issues they mention.

On a tangent, I share their discomforts about travelling to the US. The last time I was there, I felt uncomfortable being out on the streets alone. Maybe the portrayal of police brutality towards POC is a factor (for me).

Re: Passkeys: A shattered dream

#28
post #17

I still use Keepass (well MacPass) and naively "cache" what I use regularly in Keychain because I completely distrust anyone else handling the keys to my castle. Whenever I get a Passkeys notification it's an irritation as I don't actually see what the supposed benefits of this are and I'm not really interested in changing how I work. Just feels like I'm being dragged into something complex I will never be able to es…

Password managers can store the passkeys just like they store passwords. 1Password has had strong support for them for quite a while now

Re: Passkeys: A shattered dream

#29

Passkeys are pretty useless for me. At first I was somewhat hyped, but it seems that everyone just ignores them. Chrome does not support them. I set it up on mac, today I tried to login to icloud using passkey, but it just didn't work. Few websites implemented them, but overwhelming majority of websites don't. So, yeah, useless technology for now. Passwords and TOTPs are the way.

Just logged in to iCloud using chrome on a mac. Scanned a QR with iPhone and boom that was that.

Re: Passkeys: A shattered dream

#30
Question for the author regarding:

within a business where we have policy around what devices may be acceptable the ability to filter devices does matter.

Is a solution to this on desktop to use GPO policy to add a mandatory "attesting" extension (that you build yourself which just verifies the device is what it says it is), and on mobile to use a webview inside an app with similar attesting info injected into the page context??

Post reply on HN