Live data from Hacker News

Passkeys: A shattered dream

fy.blackhats.net.au

41–50 of 789 posts

Re: Passkeys: A shattered dream

#41

The biggest issue with passkeys is that I just can't trust the companies offering them. They are locked into the platform for reasons that are ostensibly security but often indistinguishable from platform lock-in. If you make a passkey on an Apple device as far as I can tell it will never leave that device, ever, and there is no way to change this. Of course this means you can never be phished for your credentials bu…

This is why services need to support multiple passkeys per user just like they should support multiple 2FA methods...

Big problem with this is that enrolling the secondary passkey requires the authenticator to be present. This is super inconvenient and risky as it always requires both authenticators to be present at the same machine/physical location, exposing both to local, physical threats (faulty USB ports on your machine frying anything you plug in? Congrats, you've now fried your main and any backup authenticators before you realized what was happening).

Ideally, you should be able to get an authenticator's public key and be able to enroll one without presenting the authenticator itself, allowing you to keep it in a safe/etc.

This would enable an easy workflow - enroll main authenticator as normal, then enroll your safely-stored backup by pasting its public key. If you lose your main, go to your safe, get your backup and "promote" it to primary and enroll a new backup one which goes in the safe.

Re: Passkeys: A shattered dream

#42

Is the author suggesting he’s not traveling to the US out of security concerns? Is that really a thing?

I think it's a hefty chunk of paranoia. The US is absolutely a non-issue unless you have previously pissed them off. This is the same for every country.

What is not is walking 30km in the middle of nowhere in Central Asia because you didn't have enough cash to pay the driver's bribe. Stuff like that is a far more realistic concern than the security border paranoia stuff that goes on. Know where you are going, plan ahead and stay out of obvious trouble. That applies everywhere. The US is not special.

(Incidentally when I got to the first town, the guy in the shop laughed at me and invited me in for tea and dinner on him and his wife and I got to learn all about their history under Russia - it's not all bad)

Re: Passkeys: A shattered dream

#43
I can't help feeling this... In an adverse world software and electronic data is too ephemeral to entrust with authentication and authorization. What if we had something solid like a Yubikey, but:

- credit card sized

- completely airgapped

- standardized

- controlled by a non-profit association

- hard- and software open sourced

- built-in camera to scan data

- built-in display to show data

- configuration mode: scan human-readable configuration

- data is QR code or something like Base58 to copy by hand

- backup by supporting applications: scan and print out data

- browser integration by an extension using a webcam

Re: Passkeys: A shattered dream

#44
post #2

I use iCloud's Passkeys extensively and have never had saved Passkeys "wiped out". I am not disputing that data loss bugs can happen, but three times for one user sounds pretty weird given the maturity of the ecosystem. The most obvious explanations seem to me to be: a) Apple loses data (presumably not just Passkeys, but also photos, passwords, and other highly noticeable stuff) all the time, and I've been lucky for…

One thing that comes to mind is with the earlier WebAuthn implementations in iOS, before they were stored in iCloud and called passkeys, there was no management interface for stored passkeys and 'clear website data' (to delete cookies etc.) would actually erase all credentials permanently. It was useless this way.

Re: Passkeys: A shattered dream

#45
post #2

I use iCloud's Passkeys extensively and have never had saved Passkeys "wiped out". I am not disputing that data loss bugs can happen, but three times for one user sounds pretty weird given the maturity of the ecosystem. The most obvious explanations seem to me to be: a) Apple loses data (presumably not just Passkeys, but also photos, passwords, and other highly noticeable stuff) all the time, and I've been lucky for…

> I use iCloud's Passkeys extensively

So what happens if you want to migrate away from iCloud for the storage of passkeys?

Re: Passkeys: A shattered dream

#46
post #17

I still use Keepass (well MacPass) and naively "cache" what I use regularly in Keychain because I completely distrust anyone else handling the keys to my castle. Whenever I get a Passkeys notification it's an irritation as I don't actually see what the supposed benefits of this are and I'm not really interested in changing how I work. Just feels like I'm being dragged into something complex I will never be able to es…

Password managers can store the passkeys just like they store passwords. 1Password has had strong support for them for quite a while now

Yeah probably can. But why do I need Passkeys?

Re: Passkeys: A shattered dream

#47
post #17

I still use Keepass (well MacPass) and naively "cache" what I use regularly in Keychain because I completely distrust anyone else handling the keys to my castle. Whenever I get a Passkeys notification it's an irritation as I don't actually see what the supposed benefits of this are and I'm not really interested in changing how I work. Just feels like I'm being dragged into something complex I will never be able to es…

Try Keepassium on iOS. It removed my need to “cache” anything in the keychain.

Re: Passkeys: A shattered dream

#48

The biggest issue with passkeys is that I just can't trust the companies offering them. They are locked into the platform for reasons that are ostensibly security but often indistinguishable from platform lock-in. If you make a passkey on an Apple device as far as I can tell it will never leave that device, ever, and there is no way to change this. Of course this means you can never be phished for your credentials bu…

This is alone a big enough reason that there never has been any reason to be hyped about passkeys. The hype train on passkeys has been insane.

Re: Passkeys: A shattered dream

#49
post #33
post #23

Earlier quoted context omitted.

Oops, you forgot the other 2 travel advisories the author quoted in that part: - "Violent crime is more common in the US than in Australia" - "Medical costs in the US are extremely high. You may need to pay up-front for medical assistance" I think some Americans don't realize that, outside of America, many people don't ever consider the risk of gun violence in their day-to-day lives, or owing thousands of dollars for…

Actually, I specifically addressed the violent crime thing... As for the medical costs - if you want to be on the safe side, you can (actually you should) get travel health insurance.

I've heard horror stories about hospitals not accepting insurance. Wouldn't want to be in a situation of being ill and having to pay more than I can earn in a lifetime.

Re: Passkeys: A shattered dream

#50

The biggest issue with passkeys is that I just can't trust the companies offering them. They are locked into the platform for reasons that are ostensibly security but often indistinguishable from platform lock-in. If you make a passkey on an Apple device as far as I can tell it will never leave that device, ever, and there is no way to change this. Of course this means you can never be phished for your credentials bu…

I thought passkeys were shared across Apple keychain (like passwords?) so you make a passkey on iPhone your iPad can use it.
Post reply on HN