Live data from Hacker News

Passkeys: A shattered dream

fy.blackhats.net.au

51–60 of 789 posts

Re: Passkeys: A shattered dream

#51

The biggest issue with passkeys is that I just can't trust the companies offering them. They are locked into the platform for reasons that are ostensibly security but often indistinguishable from platform lock-in. If you make a passkey on an Apple device as far as I can tell it will never leave that device, ever, and there is no way to change this. Of course this means you can never be phished for your credentials bu…

Honestly platform-locking has so frequently and consistently been the intent of security-washing rhetoric and major breaches have become so commonplace that I now view "security" in the press to be a euphemism for lock-in first and foremost, with other usages being anachronistic or niche

Re: Passkeys: A shattered dream

#52

Earlier quoted context omitted.

Yes, there are plenty of people who avoid travelling to the US

I know that, but I didn’t think it was because of security. I don’t think of the US as particularly dangerous, but maybe my perception is wrong…

It's the guns and the police.

People get angry or frightened. It's better for everyone else if they're not carrying a firearms at that point.

Policing a nation where everyone is armed means the police are heavily armed and the non-insane ones very frightened all the time. See above.

Re: Passkeys: A shattered dream

#53
post #2

I use iCloud's Passkeys extensively and have never had saved Passkeys "wiped out". I am not disputing that data loss bugs can happen, but three times for one user sounds pretty weird given the maturity of the ecosystem. The most obvious explanations seem to me to be: a) Apple loses data (presumably not just Passkeys, but also photos, passwords, and other highly noticeable stuff) all the time, and I've been lucky for…

> I use iCloud's Passkeys extensively So what happens if you want to migrate away from iCloud for the storage of passkeys?

I can't speak for OP, but for every service that I use passkeys with I enrolled both iCloud Passkeys (for convenience) and several YubiKeys (for portability and backup).

This is not different at all from a SSH public/private key combo. You are not supposed to duplicate SSH keys!

Re: Passkeys: A shattered dream

#54
post #50

The biggest issue with passkeys is that I just can't trust the companies offering them. They are locked into the platform for reasons that are ostensibly security but often indistinguishable from platform lock-in. If you make a passkey on an Apple device as far as I can tell it will never leave that device, ever, and there is no way to change this. Of course this means you can never be phished for your credentials bu…

I thought passkeys were shared across Apple keychain (like passwords?) so you make a passkey on iPhone your iPad can use it.

Yes, that's correct, they're stored in Keychain and shared using iCloud.

Re: Passkeys: A shattered dream

#55
post #2

I use iCloud's Passkeys extensively and have never had saved Passkeys "wiped out". I am not disputing that data loss bugs can happen, but three times for one user sounds pretty weird given the maturity of the ecosystem. The most obvious explanations seem to me to be: a) Apple loses data (presumably not just Passkeys, but also photos, passwords, and other highly noticeable stuff) all the time, and I've been lucky for…

> b) The author is doing something weird.

The author is the main dev of an identity management platform and called kanidm, so yeah I'd wager their usage is fairly non-standard. That said, it should be almost impossible for it to happen anyway.

Also, that doesn't apply to his partner.

Re: Passkeys: A shattered dream

#56

> At this point I think that Passkeys will fail in the hands of the general consumer population. Actually, I think it might be worse. The predators like Apple/Google have already pounced on passkeys as a consumer capture mechanism, so they'll ensure it doesn't fail.

Just you wait for governments to require platforms to only accept gov-signed keys.

I was sceptical about something-you-own auth vs. something-you-know auth from the beginning and recieved backlash from my tech peers for it. I hate to be able to go "told you so" on this one. Lets hope im wrong about the government involvement, but i dont think i will.

Re: Passkeys: A shattered dream

#57
post #23
post #19

Earlier quoted context omitted.

Apparently... of course, the threat of "mass casualty violence and terrorist attacks" is real, but you're probably still more likely to die in a plane crash while getting to the US (or in a car accident while there) than in a shooting or terrorist attack. And if you insist on only travelling to countries that have a lower level of violent crime than Australia, you probably won't get around much ( https://worldpopulat…

Oops, you forgot the other 2 travel advisories the author quoted in that part: - "Violent crime is more common in the US than in Australia" - "Medical costs in the US are extremely high. You may need to pay up-front for medical assistance" I think some Americans don't realize that, outside of America, many people don't ever consider the risk of gun violence in their day-to-day lives, or owing thousands of dollars for…

To be fair I've been to the US a few times and I've never been shot and I did end up in hospital and it was smooth as butter. Because I didn't hang around where I was likely to get shot and actually checked my insurance cover and had the cert on me.

Note I live in London and everyone tells me I'm going to get stabbed too and die from the pollution...

Re: Passkeys: A shattered dream

#58
post #33

Earlier quoted context omitted.

Actually, I specifically addressed the violent crime thing... As for the medical costs - if you want to be on the safe side, you can (actually you should) get travel health insurance.

I've heard horror stories about hospitals not accepting insurance. Wouldn't want to be in a situation of being ill and having to pay more than I can earn in a lifetime.

They will accept it. The cover has to be specifically for US hospitals otherwise the insurer won't pay out and they know that and won't accept it. You have to avoid insurers who only cover certain providers as well.

You have to read your insurance contract and info sheet properly rather than go for the lowest price.

Re: Passkeys: A shattered dream

#59
> But of course, thought leaders exist, and Apple hadn't defined what a Passkey was. One of those thought leaders took to the FIDO conference stage and announced "Passkeys are resident keys", at the same time as the unleashed a passkeys dev website (I won't link to it out of principal).

I'm trying to follow the developments in the 2-factor-auth space and this was one thing that confused me a lot. I've read a lot of hype on Passkeys being the next big thing but it was really hard to find an actual explanation what they are and how they work. And once I found out that these are keys that are stored on the security key, I was rather disappointed, because I really like the idea of generating keys on the fly based on the domain name that I'm authenticating against. This way I can "store" an infinite number of keys. The upside of Passkeys is supposedly that you do not need to remember which username you have on a website, but I think that's a minor upside.

Related question: What is the official name for the (FIDO2-based?/WebAuthn-based?) technology that calculates and reconstructs keys on the fly based on the domain name of the service that I'm authenticating against? It is really difficult to learn the right terminology in the area.

Edit: I think I found the answer here: https://fy.blackhats.net.au/blog/2023-02-02-how-hype-will-tu...

A key that is reconstructed on the fly is called a "non-resident credential".

Re: Passkeys: A shattered dream

#60
post #50

Earlier quoted context omitted.

I thought passkeys were shared across Apple keychain (like passwords?) so you make a passkey on iPhone your iPad can use it.

Yes, that's correct, they're stored in Keychain and shared using iCloud.

Ah, yes, poor choice of words on my part. They are in iCloud Keychain (I think this is required?). But if you only have one device it's basically the same thing, or if you're trying to leave the ecosystem.
Post reply on HN