Live data from Hacker News

Passkeys: A shattered dream

fy.blackhats.net.au

61–70 of 789 posts

Re: Passkeys: A shattered dream

#61
post #2

I use iCloud's Passkeys extensively and have never had saved Passkeys "wiped out". I am not disputing that data loss bugs can happen, but three times for one user sounds pretty weird given the maturity of the ecosystem. The most obvious explanations seem to me to be: a) Apple loses data (presumably not just Passkeys, but also photos, passwords, and other highly noticeable stuff) all the time, and I've been lucky for…

> I use iCloud's Passkeys extensively So what happens if you want to migrate away from iCloud for the storage of passkeys?

You generally enroll a passkey for a single device or connected group of devices. My icloud-syncing devices has a passkey. My windows laptop has another. My desktop has yet another. I have also enrolled my yubikey.

I could stop using my idevices tomorrow and not be negatively influenced.

Re: Passkeys: A shattered dream

#62

Is the author suggesting he’s not traveling to the US out of security concerns? Is that really a thing?

The last time I was in the US, specifically in Seattle, there were two separate shootings within blocks of where I was at the time, and one at a bar an hour after I left it.

As an Australian, seeing it on the news the next mornings made me very, very uncomfortable.

I understand that these shootings are unlikely to ever involve me, and I’m not discomforted to the point that I won’t go back to the US, but it is worth understanding that gun crime in the US is seen as uncomfortable and concerning to many. That my US friends who were at the same venues with me were completely blasé about it left me a little nonplussed.

Re: Passkeys: A shattered dream

#63
post #46

Earlier quoted context omitted.

Password managers can store the passkeys just like they store passwords. 1Password has had strong support for them for quite a while now

Yeah probably can. But why do I need Passkeys?

If you’re asking in earnest: For the majority of users, Passkeys offer a pragmatic alternative to passwords that is far superior in terms of security.

For you, based on what I’ve read in your comments, I would say that Passkeys are the first workable alternative to passwords. They are built on WebAuthn which (roughly summarized) was the standard developed by Google and Yubico in direct response to the Operation Auora attack.

While the Apple/Microsoft/Google implementations of Passkeys likely won’t meet your personal standards, they’re built on a proven and well designed open standard. Which means you can benefit from the technology without buying into a corporate ecosystem.

Re: Passkeys: A shattered dream

#64

The biggest issue with passkeys is that I just can't trust the companies offering them. They are locked into the platform for reasons that are ostensibly security but often indistinguishable from platform lock-in. If you make a passkey on an Apple device as far as I can tell it will never leave that device, ever, and there is no way to change this. Of course this means you can never be phished for your credentials bu…

Use a different factor of authentication and setup a new passkey?

Re: Passkeys: A shattered dream

#65

Earlier quoted context omitted.

This is why services need to support multiple passkeys per user just like they should support multiple 2FA methods...

Big problem with this is that enrolling the secondary passkey requires the authenticator to be present. This is super inconvenient and risky as it always requires both authenticators to be present at the same machine/physical location, exposing both to local, physical threats (faulty USB ports on your machine frying anything you plug in? Congrats, you've now fried your main and any backup authenticators before you re…

This is why you need to enrol the secondary passkey at the same time you enrol the first one, not later when you might not have the authenticator present.

In reality websites should not allow setting up a single passkey.

Re: Passkeys: A shattered dream

#66
post #46

Earlier quoted context omitted.

Password managers can store the passkeys just like they store passwords. 1Password has had strong support for them for quite a while now

Yeah probably can. But why do I need Passkeys?

Strong mitm and phishing protection.

Re: Passkeys: A shattered dream

#67
post #33
post #23

Earlier quoted context omitted.

Oops, you forgot the other 2 travel advisories the author quoted in that part: - "Violent crime is more common in the US than in Australia" - "Medical costs in the US are extremely high. You may need to pay up-front for medical assistance" I think some Americans don't realize that, outside of America, many people don't ever consider the risk of gun violence in their day-to-day lives, or owing thousands of dollars for…

Actually, I specifically addressed the violent crime thing... As for the medical costs - if you want to be on the safe side, you can (actually you should) get travel health insurance.

> As for the medical costs - if you want to be on the safe side, you can (actually you should) get travel health insurance.

Though you might need to get a US specific one. Mine contains a clause that specifically excludes the USA from coverage, and that’s not uncommon.

Re: Passkeys: A shattered dream

#68
post #63
post #46

Earlier quoted context omitted.

Yeah probably can. But why do I need Passkeys?

If you’re asking in earnest: For the majority of users, Passkeys offer a pragmatic alternative to passwords that is far superior in terms of security. For you, based on what I’ve read in your comments, I would say that Passkeys are the first workable alternative to passwords. They are built on WebAuthn which (roughly summarized) was the standard developed by Google and Yubico in direct response to the Operation Auora…

If you use a software-based password manager, passkeys are indistinguishable from passwords both from a UX perspective and a security perspective.

If you store passkeys in hardware, then yes, passkeys are more secure, but you lose portability.

Re: Passkeys: A shattered dream

#69
post #2

I use iCloud's Passkeys extensively and have never had saved Passkeys "wiped out". I am not disputing that data loss bugs can happen, but three times for one user sounds pretty weird given the maturity of the ecosystem. The most obvious explanations seem to me to be: a) Apple loses data (presumably not just Passkeys, but also photos, passwords, and other highly noticeable stuff) all the time, and I've been lucky for…

It's not hyperbole. I recently (few weeks ago) got locked out of my GitHub account after iCloud Keychain thrashed my passkey and after analyzing the root cause it turned out to be a bug in webkit (that is now fixed in Safari technology preview after me raising it with the Webkit team)

https://bugs.webkit.org/show_bug.cgi?id=270553

Re: Passkeys: A shattered dream

#70
post #64

The biggest issue with passkeys is that I just can't trust the companies offering them. They are locked into the platform for reasons that are ostensibly security but often indistinguishable from platform lock-in. If you make a passkey on an Apple device as far as I can tell it will never leave that device, ever, and there is no way to change this. Of course this means you can never be phished for your credentials bu…

Use a different factor of authentication and setup a new passkey?

Do you have to do this for every account? Like changing my password on every account?
Post reply on HN