Live data from Hacker News

Passkeys: A shattered dream

fy.blackhats.net.au

71–80 of 789 posts

Re: Passkeys: A shattered dream

#71

> At this point I think that Passkeys will fail in the hands of the general consumer population. Actually, I think it might be worse. The predators like Apple/Google have already pounced on passkeys as a consumer capture mechanism, so they'll ensure it doesn't fail.

Just you wait for governments to require platforms to only accept gov-signed keys. I was sceptical about something-you-own auth vs. something-you-know auth from the beginning and recieved backlash from my tech peers for it. I hate to be able to go "told you so" on this one. Lets hope im wrong about the government involvement, but i dont think i will.

not to diminish your point, but since at decade or so I'm a more worried about corporate surveillance capitalism than I'm about government surveillance.

Re: Passkeys: A shattered dream

#72

Earlier quoted context omitted.

Yes, there are plenty of people who avoid travelling to the US

I know that, but I didn’t think it was because of security. I don’t think of the US as particularly dangerous, but maybe my perception is wrong…

Homicide rate is 10x the rate of EU and over 30x the rate of Japan: https://independentaustralia.net/politics/politics-display/a...

Rape rate is about 3x the rate of EU: https://www.civitas.org.uk/content/files/crime_stats_oecdjan...

People killed by police (population adjusted) is about 30x the rate of Germany: https://www.statista.com/statistics/585152/people-shot-to-de... https://polizeischuesse.cilip.de/?p=1&year=2023

Re: Passkeys: A shattered dream

#73
post #51

The biggest issue with passkeys is that I just can't trust the companies offering them. They are locked into the platform for reasons that are ostensibly security but often indistinguishable from platform lock-in. If you make a passkey on an Apple device as far as I can tell it will never leave that device, ever, and there is no way to change this. Of course this means you can never be phished for your credentials bu…

Honestly platform-locking has so frequently and consistently been the intent of security-washing rhetoric and major breaches have become so commonplace that I now view "security" in the press to be a euphemism for lock-in first and foremost, with other usages being anachronistic or niche

Dont forget the euphemism "For your security" == "surveillance" -> EDR

Re: Passkeys: A shattered dream

#74
post #33
post #23

Earlier quoted context omitted.

Oops, you forgot the other 2 travel advisories the author quoted in that part: - "Violent crime is more common in the US than in Australia" - "Medical costs in the US are extremely high. You may need to pay up-front for medical assistance" I think some Americans don't realize that, outside of America, many people don't ever consider the risk of gun violence in their day-to-day lives, or owing thousands of dollars for…

Actually, I specifically addressed the violent crime thing... As for the medical costs - if you want to be on the safe side, you can (actually you should) get travel health insurance.

Every medical travel insurance I ever bought had a clause that it doesn't work in the US.

Re: Passkeys: A shattered dream

#75
Passkeys can't actually replace passwords, right? I will always need a username and password with a website, then can generate a passkey as a separate auth mechanism, which if I lose, I will recover by setting up again using my username and password? I don't get how we can get to a place where passkeys are all, how do you get a passkey on a new device when you only have passkey auth on some other device enabled?

Re: Passkeys: A shattered dream

#76
post #75

Passkeys can't actually replace passwords, right? I will always need a username and password with a website, then can generate a passkey as a separate auth mechanism, which if I lose, I will recover by setting up again using my username and password? I don't get how we can get to a place where passkeys are all, how do you get a passkey on a new device when you only have passkey auth on some other device enabled?

They are stored in your platform's password manager. So they're available on all the devices you're logged into.

If you're enrolling a new device (say you buy a new android phone) you can scan a QR code from your previous phone go log in.

Re: Passkeys: A shattered dream

#77
post #43

I can't help feeling this... In an adverse world software and electronic data is too ephemeral to entrust with authentication and authorization. What if we had something solid like a Yubikey, but: - credit card sized - completely airgapped - standardized - controlled by a non-profit association - hard- and software open sourced - built-in camera to scan data - built-in display to show data - configuration mode: scan…

If you ignore the last 6 points about cameras and displays, then this is kinda what "Smartcards" are, I think?

https://en.wikipedia.org/wiki/OpenPGP_card

In fact the Estonian Id-Card is one of these if I'm not mistaken

Re: Passkeys: A shattered dream

#78

The biggest issue with passkeys is that I just can't trust the companies offering them. They are locked into the platform for reasons that are ostensibly security but often indistinguishable from platform lock-in. If you make a passkey on an Apple device as far as I can tell it will never leave that device, ever, and there is no way to change this. Of course this means you can never be phished for your credentials bu…

I agree. So far I think KeePassXC is the only one that allows you to export your Passkeys. I believe Bitwarden are working on it as well. That said, it's unclear whether this will provide any portability of passkeys between providers.

Re: Passkeys: A shattered dream

#79
post #43

I can't help feeling this... In an adverse world software and electronic data is too ephemeral to entrust with authentication and authorization. What if we had something solid like a Yubikey, but: - credit card sized - completely airgapped - standardized - controlled by a non-profit association - hard- and software open sourced - built-in camera to scan data - built-in display to show data - configuration mode: scan…

If you ignore the last 6 points about cameras and displays, then this is kinda what "Smartcards" are, I think? https://en.wikipedia.org/wiki/OpenPGP_card In fact the Estonian Id-Card is one of these if I'm not mistaken

The problem with smartcards is: I don't see what's on them.

Re: Passkeys: A shattered dream

#80
post #75

Passkeys can't actually replace passwords, right? I will always need a username and password with a website, then can generate a passkey as a separate auth mechanism, which if I lose, I will recover by setting up again using my username and password? I don't get how we can get to a place where passkeys are all, how do you get a passkey on a new device when you only have passkey auth on some other device enabled?

They are stored in your platform's password manager. So they're available on all the devices you're logged into. If you're enrolling a new device (say you buy a new android phone) you can scan a QR code from your previous phone go log in.

I see, so you can use one device to auth and create a passkey on another
Post reply on HN