Live data from Hacker News

Passkeys: A shattered dream

fy.blackhats.net.au

81–90 of 789 posts

Re: Passkeys: A shattered dream

#81
post #19

Is the author suggesting he’s not traveling to the US out of security concerns? Is that really a thing?

Apparently... of course, the threat of "mass casualty violence and terrorist attacks" is real, but you're probably still more likely to die in a plane crash while getting to the US (or in a car accident while there) than in a shooting or terrorist attack. And if you insist on only travelling to countries that have a lower level of violent crime than Australia, you probably won't get around much ( https://worldpopulat…

The homicide rate in Australia is particularly low. But in terms of overall homicide rate the United States is higher than the vast majority of other developed countries, and indeed most developing countries.

Most of the world sees the United States as a dangerous country.

For example, using the source you've just given, the US homicide rate is over 5 times the homicide rate of the United Kingdom, France and Germany, and over 10 times that of Norway.

Granted, you're more likely to die in a car accident than to be murdered in the US, but that's no reassurance; this is partly because the vehicle accident mortality rate is so high in the US, at over four times the rate in the UK. And your comment about dying in a plane crash is completely wrong: the air travel mortality rate is very close to zero, with under 200 deaths for over 800 annual million air travellers; a rate of less than 0.025 per 100,000 per annum.

Re: Passkeys: A shattered dream

#82
Usernameless always seemed like an optimization too far to me.

I think it's totally reasonable, and probably a good thing for users having to use their username at login. Especially as it reminds them what username they are using for that service.

I could totally see a situation where a user uses a Usernameless passkey for years to access a service and for some reason loses access to the Usernameless passkey, and then has also forgotten the username for the service, so cannot even start an account recovery process.

Re: Passkeys: A shattered dream

#83

Earlier quoted context omitted.

Just you wait for governments to require platforms to only accept gov-signed keys. I was sceptical about something-you-own auth vs. something-you-know auth from the beginning and recieved backlash from my tech peers for it. I hate to be able to go "told you so" on this one. Lets hope im wrong about the government involvement, but i dont think i will.

not to diminish your point, but since at decade or so I'm a more worried about corporate surveillance capitalism than I'm about government surveillance.

I mean, same, but only because I realized a new undesirable thing was becoming a tacit reality that we'd have to accept on top of already undesirable thing

Re: Passkeys: A shattered dream

#84

Is the author suggesting he’s not traveling to the US out of security concerns? Is that really a thing?

From https://github.com/orgs/community/discussions/54450#discussi... :

"I'm Australian so I wont be attending either (I am not comfortable to enter the US due to a preexisting medical issue)."

That's the "Medical costs in the US are extremely high. You may need to pay up-front for medical assistance" part of the text.

I do not know if travel health insurance generally covers complications from a pre-existing condition, and as other mentioned, getting travel insurance which covers the US is already a special case.

Re: Passkeys: A shattered dream

#85
I've had Apple silently delete music from Music when I had iTunes Match, and I've stayed paying for Dropbox despite wanting to use iCloud, which would be no extra cost for me, because their mechanisms for dealing with conflicts are different - Dropbox saves a version with "Name's conflicted version 2024-04-26" in the filename, whereas AFAIK iCloud silently decides what to keep and drop so you can't manually decide how to merge a conflict.

I too find it hard to imagine how someone can lose all their passkeys three times, and I guess they may be doing something funky given their profession, but I think many of these events just happen too easily in the Apple ecosystem and my trust in them managing things like that is relatively low - hence my use of 1Password instead of iCloud keychain. The Music thing in particular really stung as I never got a good handle on what was missing - I'd just occasionally come across a "this file is missing" error when I tried to play a song, and I'm left with this kind of cloud of unknowing when it comes to my Music library.

Re: Passkeys: A shattered dream

#86

The biggest issue with passkeys is that I just can't trust the companies offering them. They are locked into the platform for reasons that are ostensibly security but often indistinguishable from platform lock-in. If you make a passkey on an Apple device as far as I can tell it will never leave that device, ever, and there is no way to change this. Of course this means you can never be phished for your credentials bu…

I think it is true that you can's export passkeys stored in Apple Keychain. However, the statement is false in two ways:

- Apple's iCloud Keychain syncs across devices

- Apple has APIs that allow third party apps to create and offer passkeys, presented as a first-class option in Apple's authentication system. I use this to sync my passkeys between my Mac, Windows PC, and iPhone.

Re: Passkeys: A shattered dream

#87
post #75

Passkeys can't actually replace passwords, right? I will always need a username and password with a website, then can generate a passkey as a separate auth mechanism, which if I lose, I will recover by setting up again using my username and password? I don't get how we can get to a place where passkeys are all, how do you get a passkey on a new device when you only have passkey auth on some other device enabled?

This is how I'm using them. Still have a username/password, with a passkey as an additional factor. I use 1Password for passkeys rather than Apple's solution, which enables me to use them wherever I have 1Password.

Re: Passkeys: A shattered dream

#88
I think I'm a tech guy and know my fields. I still have no real clue how passkeys work, how it is better, what it really is.

When your security feature is not as simple as - remember a name and a password and store it somewhere safe - it doesn't work.

Something about keys that are on devices. But what happens when I use a phone and a pc? How to get access then? Do I need a User/PW for the first time? Or do I need one of those keys I have to plug into the device first?

Re: Passkeys: A shattered dream

#89
post #88

I think I'm a tech guy and know my fields. I still have no real clue how passkeys work, how it is better, what it really is. When your security feature is not as simple as - remember a name and a password and store it somewhere safe - it doesn't work. Something about keys that are on devices. But what happens when I use a phone and a pc? How to get access then? Do I need a User/PW for the first time? Or do I need one…

Passkeys are exactly like SSH keys. You should use them exactly like you use SSH keys.

Re: Passkeys: A shattered dream

#90
post #57
post #23

Earlier quoted context omitted.

Oops, you forgot the other 2 travel advisories the author quoted in that part: - "Violent crime is more common in the US than in Australia" - "Medical costs in the US are extremely high. You may need to pay up-front for medical assistance" I think some Americans don't realize that, outside of America, many people don't ever consider the risk of gun violence in their day-to-day lives, or owing thousands of dollars for…

To be fair I've been to the US a few times and I've never been shot and I did end up in hospital and it was smooth as butter. Because I didn't hang around where I was likely to get shot and actually checked my insurance cover and had the cert on me. Note I live in London and everyone tells me I'm going to get stabbed too and die from the pollution...

London's homicide rate is (roughly, depending on which source you use and year you take) about one-fifth of the average US homicide rate; you are safer in London than in almost anywhere in the US.
Post reply on HN