Live data from Hacker News

Passkeys: A shattered dream

fy.blackhats.net.au

101–110 of 789 posts

Re: Passkeys: A shattered dream

#101
post #57

Earlier quoted context omitted.

To be fair I've been to the US a few times and I've never been shot and I did end up in hospital and it was smooth as butter. Because I didn't hang around where I was likely to get shot and actually checked my insurance cover and had the cert on me. Note I live in London and everyone tells me I'm going to get stabbed too and die from the pollution...

London's homicide rate is (roughly, depending on which source you use and year you take) about one-fifth of the average US homicide rate; you are safer in London than in almost anywhere in the US.

13 per million per year in London. 60 per million per year in New York.

That's an 0.006% chance of getting murdered killed in NY every year.

And that doesn't account for (a) putting yourself in a good position to get killed like being a gang member and (b) the aggregate reduction in risk by only travelling there.

Re: Passkeys: A shattered dream

#105

The biggest issue with passkeys is that I just can't trust the companies offering them. They are locked into the platform for reasons that are ostensibly security but often indistinguishable from platform lock-in. If you make a passkey on an Apple device as far as I can tell it will never leave that device, ever, and there is no way to change this. Of course this means you can never be phished for your credentials bu…

Enroll another passkey. Password manager can also do that (Bitwarden, for example), so I really don‘t see a reason for all the agitation.

Re: Passkeys: A shattered dream

#107

The biggest issue with passkeys is that I just can't trust the companies offering them. They are locked into the platform for reasons that are ostensibly security but often indistinguishable from platform lock-in. If you make a passkey on an Apple device as far as I can tell it will never leave that device, ever, and there is no way to change this. Of course this means you can never be phished for your credentials bu…

Bitwarden (& vaultwarden) also offer passkey which seem to work pretty well.

I've not had a problem registering both this and my phone on any site.

Re: Passkeys: A shattered dream

#108
post #89
post #88

I think I'm a tech guy and know my fields. I still have no real clue how passkeys work, how it is better, what it really is. When your security feature is not as simple as - remember a name and a password and store it somewhere safe - it doesn't work. Something about keys that are on devices. But what happens when I use a phone and a pc? How to get access then? Do I need a User/PW for the first time? Or do I need one…

Passkeys are exactly like SSH keys. You should use them exactly like you use SSH keys.

If they are exactly like SSH keys, then why not just keep using SSH keys. Clearly, there is something else to them.

Re: Passkeys: A shattered dream

#109

Passkeys are horrible because the design encourages the need for a smartphone, which is itself a disaster.

Passkeys only encourage the need for a password management tool, which is funny because if everyone had password management tools to begin with then we wouldn't need passkeys.

True, the technical aspect of passkeys does that. But in practical Apple and others want to heavily push for the smartphone as that tool, because it locks people further into that system.

Re: Passkeys: A shattered dream

#110

The biggest issue with passkeys is that I just can't trust the companies offering them. They are locked into the platform for reasons that are ostensibly security but often indistinguishable from platform lock-in. If you make a passkey on an Apple device as far as I can tell it will never leave that device, ever, and there is no way to change this. Of course this means you can never be phished for your credentials bu…

I agree. So far I think KeePassXC is the only one that allows you to export your Passkeys. I believe Bitwarden are working on it as well. That said, it's unclear whether this will provide any portability of passkeys between providers.

Once you export your passkeys, is there anything that can import them?
Post reply on HN