Live data from Hacker News

Passkeys: A shattered dream

fy.blackhats.net.au

481–490 of 789 posts

Re: Passkeys: A shattered dream

#482
Yeah, good riddance.

I get the capitalist inclination and desire to make things easier for people (and often infantilize them) but this just ain't it.

There is no easy solution here. Security is difficult and there are no shortcuts that involve "make things easier for the general public" that don't ALSO involve "make things MUCH HARDER (either in complexity or LIABILITY for getting it wrong) for the company providing the security."

Re: Passkeys: A shattered dream

#483
For folks who don't know how passkeys work at a technical level, take a look at this implementation guide: https://webauthn.guide/

I don't get the passkey hate -- moving to public key challenge for authentication is a strong step forward for web security. Each browser / OS safeguards & backs up the private key (and even if that's lost, you can still reset your auth credentials using a normal "forgot password" flow).

Re: Passkeys: A shattered dream

#484

Earlier quoted context omitted.

Where did you see that? This comment just 4 months ago from 1Password says that exporting isn't possible: https://www.reddit.com/r/1Password/comments/18m4iph/comment/... And I haven't seen any announcements in the opposite direction. ———— Edit: so I just checked and I can confirm that it's not possible to export passkeys from 1Password. Neither of the two available export options include passkeys. > • 1PUX A 1Passwor…

Well then their enshitification just continues with their unending quest for burning every user-centric bridge they ever built. Goddamn To answer your question, "bamboo menu, Copy Item JSON" which I believe is turned on due to my "Preferences, Advanced, Show debugging tools" being checked. I actually did try the $(op item get --format=json $its_uuid) first but figured there was some sekrit env var or --fields some_ho…

Wow I confirm that this option appears once I enable the developer options. Don't say it too loud though — I'm sure 1Password will remove it if they notice that it slipped past their view because of just dumping the JSON object.

Re: Passkeys: A shattered dream

#485

I’ve avoided passkeys so far because I just don’t have a good mental model of them. All my passwords are randomly generate and stored in a password manager so I really haven’t felt the need to switch or felt constrained by my existing set up. I fully understand username/email + password and remembering the pain of things like “app specific passwords” makes me worry that some tools (open source, cli, etc) might not in…

[deleted]

Re: Passkeys: A shattered dream

#486

Earlier quoted context omitted.

> Passkeys can make it harder to switch password managers because the password managers are designed not to let you copy-and-paste a passkey, including from Google's Password Manager to Apple's Password Manager. This part right here is what I fear the most about Passkeys. I've read too many horror stories of people getting banned from Google (often for no valid reason) and losing access to all of their data. It is ab…

I have been using passkeys for a while in the form of yubikeys Best practice is to register two keys to every website. Keep one physically in a safe. With password managers I would say the same basic practice applies. Make sure you have a working offline backup of whatever secrets you hold dear. There are some sites that only allow you to register a single passkey for an account (AWS Console last I checked) but these…

> Best practice is to register two keys to every website. Keep one physically in a safe.

Well, this sounds convenient. Keep the second one in a safe, but register a key to it for every website you use.

Is this a practice we actually believe users will carry out?

Re: Passkeys: A shattered dream

#487
post #23

Earlier quoted context omitted.

Oops, you forgot the other 2 travel advisories the author quoted in that part: - "Violent crime is more common in the US than in Australia" - "Medical costs in the US are extremely high. You may need to pay up-front for medical assistance" I think some Americans don't realize that, outside of America, many people don't ever consider the risk of gun violence in their day-to-day lives, or owing thousands of dollars for…

We don’t actually consider that in the US either, you probably shouldn’t get your views of the US from Reddit or the Guardian.

I know several Americans who consider both of those things.

Re: Passkeys: A shattered dream

#488
post #455

Earlier quoted context omitted.

I don't sync anywhere because I don't use the Apple keychain for my passwords. No idea if there is a solution for Android but the original claim was syncing between your devices was only possible if you stayed strictly with the Apple ecosystem. This is not accurate since you can sync to Windows even if you can't sync to Android.

However the Windows sync is only possible due to Apple providing an app for use in Windows which suggests its still within the Apple ecosystem. Apple could on a whim decide to discontinue their app for Windows.

Then you export from keychain and import into a different password manager.

Re: Passkeys: A shattered dream

#489

Earlier quoted context omitted.

> there's no social-engineering technique someone can use to get you to copy and paste your passkey to an enemy This is a deep, fundamental flaw in passkeys. It's just another example of enshittification disguised as denying end-user control "for their own good." There is no for-profit organization anywhere that I trust more than I trust myself, and there's no threat model where it's more likely I'll be socially engi…

Then use a password manager that allows it

[deleted]
Post reply on HN