Live data from Hacker News

Passkeys: A shattered dream

fy.blackhats.net.au

521–530 of 789 posts

Re: Passkeys: A shattered dream

#521
post #503

Earlier quoted context omitted.

> But they don't have the right to extract something from your brain. sure they do if, unless you want to be held in contempt of court for not providing the information.

Don’t you have a right to not incriminate yourself? You only have to give them information as long as you’re not incriminating yourself, right?

Historically, US courts have declared that giving a password is proof that you control the given asset and that this can be incriminating.

In practice, juries will take a refusal to divulge a password as evidence of guilt, the cops will use it as an excuse for even greater brutality, the FBI is perfectly willing to hold you without trial for years on end, and in most cases they don't need it anyway because everything lives on someone else's computer and they're perfectly willing to hand your data over if they haven't already. Furthermore, because the defense is founded on the principle that the password serves as evidence that you owned the encrypted data, if the prosecution is able to prove that you owned the encrypted data in any other way, that protection goes away.

  > In Boucher, production of the unencrypted 
  > drive was deemed not to be a self-incriminating
  > act, as the government already had
  > sufficient evidence to tie the encrypted
  > data to the defendant
I am, of course, not a lawyer. I'm just summarizing easily available information, i.e. wikipedia.

Re: Passkeys: A shattered dream

#522
post #488

Earlier quoted context omitted.

However the Windows sync is only possible due to Apple providing an app for use in Windows which suggests its still within the Apple ecosystem. Apple could on a whim decide to discontinue their app for Windows.

Then you export from keychain and import into a different password manager.

I’ve read multiple times in this thread that you can’t export passkeys from Apple’s keychain.

Re: Passkeys: A shattered dream

#523

The biggest issue with passkeys is that I just can't trust the companies offering them. They are locked into the platform for reasons that are ostensibly security but often indistinguishable from platform lock-in. If you make a passkey on an Apple device as far as I can tell it will never leave that device, ever, and there is no way to change this. Of course this means you can never be phished for your credentials bu…

There is a way around this. Password managers. I use 1Passwords and it acts as the vault for all my Passkeys. Can access them on all devices. Super happy with it.

Re: Passkeys: A shattered dream

#524

Earlier quoted context omitted.

But my password manager locks….requiring something stored in my brain.

Doesn't your password manager use biometrics to unlock though?

Yes, but that’s locked behind an OS level pass screen.

Re: Passkeys: A shattered dream

#525

Earlier quoted context omitted.

> and shut down my Google Pay account I never knew I had Google loves that nonsense, don't they? It's as though they think so highly of themselves that they cannot imagine they might not be strictly doing us all a favor by signing us up for their services. Fifteen years later, I still have friends occasionally sending messages to a GMail address I never asked for, never used, and didn't even know about for most of a…

Why don’t you setup the Gmail account to forward? I know it’s a hassle, but will resolve the issue

[deleted]

Re: Passkeys: A shattered dream

#526

The biggest issue with passkeys is that I just can't trust the companies offering them. They are locked into the platform for reasons that are ostensibly security but often indistinguishable from platform lock-in. If you make a passkey on an Apple device as far as I can tell it will never leave that device, ever, and there is no way to change this. Of course this means you can never be phished for your credentials bu…

The platform lock in attempt is wild, my initial experiences with Passkeys were great on iOS and Safari, either getting pushed to touch-id or scanning a QR with my phone. But then in Chrome I couldn't get into GitHub because chrome would only push me to use their manager and wouldn't offer a QR code. Seeing this more and more with Chrome, like Credit Card numbers used to just save and autocomplete in browser but then…

Same thing with google app on ios. My wife saved a password to a site on her phone and we were trying to find it to log in again. Since she had navigated to the site through the Google app, the password ended up in her google account instead of the iPhone keychain - unlike in every other app on the iPhone.

Re: Passkeys: A shattered dream

#527

Earlier quoted context omitted.

Could you expand on how to trick a password manager to enter the password on a fake domain ? I'd see having the user add the domain themselves, or get the user to copy/past the password themselves on some other form. But the phishing is not happening on the password manager side, and these use cases still exist even after you chose passkeys (i.e. I'd still need to somewhat log into Google's auth from my Nest hub for…

It happens to me very regularly that a password in my password manager is needed on a different domain. Maybe the logon process is at id.domain.com and password is pinned to domain.com, or maybe the password was created at signup.domain.com and so it doesn't pop up on domain.com, or you have to log in to a hotel's site with the password from their reward scheme (different domain), etc... In any case users are trained…

Also autofill is just broken by some sites and app login screens, so users are used to looking at and typing their passwords every now and then.

Re: Passkeys: A shattered dream

#528

Earlier quoted context omitted.

> and shut down my Google Pay account I never knew I had Google loves that nonsense, don't they? It's as though they think so highly of themselves that they cannot imagine they might not be strictly doing us all a favor by signing us up for their services. Fifteen years later, I still have friends occasionally sending messages to a GMail address I never asked for, never used, and didn't even know about for most of a…

Why don’t you setup the Gmail account to forward? I know it’s a hassle, but will resolve the issue

The account doesn't exist anymore.

Re: Passkeys: A shattered dream

#529
post #503

Every time I see a long inscrutable discussion about Passkeys, I see a weird avoidance of the "something you know" part of security. Here in the US, courts and law enforcement have every right to get your username, fingerprint, retina scan, face ID, whatever. But they don't have the right to extract something from your brain. Unless I'm missing something basic (which at this point, I don't think is my fault since thi…

> But they don't have the right to extract something from your brain. sure they do if, unless you want to be held in contempt of court for not providing the information.

In the U.S., this is a still-evolving area of law, which has been raised before the Supreme Court: https://www.supremecourt.gov/DocketPDF/23/23-1020/302999/202...

The State of Utah instructed the jury in State vs. Valdez to infer that a suspect was guilty because he refused to provide his password to the police. On appeal, the Utah Supreme Court ruled that he had the right to withhold his password according to the 5th Amendment, and he shouldn't face negative consequences for doing so. The state appealed that ruling to the U.S. Supreme Court, citing various other state and Federal courts which have made conflicting rulings on this same issue.

Sixteen states (Indiana, Alabama, Alaska, Delaware, Iowa, Kansas, Louisiana, Maine, Michigan, Mississippi, Nebraska, North Dakota, Ohio, Oregon, South Carolina, South Dakota, and Texas) just filed a motion asking the Court to hear the case: https://www.supremecourt.gov/DocketPDF/23/23-1020/307804/202...

Quoting that brief:

"[C]ourts have issued orders requiring persons to unlock devices or provide passcodes. But courts across the country are divided as to whether the Fifth Amendment bars such orders. [...] The Court should grant certiorari to provide guidance on how the Fifth Amendment’s guarantee against self-incrimination applies in the modern context of electronic devices."

The Court has yet to decide if they'll hear arguments: https://www.supremecourt.gov/search.aspx?filename=/docket/do...

More info/commentary here: https://reason.com/volokh/2023/12/14/is-compelled-decryption... (But I recommend going directly to the primary source material—legal documents in Supreme Court cases are very accessible, even to non-lawyers.)

Re: Passkeys: A shattered dream

#530
post #500

For folks who don't know how passkeys work at a technical level, take a look at this implementation guide: https://webauthn.guide/ I don't get the passkey hate -- moving to public key challenge for authentication is a strong step forward for web security. Each browser / OS safeguards & backs up the private key (and even if that's lost, you can still reset your auth credentials using a normal "forgot password" flow).

> I don't get the passkey hate The linked article does a quite good job explaining why hating passkeys make sense. Here's a key quote, but I do recommend reading the whole article. > Since then Passkeys are now seen as a way to capture users and audiences into a platform. What better way to encourage long term entrapment of users then by locking all their credentials into your platform, and even better, credentials t…

I don't believe this is necessarily true, as far as intent goes. I think Apple and Google focused on a core use case, shipped it, and subsequently lost interest or fired everyone involved.

Unfortunately, this scenario is indistinguishable from one in which they deliberately mishandled the specs in order to lock in users.

Post reply on HN