Live data from Hacker News

Passkeys: A shattered dream

fy.blackhats.net.au

571–580 of 789 posts

Re: Passkeys: A shattered dream

#571

Here's my opposing view: I love Passkeys. I use Firefox as my browser and 1Password as my password manager. On my iPhone, I use 1Password + Firefox. I look at https://passkeys.directory/ every so often and switch my logins from passwords to passkeys. This has included a lot of my common logins like GitHub, Google, and Microsoft. There is a lot of confusing terminology. For some reason sites will say "login with Touch…

If your only argument is "wow, it's easy", you're not arguing from the perspective of any kind of security.

I can believe it's easy. But just knowing this doesn't give you any understanding of potential downsides.

Years ago I lost access to various stack-exchange accounts when Yahoo stopped offering Oauth services. Thankfully not a biggie for me but it soured me on relying on third parties for access to a given account.

Re: Passkeys: A shattered dream

#572
post #537

Earlier quoted context omitted.

Thanks for your faith. I work on the team shipping passkeys at Google. We are very much hard at work to realize the full potential of passkeys. Platform lockin serves no one. That is no one's intent - independent password managers storing passkeys is already a thing today. More interop will come once relevant standards are blessed.

I’m sorry, but you’re either naive or lying. This is precisely like the imaging standards trying to replace JPG. After two decades of vendors like Google trying to establish a new standard, I can’t send anything other than an SDR sRGB JPEG to anyone, especially to an Android user. The current post-JPG formats may as well be called “the Apple format”, “Google image”, and “Netflix pics”. There is no practical interoper…

I said "more interop" is coming..

There is a significant amount of interop that already exists, that folks are looking past or just already taken for granted (which is actually fine too!). While on a Windows machine using Edge, you can save a passkey for your Google account to your 1Password vault, and use it to sign in to that Google account on Chrome on Mac (if you have signed in to the same 1Password account on the machines). Or you could use a passkey you saved to your iPhone / iCloud to sign in to the Google account on ChromeOS. This is the level of interop that exists today. This did not just happen magically - all these companies (and more) worked hard to make it happen.

Also speaking for Google accounts, passkeys are an additional option for users. Using a passkey is not preventing you from keeping any other sign in method on your account that you feel has less of the lockin risk.

Re: Passkeys: A shattered dream

#573
post #201

Earlier quoted context omitted.

> I want to still use a username/password and the Yubikey. Why?

Because of the whole "multi-factor" thing, and not making account recovery impossible? Passkeys are always going to be less secure than username + password + Webauthn, why would you intentionally make your account less secure and give yourself a massive failure mode in the process?

You can (and are generally required to unless you purposefully use a "non-compliant" implementation that ignores it) set a PIN on your passkey.

> Passkeys are always going to be less secure than username + password + Webauthn

It's less secure in the same way that a door is less secure if you put a single strip of duct tape across that same door. Technically yes, but not in any meaningful sense.

Re: Passkeys: A shattered dream

#574
post #511

Earlier quoted context omitted.

So use a password manager still (1P). You can have multiple passkeys for different devices or keychains but no entering passwords or credentials. Still an improvement and far less vulnerable.

1Password is a platform, one that has gotten worse over the years. They've taken a bunch of venture capital, switched to rental pricing, and apparently now demand that everything be in the "cloud". No thanks. I prefer to be my own password manager.

Then perhaps Bitwarden… or do you have a bone to pick with them as well?

There are choices.

Re: Passkeys: A shattered dream

#575
post #218

The part I hate most about Passkeys is that it essentially killed the FIDO1/U2F ecosystem. Just about every website which implemented Passkeys removed the option to use hardware tokens with "non-resident" credentials. This means you're stuck using your Yubikey as either an insecure TOTP token, or as a practically-useless Passkey. We had the perfect 2FA method with U2F hardware tokens, why did they have to take that a…

> Just about every website which implemented Passkeys removed the option to use hardware tokens with "non-resident" credentials

Which ones? AFAIK they support passkeys in addition to password+U2F 2FA

Re: Passkeys: A shattered dream

#576

I just went through the dance of logging out of all my google accounts and then logging back into them. While I was doing that, I added passkeys as a security layer. Using bitwarden, it adds them in just fine. But, if you go and try to log into a Google account with Brave, it tries to use the Brave system builtin instead of the Bitwarden one. Presenting a dialog too. As an end user, I don't know if it is bitwarden, b…

It's Brave, the browser is responsible for handling the WebAuthn (or alternatively, the Bitwarden extension for Brave, assuming that Brave exposes some API to extensions which Bitwarden has not implemented correctly)

Re: Passkeys: A shattered dream

#577

Earlier quoted context omitted.

You are able to share an Apple passkey to any nearby Apple device at any time using AirDrop. Passkeys can also be used cross-platform during sign in via an NFC/Bluetooth handshake initiated by QR code. Additionally, passkeys are just a synced-via-cloud implementation of FIDO2, an open standard that has other implementations you may feel more comfortable using. For someone who requires being able to sign in to, say, G…

But what happens if I as an iPhone user want to switch to Android next year? Can I move my Apple passkeys?

You can use passkeys cross platform already, eg with 1Password or even KeePass XC.

But I do agree with the point that Passkeys make it really easy to get locked in unless you’re careful.

Re: Passkeys: A shattered dream

#578

Earlier quoted context omitted.

1Password is a closed-source, cloud-hosted service. At any time, for any reason, they can close and delete your account, leaving you high and dry. Self-hosted, multi-device password managers are the only real solution. Thankfully, Vaultwarden and KeePassXC fill this role perfectly. Now if we could just get the other providers that require insecure email/SMS 2FA to follow suit, that would be great...

I’m really not sure the “only real solution” is every human needs to selfhost a password manager. That’s ill-advised; an extreme take. The vast majority of the population will do a worse job on the availability and security of a selfhost solution than 1Password, whose core business and value proposition is password management. I’m a very happy user of 1Password for Families and consider it the likely the best ~$50 a…

Agreed. I self hosted the key 100 bitcoin in like 2010. Machine crashed. Oops.

Re: Passkeys: A shattered dream

#579

Earlier quoted context omitted.

I use 1Password which supports Passkeys, and don’t have an issue across mobile or desktop. I don’t get what the issues people have really are. I never experience them (fortunately!).

1Password is a closed-source, cloud-hosted service. At any time, for any reason, they can close and delete your account, leaving you high and dry. Self-hosted, multi-device password managers are the only real solution. Thankfully, Vaultwarden and KeePassXC fill this role perfectly. Now if we could just get the other providers that require insecure email/SMS 2FA to follow suit, that would be great...

And KeePass XC supports passkeys too[1]. Although I’ve not had a chance to try that out yet.

[1] https://keepassxc.org/docs/KeePassXC_UserGuide#_passkeys

Re: Passkeys: A shattered dream

#580

The biggest issue with passkeys is that I just can't trust the companies offering them. They are locked into the platform for reasons that are ostensibly security but often indistinguishable from platform lock-in. If you make a passkey on an Apple device as far as I can tell it will never leave that device, ever, and there is no way to change this. Of course this means you can never be phished for your credentials bu…

I think it’s about platform lock-in as well, tightly correlated to pivoting away from cookies due to regs and user pushback.

If you read adtech docs, authenticated user sessions are the gold standard on enumerating user preferences for the sake of ads.

Un/pw friction is noted as a difficulty in achieving this. Cookies developed the way they did in response, +/- details.

If cookies go, then passkeys look a lot like a tangible and realistic solution to enumerating users via authn/z’d sessions, minus the friction of un/pw and a pw manager.

IMO, the impacts of passkeys will feed right into this solution, and while I’m not sure if you can safely argue passkeys are a nefarious plan to replace cookie tracking, I don’t think you can get a tech giant to support such a reimagining of user experience if it didn’t have ancillary benefits beyond solely security use cases. When has a company like Apple or Google ever done such an equivalently large amount of work solely in support of security?

Post reply on HN