Live data from Hacker News

Passkeys: A shattered dream

fy.blackhats.net.au

681–690 of 789 posts

Re: Passkeys: A shattered dream

#681

The biggest issue with passkeys is that I just can't trust the companies offering them. They are locked into the platform for reasons that are ostensibly security but often indistinguishable from platform lock-in. If you make a passkey on an Apple device as far as I can tell it will never leave that device, ever, and there is no way to change this. Of course this means you can never be phished for your credentials bu…

You are able to share an Apple passkey to any nearby Apple device at any time using AirDrop. Passkeys can also be used cross-platform during sign in via an NFC/Bluetooth handshake initiated by QR code. Additionally, passkeys are just a synced-via-cloud implementation of FIDO2, an open standard that has other implementations you may feel more comfortable using. For someone who requires being able to sign in to, say, G…

"Alright Mom, here's what you have to do..."

Re: Passkeys: A shattered dream

#682

The biggest issue with passkeys is that I just can't trust the companies offering them. They are locked into the platform for reasons that are ostensibly security but often indistinguishable from platform lock-in. If you make a passkey on an Apple device as far as I can tell it will never leave that device, ever, and there is no way to change this. Of course this means you can never be phished for your credentials bu…

Bitwarden? Proton?

Re: Passkeys: A shattered dream

#683
post #411

Here's my opposing view: I love Passkeys. I use Firefox as my browser and 1Password as my password manager. On my iPhone, I use 1Password + Firefox. I look at https://passkeys.directory/ every so often and switch my logins from passwords to passkeys. This has included a lot of my common logins like GitHub, Google, and Microsoft. There is a lot of confusing terminology. For some reason sites will say "login with Touch…

I went through passkeys.directory site and it's underwhelming. Too few sites implement it, and many implement it inconsistently: - PayPal only allows one passkey and don't support logging in with it on Firefox on Windows. You still have to use your password. - Twitter only offers it if you pay for a subscription. - Playstation Network doesn't implement usernameless, and still asks for your email to log you in with a…

> It seems like we still have some way to go before we figure it all out.

You're 100% right, though I'm actually surprised that so many sites already support passkeys.

If passkeys is a good idea and consumers use them, then gradually sites will shift over. Changing how everyone in the world does auth is not going to happen overnight, or even in a year.

Re: Passkeys: A shattered dream

#684

The biggest issue with passkeys is that I just can't trust the companies offering them. They are locked into the platform for reasons that are ostensibly security but often indistinguishable from platform lock-in. If you make a passkey on an Apple device as far as I can tell it will never leave that device, ever, and there is no way to change this. Of course this means you can never be phished for your credentials bu…

Wouldn't this be solved by just having multiple passkeys for each account?

You create one on your iPhone and another "backup" key from a desktop PC running some open source software. If your iPhone breaks you can always use the other.

Similar to a server configured to accept multiple different SSH keys.

Re: Passkeys: A shattered dream

#685

Earlier quoted context omitted.

Just add a passkey for brave too

No, I don't want to be tied to a single browser for my passkey, what happens if I want to log into a site on my phone using safari or chrome? I also don't want it tied to my apple keychain. What if I want to share my passkey with my partner?

lol it’s a passkey… why would you want 1 that can be shared and… lost you just register another one

Being like “I don’t want to add another passkey” is really a semantic issue what exactly is the difference to you or adding a passkeys to an account vs copying a passkey to another device except the fact that if you can copy it/share it… it’d be far less secure with more ways to leak

Re: Passkeys: A shattered dream

#687

Earlier quoted context omitted.

> 1Password is a closed-source, cloud-hosted service. At any time, for any reason, they can close and delete your account They used to offer their apps offline and you could "host" it anywhere. Venture Capital ruined them.

Having the passwords in the cloud is useful though. Before, if you wanted to use your vault across multiple machines, you had to store your vault in someone else’s cloud. This simplifies the process.

Incorrect. 1P orginally offer direct LAN syncing among machines.

Re: Passkeys: A shattered dream

#688

The biggest issue with passkeys is that I just can't trust the companies offering them. They are locked into the platform for reasons that are ostensibly security but often indistinguishable from platform lock-in. If you make a passkey on an Apple device as far as I can tell it will never leave that device, ever, and there is no way to change this. Of course this means you can never be phished for your credentials bu…

You are supposed to use multiple passkeys or you can use a password manager to store and sync your passkeys cross platform.

Your passkeys sync in iCloud they aren’t device bound, just platform bound. Passkey export import is being worked on.

Re: Passkeys: A shattered dream

#689

Earlier quoted context omitted.

1Password is a closed-source, cloud-hosted service. At any time, for any reason, they can close and delete your account, leaving you high and dry. Self-hosted, multi-device password managers are the only real solution. Thankfully, Vaultwarden and KeePassXC fill this role perfectly. Now if we could just get the other providers that require insecure email/SMS 2FA to follow suit, that would be great...

I’m really not sure the “only real solution” is every human needs to selfhost a password manager. That’s ill-advised; an extreme take. The vast majority of the population will do a worse job on the availability and security of a selfhost solution than 1Password, whose core business and value proposition is password management. I’m a very happy user of 1Password for Families and consider it the likely the best ~$50 a…

I also think that the "self-hosted" requirement is an over-reach. It would be sufficient to require some standardized commodity that can, in principle, be self-hosted, but is available in an equivalent form from multiple unaffiliated third parties. E.g., a WebDAV folder.

Re: Passkeys: A shattered dream

#690

Earlier quoted context omitted.

Agreed. I self hosted the key 100 bitcoin in like 2010. Machine crashed. Oops.

That's a fundamental problem with cryptographic security: you cannot trust people to manage your keys for you (because due to lack of regulation preventing that companies have this bad habit of pulling the rug under their customers' feet) but you cannot trust yourself doing that either, because you can, and will, make mistakes.

It's worse: there are regulations (called "sanctions" and "KYC") that force companies to pull the rug.
Post reply on HN