Live data from Hacker News

Passkeys: A shattered dream

fy.blackhats.net.au

721–730 of 789 posts

Re: Passkeys: A shattered dream

#721

Earlier quoted context omitted.

It's a Google sign-in workflow problem. I've seen the same issue more than once - for whatever reason it decides that this one way of signing in is the one that you want to use right now, and it can be impossible to back out until some timeout kicks in.

If even Google can't get it right...

I'm not entirely sure Google is trying to "make it right" so much so as funnel users to its own products (i.e. Android devices and Google Authenticator).

Re: Passkeys: A shattered dream

#722
post #692
post #112

As someone who happily uses Yubikeys, I really don't want to use a Passkey. I want to still use a username/password and the Yubikey. Not just username and Yubikey. Google tries to force use of passkey now that if you enroll a Yubikey it will now be a Passkey, instead of a second factor. With no option to disable it. I have to run the Yubikey Manager tool and then disable "FIDO2", so that I can force it only be used a…

If you use Google Workspace you can set 2FA directly from the admin console, so you don't need to disable FIDO2 on the key. Does not help with gmail, though.

Not in my experience. In the Admin console I said do not use Passkey and it still created it as a Passkey :( This was about a month ago, so maybe they fixed it. Turning off FIDO2 made things work.

Re: Passkeys: A shattered dream

#723
post #722
post #692

Earlier quoted context omitted.

If you use Google Workspace you can set 2FA directly from the admin console, so you don't need to disable FIDO2 on the key. Does not help with gmail, though.

Not in my experience. In the Admin console I said do not use Passkey and it still created it as a Passkey :( This was about a month ago, so maybe they fixed it. Turning off FIDO2 made things work.

If you add a FIDO2 key as a security key in the admin console, it will show as a "passkey" in Google account settings, but it will actually be a non-resident key used only for 2FA and won't be able to be used for anything more than that.

Keys that do not support resident keys (or when you turn FIDO2 off) show differently in Google account settings which makes it all very confusing. The UX is inexcusable, really.

As a side note, turning on Advanced Protection also turns off passkeys.

Re: Passkeys: A shattered dream

#724

The biggest issue with passkeys is that I just can't trust the companies offering them. They are locked into the platform for reasons that are ostensibly security but often indistinguishable from platform lock-in. If you make a passkey on an Apple device as far as I can tell it will never leave that device, ever, and there is no way to change this. Of course this means you can never be phished for your credentials bu…

Webauthn, FIDO, etc. is run by a consortium of corporations whose goal is to be your sole identity provider and own your digital life. Nobody should have been hyped about this crap from day one.

Re: Passkeys: A shattered dream

#725

Earlier quoted context omitted.

I’m really not sure the “only real solution” is every human needs to selfhost a password manager. That’s ill-advised; an extreme take. The vast majority of the population will do a worse job on the availability and security of a selfhost solution than 1Password, whose core business and value proposition is password management. I’m a very happy user of 1Password for Families and consider it the likely the best ~$50 a…

Agreed. I self hosted the key 100 bitcoin in like 2010. Machine crashed. Oops.

Do you have machines with no backups? Why?

Re: Passkeys: A shattered dream

#726
post #572

Earlier quoted context omitted.

I’m sorry, but you’re either naive or lying. This is precisely like the imaging standards trying to replace JPG. After two decades of vendors like Google trying to establish a new standard, I can’t send anything other than an SDR sRGB JPEG to anyone, especially to an Android user. The current post-JPG formats may as well be called “the Apple format”, “Google image”, and “Netflix pics”. There is no practical interoper…

I said "more interop" is coming.. There is a significant amount of interop that already exists, that folks are looking past or just already taken for granted (which is actually fine too!). While on a Windows machine using Edge, you can save a passkey for your Google account to your 1Password vault, and use it to sign in to that Google account on Chrome on Mac (if you have signed in to the same 1Password account on th…

I'll believe you when every home in America has a fusion reactor.

Re: Passkeys: A shattered dream

#727
post #206
post #75

Passkeys can't actually replace passwords, right? I will always need a username and password with a website, then can generate a passkey as a separate auth mechanism, which if I lose, I will recover by setting up again using my username and password? I don't get how we can get to a place where passkeys are all, how do you get a passkey on a new device when you only have passkey auth on some other device enabled?

They can, and hopefully will. To get a new passkey on another device, the provider needs to allow you to prove you have possession of your other device first. They can do that by sending you a one-time code, for example, when you authenticate using your existing device, which you can then type in the new device, and that lets you associate your new device-generated key with your existing account. With iCloud, you don…

A long recovery code that both you and the provider need to know in order to authenticate you IS a goddamn password no matter how infrequently you expect to use it. It just changes what knowledge a hacker looks for either in your digital storage or in a company's databases.

If you get rid of all knowledge-based authentication in order to increase account security, then you necessarily increase the chances of permanent lockout. You can't square a circle.

As for phishing, maybe google should put its AI capabilities to good use, and if the text of an email matches enough patterns of examples it's seen before, there should be a banner at the top of the email warning "this looks like a phishing attempt: common tactics include X, Y, and Z. Confirm authenticity before reacting to this email."

Re: Passkeys: A shattered dream

#728

I may be mistaken in its implications, but given the 9th Circuit's decision in U.S. v. Payne this week [1], I don't know if moving all our password knowledge to biometrics is a secure idea. [1] - https://arstechnica.com/tech-policy/2024/04/cops-can-force-s...

I suspect that's part of the eagerness to move everyone to passkeys.

Re: Passkeys: A shattered dream

#729
post #336

Why did it took so long to figure out that passkeys was a bad idea?

Because if something is new, then it's automatically better, even if it's not, so it gets a hype cycle.

Honestly I'm just relieved this appears to be crashing and burning on the runway. Crypto bullshit's gone through several destructive hype cycles by now and the main consequence of the latest round of the AI craze will be a nuclear wasteland of an internet.

Re: Passkeys: A shattered dream

#730

Earlier quoted context omitted.

Why don’t you setup the Gmail account to forward? I know it’s a hassle, but will resolve the issue

That seems like an invitation for long-term pain if Google changes their policies, requiring someone to log in every X months or have their gmail account locked, for example, or some AI enforcement tool locks the account for inscrutable reasons.

I've got some active GMail forwarding addresses that I haven't logged into for 10+ years. I don't think they could change how that worked now even if they wanted to.
Post reply on HN