Earlier quoted context omitted.
> Passkey are more like password managers, and less like MFA tokens No: - I can always export and import all my passwords from/into my password manager - My passwords always work independently of a password manager or any specific app/OS/hardware That is not true for passkeys and makes them much more like tokens. Of course they don't have to be used in MFA, just like passwords.
I just exported my Bitwarden vault and the resulting .json file has my passkeys in it. I'm not going to try to test import, but if it doesn't work that would obviously be more "bug" than anything else. Clearly "export" is the high concern functionality and once exported, importing them is not a big deal. This is only about your first paragraph, it doesn't affect your second.
Emailing a one-time code is worse than passwords
471–480 of 816 posts
Re: Emailing a one-time code is worse than passwords
#472Re: Emailing a one-time code is worse than passwords
#473Earlier quoted context omitted.
> More like abuelita gets robbed at gunpoint and made to unlock and clear out her bank account, then has no recourse at home because her device was taken. You are describing the current status quo, without passkeys. This is already possible. Well, except maybe for the "without recourse" part, because there are some legal and policy avenues available for dealing with this situation.
The without recourse is the part that matters... With passkeys or 2FA she's at risk of having to wait a day or more to go to the physical location (if there even is one, digital banks are huge in Latin America), with passwords she can just check her notebook the same night and start the recourse through official channels. I know she could just call the hotline, but if 24hr customer service guy can get you in your acc…
Yes, and I'm saying that part isn't accurate either for the story you're portraying with passkeys or for the status quo. That's not how account recovery flows work.
Re: Emailing a one-time code is worse than passwords
#474Earlier quoted context omitted.
They are referring to the ability of a site you are logging into forcing you to use a client from a specific list or having a list of clients to deny. It's copied over from FIDO hardware keys where each device type needed to be identifiable so higher tier ones could be required or unsecured development versions could be blocked.
It's like DRM: it will annoy legitimate users and keep them from obviously legit usecases, and be circumvented by people who are motivated.
What a crock, to not bother coming up with a way to make passkeys portable and then threaten to ban providers who actually thought about how humans might use them in the real world
Re: Emailing a one-time code is worse than passwords
#475Earlier quoted context omitted.
> Passkey are more like password managers, and less like MFA tokens No: - I can always export and import all my passwords from/into my password manager - My passwords always work independently of a password manager or any specific app/OS/hardware That is not true for passkeys and makes them much more like tokens. Of course they don't have to be used in MFA, just like passwords.
I just exported my Bitwarden vault and the resulting .json file has my passkeys in it. I'm not going to try to test import, but if it doesn't work that would obviously be more "bug" than anything else. Clearly "export" is the high concern functionality and once exported, importing them is not a big deal. This is only about your first paragraph, it doesn't affect your second.
Re: Emailing a one-time code is worse than passwords
#476Four times a day, I get an email notification that someone requested a password reset for my Microsoft account, which gives me a six-digit number to recover my account. So every day, an attacker has four shots in 1,000,000 of stealing my account by just guessing the number. They've been doing this for years. If the attacker's doing this to thousands of accounts - which I'm sure they are - they're going to be stealing…
Adding 2FA was the solution
I couldn't find the method they were using in the first place, because for me it always asks for the password and then just logs me in (where were they finding this 6-digit email login option?!), but this apparently blocked that mechanism completely because I haven't seen another sign-in attempt from that moment onwards. The 2FA code is simply stored in the password manager, same as my password. I just wanted them to stop guessing that stupid 6-DIGIT (not even letters!) "password" that Microsoft assigns to the account automatically...
Re: Emailing a one-time code is worse than passwords
#477Earlier quoted context omitted.
Wouldn't that be incredibly insecure? Attacker would just need to initiate a login, and if the user happens to click the link they've just given the attacker access to their account.. The reason why magic links don't usually work across devices/browsers is to be sure that _whoever clicks the link_ is given access, and not necessarily whoever initiated the login process (who could be a bad actor)
> Wouldn't that be incredibly insecure? If done naively with a simple magic link, yes. > and if the user happens to click the link they've just given the attacker access to their account Worse: if the user's UA “clicks the link” by making the GET request to generate a preview. The user might not even have opened the message for this to happen. > Wouldn't that be incredibly insecure? It can be mitigated somewhat by ma…
You mean something like a popover preview that appears when the user hovers over a link?
Isn’t there a way to configure the `a` element so the UA knows that it shouldn’t do that?
Re: Emailing a one-time code is worse than passwords
#478The attack pattern is: 1) User goes to BAD website and signs up. 2) BAD website says “We’ve sent you an email, please enter the 6-digit code! The email will come from GOOD, as they are our sign-in partner.” 3) BAD’s bots start a “Sign in with email one-time code” flow on the GOOD website using the user’s email. 4) GOOD sends a one-time login code email to the user’s email address. 5) The user is very likely to trust…
> Passkeys is the way to go. Password manager support for passkeys is getting really good. I set up a passkey for github at some point, and apparently saved it in Chrome. When I try to "use passkey for auth" with github, I get a popup from Chrome asking me to enter my google password manager's pin. I don't know what that pin is. I have no way of resetting that pin - there's nothing about the pin in my google profile,…
it's not quite new, as a dump example depending where in android contacts you click on a address it might always force open google maps (2/3 cases) or (1/3 cases) propelry goes through the intend system and gives users a choice
stuff like that has been constantly getting worse with google products, but it's not like Microsoft or apple are foreign to it
Re: Emailing a one-time code is worse than passwords
#479Earlier quoted context omitted.
No need to write like that. I know, understand and use passkeys for quite a while now. I don't love them. I don't love passwords either. But while I don't fear passwords, I fear passkeys. The reason is that it makes the tech even more intransparent. My password manager stops working, completely dies or I can't use it anymore for other reason? No problem, I can fallback to a paper list of passwords if I really have to…
I have yet to see passkeys used as a sole method of logging in. There's always a traditional username and password setup first. There's always a recovery code set up for the passkey. I have yet to see passkeys offered as the only means of MFA. Which means that your backup methods still work. You can use them for recovering your access. I see passkeys as an optional convenience. It works well for me by that measure.
Re: Emailing a one-time code is worse than passwords
#480Earlier quoted context omitted.
Your style of thinking is exactly why linux never became a leader in desktop os's. Why we're still dealing with the most ridiculous tech debt and complexity in OSS tooling to date. You're obsessed with fake problems that have no bearing on real people. When grandma does indeed loose all her money because some prick phished her password away, I would love to watch you explain how that's actually better than BigTech ta…
You're the one dismissing real problems like "lose all passkeys when you lose your phone".
> The problems of Passkeys are more nuanced than just losing access when a device is lost (which actually doesn't need to happen depending on your setup).