Live data from Hacker News

Passkeys were invented by engineers with zero understanding of consumer brain

twitter.com

411–420 of 813 posts

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#411
post #8

I do not know how to use a Passkey in a way that won’t impede how I log in to systems. I’ve been in tech for 26 years, and I understand the Public/private key behind what a Passkey is. Here’s what I don’t understand: I access a website through at least four different devices (my iPad, iPhone, Windows Desktop computer, and MacBook Pro) and three different browsers on each device (Brave, Firefox, Safari) , and I use La…

I get your problem, i don't really accept it as valid. Passkeys were always supposed to be fungible. You have one in your iPhone, a different one on your desktop. A third in your significant other's phone. All stored in the hardware tpm equivalent. You can have 7 passkeys. You can have 14. The real failure of passkeys (emphasis on the s!) is that people think they must only have one.

Again, is this true for all major sites that support passkeys? And how do you set it up? My passwords are automatically synced between my devices, how to I achieve the same thing if I set up an account with a passkey?

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#412

I don’t understand this point at all. I think the author has himself confused with the average consumer. For the first time in a decade or so you can buy a PHYSICAL key and use it to sign into websites. I can explain this to any grandma out there. Likewise, I’m an Apple user. Once you’re in Apple universe passkeys are extremely easy. Tap your thumb on the scanner, done. Now we can put on the tinfoil hat and say how t…

> Once you’re in Apple universe And there's your blocker. Being limited to only devices from a single vendor is horrible, and a firm no from a lot of people. > Now we can put on the tinfoil hat and say how this fosters vendor lock The fact that you call it a tinfoil hat type issue is just insane to me. Literally every person in my household has some apple devices and some other ones (android, windows, etc). And some…

> Being limited to only devices from a single vendor is horrible, and a firm no from a lot of people.

Maybe for a lot of tech people, I don't think the general public understands the risks enough to care.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#413

Security people don't care about usability. They genuinely think we are all CIA field agents. Look I remember my PIN everything else is in Firefox password manager.

> Security people don't care about usability.

I spent a long time working in the network security field, and you speak truth. The perverse thing about it is that security people should care a lot about usability. If the scheme isn't usable enough, people will figure out how to bypass it or aspects of it.

The technically weaker security scheme that everybody accepts is more secure than the technically stronger security scheme that everybody tries to bypass.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#414
post #8

I do not know how to use a Passkey in a way that won’t impede how I log in to systems. I’ve been in tech for 26 years, and I understand the Public/private key behind what a Passkey is. Here’s what I don’t understand: I access a website through at least four different devices (my iPad, iPhone, Windows Desktop computer, and MacBook Pro) and three different browsers on each device (Brave, Firefox, Safari) , and I use La…

I get your problem, i don't really accept it as valid. Passkeys were always supposed to be fungible. You have one in your iPhone, a different one on your desktop. A third in your significant other's phone. All stored in the hardware tpm equivalent. You can have 7 passkeys. You can have 14. The real failure of passkeys (emphasis on the s!) is that people think they must only have one.

> [...] people think they must only have one.

That's the real failure? I think the real failure is that people must have _more than one_. I thought so hard to add all my credentials to 1Password. Now people tell me I should use a Yubikey (or better two or three of them). What do you think, I'm going to register a couple of hundred accounts times three for something I already have (my password manager)?

The real advante in passkeys is in allowing me to log in into a service on a foreign device without typing [my password], which is (honestly) something now sane person should ever do.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#415

Earlier quoted context omitted.

Yes, this is exactly the problem. Multiple pieces of software vying to be your passkey provider, often using dark patterns so you don’t realize you’re making a choice, and not using the term “passkey” so people are using the technology without knowing what it is or how to research it. Kind of reflects the state of the web today, where every company wants to be your intermediary in every interaction, from making a pur…

> Multiple pieces of software vying to be your passkey provider, Which entirely defeats the point of using passkeys. There shouldn't be a passkey provider the "provider" is your device's TPM/secure enclave + your biometric challenge. They are supposed to be mathematically non-exportable, device-bound.

"supposed" is doing a lot of heavy-lifting here. According to who? The FIDO2 or Webauthn standards? Or in a perfect world?

FIDO 1.0 started as two different standards: UAF and U2F. U2F was for USB keys used as second factors (so almost always stored in a TPM-like chip and device-bound, but not provided by your platform and there could be multiple of them). UAF were either provided by your platform or by any software and there was no requirement for them to be stored in TPM. Back in the day, very few platform had any FIDO support built-in, so in practice UAF was always done in software (usually based on whatever biometrics/TPM the hardware provided).

So competing options were the default for early FIDO, getting a default platform option is something that came later.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#416

Earlier quoted context omitted.

> Every device is supposed to have its own unique private key, stored in TPM, released only when passing the user challenge (biometrics or pin, or a yubikey). I have just shy of 2000 site credentials in Keepass. Let's assume that they were all Passkeys. 1) When I buy a new device, how do I create 2000 new Passkeys for that device? 2) Can I still do that if I don't have access to the old device? Maybe it was destroyed…

Apple's keychain or google password manager - can hold 2000 passkeys easily.

Did you not read the comment thread you're responding to?

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#417

Earlier quoted context omitted.

> Every device is supposed to have its own unique private key, stored in TPM, released only when passing the user challenge (biometrics or pin, or a yubikey). I have just shy of 2000 site credentials in Keepass. Let's assume that they were all Passkeys. 1) When I buy a new device, how do I create 2000 new Passkeys for that device? 2) Can I still do that if I don't have access to the old device? Maybe it was destroyed…

Apple's keychain or google password manager - can hold 2000 passkeys easily.

Nothing in the post you're replying to is about "is 2000 passkeys storable", it's about "if I have 2000 passkeys and I need to move between an Apple device and an Android device, do I need to establish a second set of 2000 passkeys"?

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#418
post #8

I do not know how to use a Passkey in a way that won’t impede how I log in to systems. I’ve been in tech for 26 years, and I understand the Public/private key behind what a Passkey is. Here’s what I don’t understand: I access a website through at least four different devices (my iPad, iPhone, Windows Desktop computer, and MacBook Pro) and three different browsers on each device (Brave, Firefox, Safari) , and I use La…

I save all my passkeys in Bitwarden and they sync across devices.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#419

Earlier quoted context omitted.

I am an engineer and have some insights on the discussions and developments around it. ITS NOT SIMPLE AT ALL 1. The idea was to provide a phishing resistant authentication method for enterprise users (companies loose quite a lot of money to phishing). 2. Majority of industry players shared the vision of a credential which is available across the platforms and browsers 3. The vision for collaboration never materialize…

I don’t see hardware tokens (like Yubikey) in the list. Those are the only ones that provide a true second factor, to protect against the theft or compromise of your primary device. I’m a little afraid that hardware tokens are getting lost in all the passkey marketing BS. At least they continue to work for now.

> I don’t see hardware tokens (like Yubikey) in the list. Those are the only ones that provide a true second factor

passkeys are not meant to be a second factor; they are meant to replace the password as a primary factor.

>to protect against the theft or compromise of your primary device.

I love Yubikeys, but the only additional protection you get by making the passkey hardware-bound is preventing an attacker who has already compromised your operating system from stealing the credential.

But! Unless you are also doing hardware binding of the session (aka cookie) after sign-in, then doing hardware binding of your credential is mostly security theater, because the attacker can just wait for you to sign in and then steal your session.

And there is standards work happening separately for hardening session security, such as DBSC: https://w3c.github.io/webappsec-dbsc/

I have no idea if Yubico is involved with DBSC, but I would hope that they are, because it would help them make Yubikeys live up to the security guarantees that I personally feel are heavily implied by their marketing.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#420

Earlier quoted context omitted.

> I went to a physical branch to get it fixed and was told that branches don't have that kind of ability so I'd have to call customer support. What are the branches even for if not customer support?

> What are the branches even for if not customer support? Lots of physical locations make the bank seem big/safe/reputable. Beyond that, it's sales and a place to have ATMs. I have sometimes been able to get a replacement card issued at a branch instead of waiting for one to show up in the mail. Some branches will accommodate special requests like "can I withdraw $200... in two dollar bills" / take coin deposits but…

My local branch has had a sign on the front door "our coin counter is broken, sorry for the inconvenience" for the past 6 months. I refuse to believe they don't have a working coin counter in a bank branch; they just don't want customers bringing in a big jars of coins.
Post reply on HN