Live data from Hacker News

Passkeys were invented by engineers with zero understanding of consumer brain

twitter.com

591–600 of 813 posts

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#591
post #92

Earlier quoted context omitted.

Only to other proprietary systems within the FIDO Alliance that you don't own or control. Additionally passkeys allow services to detect and ban specific password managers, so have fun when the only approved managers that works consistently across all services are Google/Apple/Microsoft. There is already a list of "bad" clients here https://passkeys.dev/docs/reference/known-issues/

Again, what are you taking about? There are open source implementations available. I can write my own. They do work. This list just shows some which do not actually implement the spec correctly. Also moving the goalpost. The post I replied to said I couldn’t export it. I absolutely can, and have, with a single click. To another provider. It’s really not a big deal.

> This list just shows some which do not actually implement the spec correctly.

KeepassXC was threatened to be blocked.[1]

[1] https://github.com/keepassxreboot/keepassxc/issues/10407#iss...

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#592
post #555

Earlier quoted context omitted.

On most websites logging in through QR codes works out of the box for passkeys. You usually click "log in with device" or something like that with every desktop OS. You scan the QR code, click the confirmation button, and you're signed in. It's part of the standard UI of normal operating systems. Might not work (well) if you're on an old computer without decent Bluetooth but everything has Bluetooth these days.

I don’t think this ever works with passkeys stored in pw managers though, only Face ID/whatever Android is doing?

It does using 1password.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#593
post #104

Earlier quoted context omitted.

I recognize the point of your post is more about the lack of clarity and details around passkeys. That's real, and I don't really have an answer for that - other than, I think maybe the quest for making them simple and "just work" has maybe made them nebulous enough that we've wound up in the current situation where a lot of even technically savvy people don't really understand them. But I feel like answering your qu…

> Still, I can see a lot of scenarios where this might not work - e.g., the first one I thought of was a public computer at a library where Bluetooth might be locked down; corporate computers or remote servers could also be troublesome. None of my desktop computers support Bluetooth. Neither do my wife’s.

Yes, I mean, that’s also a possibility - or someone didn’t know they needed to screw on the antenna, or it’s otherwise borked. Every PC motherboard (sample size of four, three for me and one for a nephew) I’ve bought in the last five years has had on-board WiFi and Bluetooth though, so I’m curious to know, was that a deliberate choice?

(In thinking about it, it’s possible that the motherboards I bought did have non-wireless alternatives that weren’t stocked at my local Micro Center - lot of digging required to figure that out, though :) )

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#594
post #356

Earlier quoted context omitted.

I have come across many websites that limit how many passkeys I can add. Some have only allowed one or two.

Yeah, it's bad implementation on the websites but the protocol doesn't have a limit.

1 of gortok's points was I don’t know whether each website/app that has set up Passkeys has decided the answers to those questions in the same way as the others.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#596

Earlier quoted context omitted.

I do love the cloud version of passkeys, but I also have a backup YubiKey. I could do two backup YubiKeys, drop the cloud, and keep one YubiKey in a safe deposit box and one elsewhere, but I haven't had much reason to yet. A passkey doesn't give up anything compared to a password, and is in fact much much easier to handle, IMHO. I have kept all of my private SSH keys in secure hardware for a decade, so perhaps I'm mo…

> I do love the cloud version of passkeys, but I also have a backup YubiKey How does this work, exactly? Does you cloud password/key manager allow syncing to the YubiKey? Or do you register a second passkey that you store on the YubiKey whenever you create a passkey? If it is the latter, do all services that allow passkey authentication also allow registering multiple passkeys? How many? > could do two backup YubiKey…

I create multiple passkeys for the account: an iCloud passkey and a Yubikey passkey.

Both passkeys are independent of each other and know nothing about each other, only the website knows that both are mapped to the same account.

It's like setting up multiple API keys for a service. Passwords are usually restricted to just one, but passkeys are (generally) allowed to have multiple backups.

When I go to login to Google, for example, it will prompt for a passkey. Currently, in Safari, it will prompt for biometrics on my iCloud passkey. I can either give it my fingerprint/face, or hit the "More options" button, which in the current list allows either 1) insertion of a USB security key, or 2) presenting a QR code that a phone device can scan, allowing use of the passkeys on the phone.

(All very good questions, BTW!)

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#597

Earlier quoted context omitted.

I resent that I need a special app to "manage" them. I want to know where this key is on my filesystem so I can back it up and edit it myself, not have to use some app to access it. My ssh authorized_keys is just a text file. I can "manage" it with something as simple as vim. Maybe KeePassXC and BitWarden give you that simplicity, if so great!

KeePassXC "supports passkeys" but the website/app that offers the passkey needs to offer it in the correct way for KeePassXC to ingest it. I've found a fair amount of scenarios where they don't correctly let you drop it into them.

Until I can have all my keys as cleartext in a text file, I won't use passkeys.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#598
post #491

Earlier quoted context omitted.

> You generate another passkey is your answer. How do you do that? The exact same way you do today. How can I do that, if Passkeys are the only option to log in? If I can just use a password to log into a website without Passkeys, then Passkey is useless and doesn't add any security benefit. > Why would you need to delete invalid passkeys? You wouldn't. I sell my old (and no longer updated) phone or PC and don't want…

> How can I do that, if Passkeys are the only option to log in? It is not feasible to remove password login or some other recovery login method. > If I can just use a password to log into a website without Passkeys, then Passkey is useless and doesn't add any security benefit. It isn’t useless, point is you don’t get to type in your password on a device that has passkey generated already, or get phished on a fake web…

> It is not feasible to remove password login or some other recovery login method.

Then passkeys doesn't provide any real value if you have other less secure recovery option.

Let's say I have a bank account, going to the branch and doing an in person ID check is a valid recovery option, but nobody would want to do that just to log in from a new device.

> It isn’t useless, point is you don’t get to type in your password on a device that has passkey generated already, or get phished on a fake web address for example.

That's solved by letting the browser to remember the passwords.

> Passkeys are meant to be protected by either PIN or biometrics, however they are also meant to be revocable on the web, at least they are for services i’ve been using with passkeys.

PIN and biometrics doesn't have any inherent security. They rely on some hardware (or software separated from main system) feature, and even those can have vulnerabilities.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#599

Earlier quoted context omitted.

I refuse to be part of an "ecosystem".

KeepassXC is free, open source, and supports passkeys. You can locally store your encrypted password vault wherever you like, and transport it between devices using physical media if you like (or self host your own personal storage synchronization server and sync your passkeys between devices like that). No need to be a part of an 'ecosystem' to use a password manager or passkeys.

> KeepassXC is free, open source, and supports passkeys.

KeepassXC was threatened to be blocked.[1]

[1] https://github.com/keepassxreboot/keepassxc/issues/10407#iss...

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#600

Earlier quoted context omitted.

I do not want my identity to be device-bound. I want it to be me-bound.

That's self sovereign identity. But you still need someones that can issue those verifiable credentials, and we (as a global society) can't decide who that should be in the web of trust? Our banks? Governments? Schools? Doctors at time of birth? Arguably, that's the only way forward. SSI is also nice because you get to fully control what you share and don't share (e.g., age verification, you get to only share "I am o…

Put yourself in the role of a consumer for a second.

As a consumer, I don't give a shit. I use my driver's license to apply to jobs, my passport to fly, and a password (with 2FA depending on how much I / my employer cares) for everything else. I prefer whatever I use for 2FA to not be device-bound, because that's obnoxious, error-prone and constraining.

As a consumer, I don't see any reason for my auth to be more complicated than that.

Post reply on HN