Live data from Hacker News

Passkeys were invented by engineers with zero understanding of consumer brain

twitter.com

621–630 of 813 posts

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#621

With physical U2F key, I could explain to my 78 year-old-parents "this is a physical key needed to access your account. Think of it like the front door key to your house. Don't lose it or lend it to anyone. We should have a couple of backup keys too." And they got completely understood and added it to all of their accounts. This was not hard. People assumed consumers were too stupid to do this without even giving the…

I still can't even get a physical key anywhere in person. You can certainly get phones just about anywhere, but you can't get any FIDO keys at brick and mortar, last I checked. Until I can tell Grandma to "go down to Walmart and ask the man at the electronics counter for a Yubikey", we still have a few issues. (No. Ordering online is *not* a valid option in this scenario. If I want to order a Yubikey to this address…

I can in fact buy one at a local brick-and-mortar store, but the price is triple/quadruple the amount I'd pay for a copy of my house key. Add in that the whole flow is something grandma is not going to be able to grok, and the whole idea is still-born.

If I were administrating that part of her life too, then maybe, but I'm not really happy with how Yubikey has solved for this problem either. If I could buy them for nearly throwaway amounts of money, and I could make backup copies without issue, then I might even jump on that particular train myself.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#622
post #604

Earlier quoted context omitted.

> A few stories in the news represents a beyond negligible fraction of billions of user accounts. https://support.google.com/accounts/threads?thread_filter=(c... How many times do you have to click "View more" to reach a post from last week? It's a problem. The repeated advice from the "diamond product experts" says it all: If you can't recover your account using Google's automated recovery process, the account is lo…

Those complaints aren't Google arbitrarily or maliciously locking accounts. They are mostly people who forgot their password and also simultaneously lost their sim card and phone number and recovery email and backup codes etc etc. Google provides excellent features to prevent this from happening and I have already taken advantage so that I won't simultaneously lose access to all my recovery options. You also have no…

[deleted]

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#623

Earlier quoted context omitted.

> It seems like everyone wants to be _the_ password manager for all your passkeys. Which defeats part of the point of passkeys in the first place in that they are supposed to be device-bound, the private key held in the TPM or secure enclave or whatever other security chip, mathematically non-exportable. Storing all your private keys in a cloud vault still leaves you exposed to potential credential theft if your vaul…

> Which defeats part of the point of passkeys in the first place in that they are supposed to be device-bound If you watch the original Apple WWDC talk presenting passkeys, you will find that they were always intended to sync, at least for the consumer use-case. What you are describing is how the WebAuthn standard had been implemented by Yubico and Google up until the point of the introduction of “passkeys” by Apple.…

> The reason passkeys have their own name and definition is because they are meant to be a phishing-resistant primary factor that competes with the UX of passwords. And a great usability trait of passwords is that they’re convenient to use across all your devices. With a technology involving public/private keypairs, the only possible way to compete with that UX is to sync the private key across the user’s devices.

Another way would be auto-enrolling passkeys from other devices you own through a standard API. Enroll your trusted Apple device in your Google Account's settings, or your Bitwarden/KeePass, and vice-versa. When your iPhone creates a passkey at a site, iCloud notifies Google, which issues a new passkey and sends the public key to iCloud, which auto-enrolls it at the site alongside the iCloud passkey. BitWarden gets the same treatment. When you open your KeePass vault it checks Google and iCloud and picks up any pending offers for passkey enrollment and completes them.

Simple, secure, opt-in, and users control their devices and passkey vaults with minimal hassle. If a device is lost, the other services can help you automatically delete the compromised passkeys and set up your new replacement device.

Matter does something very similar with cross-compatibility between Apple and Google (and the rest of the ecosystem) when new devices get enrolled with the user's choice of PAA; the only thing missing is roughly cross-PAA enrollment but that would be just one additional trivial trust relationship in both ecosystems.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#624
post #524

Earlier quoted context omitted.

In the Apple ecosystem, passkeys are stored in your iCloud, and access to the passkeys is device bound. So if I generate a passkey on a MacBook, I can then use it from my iPhone as well, because it's encrypted to all my hardware devices.

Replace the word passkey with password in your comment. What’s the benefit of passkeys again? If you’re not storing the actual private key in the Secure Enclave but only the “access to it” what’s changed from how Apple’s keychain already manages password syncing to iCloud? The only benefit (and it’s still a decent one) is that some random website breach can’t disclose your private key.

The far bigger benefit is phishing resistance (with hardware-contained keys themselves being phishing-proof on a non-compromised system).

It moves to the account recovery flows, but that can be much more difficult to phish.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#625
post #238

Earlier quoted context omitted.

There is security value. A passkey will not work anywhere except the actual website. Fake look a like sites can't get the credentials. Evidently they can trick you into authorizing their device.

That's also how any good password manager works. You'd have to manually copy-paste the password to get around the same-site fill restriction (whether it's autofill or manual fill).

Passkeys have an advantage in that the server doesn't have your password and every passkey should be unique.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#626

Earlier quoted context omitted.

There’s a process to scan a QR code with your phone and your phone then authenticates with the passkey.

Discord has an option to login with qr code. And it's very often used maliciously to steal accounts.

The passkey method uses Bluetooth to ensure proximity.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#628

Earlier quoted context omitted.

Again, is this true for all major sites that support passkeys? And how do you set it up? My passwords are automatically synced between my devices, how to I achieve the same thing if I set up an account with a passkey?

Why would you take one passkey and move it between devices? Generate a new one. They're fungible. You set it ask to the exact same way you do today. It's not a problem.

Again, do all major sites allow you to register 6-10 passkeys? Not asking if they could in principle, but do they in practice do it? And how easy is it to log in with a new device to generate that passkey? Do I have to jump through hoops on my laptop, second phone, secondary browser, and so on?

Finally, if it is easy to register a new device, how does the anti-phishing still work? Can't an attacker just convince me to use whatever means I would normally use to register a new device, instead of an existing secure passkey?

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#629

Earlier quoted context omitted.

You're agreeing precisely with the parent commenter that passkeys are, from a user's perspective, just passwords that require the use of a password manager. The difficulties many people have understanding or using passkeys are valid to point out and criticize, but they're precisely the same difficulties people have moving from the paradigm of "memorizing or writing down all my passwords" to "using a password manager.…

> they're precisely the same difficulties people have moving from the paradigm of "memorizing or writing down all my passwords" to "using a password manager." Errr, no. You can transfer a password from one manager to another. Those very same password managers won't let you transfer a passkey they hold. And if you know the password, you can use it anywhere by just typing it in - no complex technology or protocols invo…

That’s a fair point. My thinking was that, once you’re using a password manager, you’ll A) use it to generate random passwords that would be unwieldy to memorize and B) have passwords synced to all your devices such that you will never deal with the plain text password directly.

Of course it is conceivable to want to directly access the plain text password for reasons you mention, although that would be exceedingly rare (at least for me). In those cases I agree that passkeys don’t work, although I might argue that if the average user thinks they need to access the plain text password, there’s a significant chance that they’re being phished!

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#630

It’s quite the opposite. Passkeys are phenomenal for a lot of consumers. Based on this thread, it’s the engineers who understand authentication in the first place and have their own system (eg password manager) that are confused. Consider a user in the Apple ecosystem: you are already conditioned to just do Touch ID or Face ID when asked. I was on Amazon the other day, it prompted randomly for “want to set up a passk…

>"Consider a user in the Apple ecosystem" Already you're off-base. Of course it works when your devices are homogenized, but very little folks work that way. Some people have a Windows computer using Brave, an iPhone using Safari, an Android device using Chrome, and a work computer with its own hardware/software limitations and partitions. Of course it works when your ecosystems are not diversified. Problem is, most…

Even using passwords instead of passkeys is going to be a worse experience when using different platforms like you mentioned - I have a massive number of passwords from recent decades.

A cross-platform password manager like Bitwarden handles passkeys (and passwords) across multiple operating systems, browsers, etc.

Post reply on HN