Live data from Hacker News

Passkeys were invented by engineers with zero understanding of consumer brain

twitter.com

701–710 of 813 posts

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#701
post #341

Earlier quoted context omitted.

Just the other day I was creating an ID on a government web site, which offered a list of security questions such as "Title of your favorite movie" or "Someone that you admired as a child" and the answer was not allowed to have any spaces. Just absurd.

Security questions have always been ridiculous, but I'll especially never understand how "favorite [thing]" ever made it to production anywhere. "Favorite movie" can change multiple times in the same conversation.

Still better than the government (!!!) website that a few days ago gave me the option of using "What's the name of the company you first worked at?"

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#702
post #670

Earlier quoted context omitted.

Think of it like SSH authorized keys but automated for the web. Instead of storing the keys in a file; it stores them in a hardware security module (yubikey, or TPM). Registration generates an asymmetric key pair between your passkey, and the website. Login is the usual challenge/response process. The biggest step forward is phishing resistance. A fake login page can relay a TOTP code, but not the passkey challenge/r…

Yes, those are the easy parts - but none if that answers GP's questions: > If my passkey is on my phone what happens if I lose my phone? Do I need a unique passkey per device? How do I rotate them? What if a device gets stolen? I'd also add: How do I login on a device or browser that I've never logged in before? If I'm on a public computer that I trust enough for quickly logging into my emails but (say, the local lib…

Answering respectively: it's lost; no; same way you reset passwords; depends what you mean "what if" - if your passwors manager is already authenticated and doesn't require reauthentication, then yes, it could be used to login.

And to answer your additional question, yes, I suppose you would either need to install your password manager or use whatever alternative 2FA login you have.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#703

Earlier quoted context omitted.

Yeah they're really trying to solve problems that should be solved at a technical level with soft solutions in porcelain. See also this issue asking keepassxc to disable plaintext exports, which is completely technically feasible https://github.com/keepassxreboot/keepassxc/issues/10407

The author of this ticket seems to come across as an arrogant know-it-all that thinks "the threats i thought of (or personally face) are the only threats that are significant, fuck anyone in a different situation." I proudly print my entire KDBX file including passkey private keys and I encourage my elderly parents to do so too. Lightning strikes (and assisting people with cleanup and repair from them) have taught me…

>I proudly print my entire KDBX file including passkey private keys and I encourage my elderly parents to do so too.

Do you mean you print the raw values to paper or some encoding that would let you reconstitute the file (some giant QR code or something?)?

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#704
post #37

FWIW: I find passkeys to be a very simple and easy to use concept. Simple: it's like a password that I don't have to type in Easy to use: because I use 1Password and just have it installed on everything. On Android, it can be set as the default passkey provider so, even on mobile, I am using passkeys shared across devices. Is this "less secure" because I'm sharing the keys through 1Password. I suppose, at some level.…

This is a big problem I have with "just works". Everyone is used to services only allowing a single password. I know the answer to this, but it's not clear in the marketing or how it's explained to normie end-users: Won't creating a passkey erase my password? How do you sign in on another device? Won't that change the passkey and lock me out from the first device?

Creating a passkey generally won't erase your password, no. Using a passkey generally requres a password manager or yubikey, so you can set that up on the other device and use the same passkey.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#705

Earlier quoted context omitted.

This is why I am so concerned about passkeys. They could be a good improvement, but in practice I already see how it's going to result in Google/Apple/Microsoft/whoever seizing even more control. The document there is laughable too, because KeepassXC is listed as "not performing User Verification" when it demands manual authorization per request. But this isn't good enough for the passkey people. Ultimately, I see an…

Yeah they're really trying to solve problems that should be solved at a technical level with soft solutions in porcelain. See also this issue asking keepassxc to disable plaintext exports, which is completely technically feasible https://github.com/keepassxreboot/keepassxc/issues/10407

See this comment as well:

>I've already heard rumblings that KeepassXC is likely to be featured in a few industry presentations that highlight security challenges with passkey providers, the need for functional and security certification, and the lack of identifying passkey provider attestation (which would allow RPs to block you, and something that I have previously rallied against but rethinking as of late because of these situations).

https://github.com/keepassxreboot/keepassxc/issues/10407#iss...

They 100% will lock it down to "secure" options you cannot control. I suppose if there's any hope, it would maybe be the official keepass submitting to their demands, while keeping them easy to bypass with a recompile.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#706

It seems to me like those who like passkeys/consider them simple are those who entrust all their credentials to proprietary cloud software vendors that sync them to all their devices. Those of us who are not comfortable with that and want to keep our credentials offline and sync/backup them ourselves have questions about how the registration/backup/sharing flows work exactly. I see this as part of a trend together wi…

You can use passkeys with any password manager, including selfhosted ones like keepass.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#707

Earlier quoted context omitted.

Again, what are you taking about? There are open source implementations available. I can write my own. They do work. This list just shows some which do not actually implement the spec correctly. Also moving the goalpost. The post I replied to said I couldn’t export it. I absolutely can, and have, with a single click. To another provider. It’s really not a big deal.

> This list just shows some which do not actually implement the spec correctly. KeepassXC was threatened to be blocked.[1] [1] https://github.com/keepassxreboot/keepassxc/issues/10407#iss...

Because they were exporting secrets in plain text. And they didn’t threaten, they said relying partners (so the site itself, for example GitHub) might block them.

This is not some conspiracy, and again has nothing to do with the fact that I can export my key passes

I don’t get the activism here

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#708

I dislike passkeys because they support remote attestation. It's my key -- why does the website care what app I'm using to host it or if I'm allowed to copy it? Or what operating system I'm using, for that matter. Because of this, I will not use passkeys. It's a slippery slope. Once we're all on passkeys, website devs won't resist enabling the remote attestation bit, locking out linux users.

Passkeys aren't tied to any specific app or operating system.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#710
post #108

Earlier quoted context omitted.

>This is much, much simpler than you think it is. Passkeys are just passwords that require a password manager. The issue isn't what passkeys _are_ (e.g. explaining they are like public/private "ssh keys" and hoping that type of explanation ends the confusion). Instead, it's the workflow around passkeys. The websites show very confusing dialog popups and choices that a lot of normal people will not understand. This is…

sadly it seems like most of the banks I use still enforce antiquated password rules, no MFA and rely on stupid questions most of which can easily be guessed from public records.

Yet they still work and people generally don't have their accounts stolen. Why? Because security is more than technology. Stealing a bank account is illegal and you will be prosecuted for it.
Post reply on HN