Earlier quoted context omitted.
You don’t. You don’t store anything at all. On registration, a keypair is generated, then the private key is encrypted with the long-term key burned into your security key fob or hardware. The encrypted blob is sent to the server and stored there. On authentication, after you enter your login, the server sends the encrypted blob and your security key tries to decrypt it with the long-term key it has. If it succeeds,…
> You don’t. You don’t store anything at all. Yes, you do. Whenever a website offers to create a passkey, it could end up in any of these: - Samsung's Password Manager (if using a Samsung phone) - Apple's Keychain (if using an iPhone) - Google Password Manager - Your operating system's keychain - A bespoke password manager (e.g., Bitwarden or LastPass) - Your hardware key Most users do not have a security key fob. In…
Passkeys were invented by engineers with zero understanding of consumer brain
771–780 of 813 posts
Re: Passkeys were invented by engineers with zero understanding of consumer brain
#772Earlier quoted context omitted.
> You don’t. You don’t store anything at all. Yes, you do. Whenever a website offers to create a passkey, it could end up in any of these: - Samsung's Password Manager (if using a Samsung phone) - Apple's Keychain (if using an iPhone) - Google Password Manager - Your operating system's keychain - A bespoke password manager (e.g., Bitwarden or LastPass) - Your hardware key Most users do not have a security key fob. In…
I have to think people aren't doing any research. Both Android and Apple sync your passkeys to your account. You can toss all your devices in a wood chipper, buy a replacement and still have access to all your passkeys.
Remember that your average user has no idea what a passkey is, doesn't remember half of their passwords and has no idea what a password manager is.
Re: Passkeys were invented by engineers with zero understanding of consumer brain
#773Earlier quoted context omitted.
> You don’t. You don’t store anything at all. Yes, you do. Whenever a website offers to create a passkey, it could end up in any of these: - Samsung's Password Manager (if using a Samsung phone) - Apple's Keychain (if using an iPhone) - Google Password Manager - Your operating system's keychain - A bespoke password manager (e.g., Bitwarden or LastPass) - Your hardware key Most users do not have a security key fob. In…
I was talking about the non-resident FIDO keys. “Passkey” term is meaningless unfortunately because FIDO Alliance did not define it initially, it was a marketing term invented by Apple and then re-introduced (or shoved down the throat) by the FIDO alliance. In non-resident keys scenario you don’t store anything and from what I see there is no security downside of using non-resident keys. Loosing both (or multiple) se…
Indeed, the only advantage to Resident Keys (i.e., Passkeys) is the discoverabillity of them, so you can login without even using a username. It's a shame all of the terminology around WebAuthn/FIDO2 and Passkeys is so loose and badly defined.
Honestly, I think OAuth logins are still an ok option for the average user, unfortunately, as I would never recommend someone I love to use Passkeys and put them through the burden of having to understand and deal with all of this mess.
Re: Passkeys were invented by engineers with zero understanding of consumer brain
#774Earlier quoted context omitted.
Not at the moment. But if you sign into google account in iPhone then you can use Google's passkeys in iPhone. At the end, passkeys are built not for the tin-foil, (I hate Google Apple fellows), I want to keep every single locally, RMS fans. No. A majority will benefit. End of matter. A majority don't change platforms (I have not seen them do it). And lets be honest - even if they were portable are you privacy person…
No, the majority will not. If through some miracles, passkeys gain sudden and wide adoption, there will be a day of reckoning come around the next mobile refreshment cycle, maybe earlier. People break their phones . That is normal experience. Entirely unsupported by passkeys as they are today. I'm actually surprised we didn't have more pushback for ubiquitous 2FA, as they have similar threat profile - i.e. addressing…
People break their phones less often compared to telling them keep their keepassdatabase in sync across devices.
Even recently my friend fixed his iPhone XR (10 year old) 3rd party. Everything including passkeys work fine.
Re: Passkeys were invented by engineers with zero understanding of consumer brain
#775Earlier quoted context omitted.
Why does a passkey need bluetooth? For what? Isn't that another vulnerability?
A "passkey" is a bunch of metadata and a public/private keypair. It doesn't do anything by itself, of course. A physical device, like a Yubikey or a Titan, doesn't have Bluetooth. For phones and tablets these keys do support NFC but that's a whole different story. The Bluetooth connection is how your phone exchanges the key and authenticates you through the computer. In its most secure phone, the key never leaves the…
Re: Passkeys were invented by engineers with zero understanding of consumer brain
#776Earlier quoted context omitted.
Think of it like SSH authorized keys but automated for the web. Instead of storing the keys in a file; it stores them in a hardware security module (yubikey, or TPM). Registration generates an asymmetric key pair between your passkey, and the website. Login is the usual challenge/response process. The biggest step forward is phishing resistance. A fake login page can relay a TOTP code, but not the passkey challenge/r…
Yes, those are the easy parts - but none if that answers GP's questions: > If my passkey is on my phone what happens if I lose my phone? Do I need a unique passkey per device? How do I rotate them? What if a device gets stolen? I'd also add: How do I login on a device or browser that I've never logged in before? If I'm on a public computer that I trust enough for quickly logging into my emails but (say, the local lib…
For example, passkey on iPhone and on the same account register a second key such as a yubikey.
That’s how my github is configd, for example: my phone and MacBook can auth w OS passkeys. If I need to login on another host, like my windows host or in your example at the library, the yubikey is another registered hardware authenticator.
Worth adopting/looking into imo
Re: Passkeys were invented by engineers with zero understanding of consumer brain
#777Earlier quoted context omitted.
I have to think people aren't doing any research. Both Android and Apple sync your passkeys to your account. You can toss all your devices in a wood chipper, buy a replacement and still have access to all your passkeys.
Yeah, they do. But what if you want to move from Android to iPhone or vice versa? That's the big problem regarding these keychains/password managers. Some of them didn't even allow you to export your Passkeys until a few months ago, meaning you were literally locked into their platform. Remember that your average user has no idea what a passkey is, doesn't remember half of their passwords and has no idea what a passw…
Re: Passkeys were invented by engineers with zero understanding of consumer brain
#778Earlier quoted context omitted.
If you store the key in Bitwarden or Keepass, what makes it different from a password?
The difference is you can't just copy and paste the private key into a phishing website. The login process validates your private key and logs you in. Also since the service does not store your private key, it is more resistant to data-breaches as that is one less potential breach source.
Re: Passkeys were invented by engineers with zero understanding of consumer brain
#779Earlier quoted context omitted.
If you store the key in Bitwarden or Keepass, what makes it different from a password?
They are bigger. Not as easy to guess. More like pretty impossible. It's like not letting the user choose the password. That way they can't have a bad password.
Heck, the company could easily say that your password needs to be 128 characters long and use multiple types of characters - and tell you to use a password manager (that both generates and fills in that information for yet).
Re: Passkeys were invented by engineers with zero understanding of consumer brain
#780Earlier quoted context omitted.
I literally presented you with the solution in the sentence before. Buy a usb c dongle key. You pay 20 euros to NEVER have to remember a single password ever again. Seems like an ok trade off to me. Likewise you can register multiple passkeys for multiple devices, so long as you do it in sequence (first Apple, then Android) etc. Really it takes very little getting used to. Ever tried to fill out a crap password form…
How does that USB-C dongle work on my corporate computer that has USB blocked? How does it work with my iPhone or my iPad or my Kindle?