At Caution we -exclusively- allow passkeys. The entire database is user ids and public keys. If it leaks, it would only be mildly annoying. If you are confused about digital passkeys, you can use a physical yubikey or nitrokey and tap it when it blinks. You can treat them like a credit card or house keys. Asking people to keep up with and remember passwords is and always has been the thing that was invented with zero…
> -exclusively- allow passkeys Isn't that just a euphemism for "we mandate passkeys"? Saying 'exclusively allow' draws the reader's attention to the positive (allowing!) while de-emphasizing what's not permitted. Regardless, I think it's a lot less of an issue for services exclusively oriented at people in tech instead of just everyone. Even then, there is a barrier to adoption besides just understanding it, which is…
Passkeys were invented by engineers with zero understanding of consumer brain
781–790 of 813 posts
Re: Passkeys were invented by engineers with zero understanding of consumer brain
#782So Amazon did not understand FIDO, but J random webmaster is supposed to understand passkeys?
Re: Passkeys were invented by engineers with zero understanding of consumer brain
#783Earlier quoted context omitted.
I think it is important to explain why I and others are so reluctant to this. In security, you identify reasonable threats. You can't protect against all of them, and some may even be contradictory. When I get a call on my phone that says "Potential Spam", I have never even once in my life decided to run over to my list of passwords and hand them over to the President of the Spanish National Lottery. Not even once. B…
You aren't considering all the advantages of passkeys. Passkeys only work on the domain they were created for. Password managers usually default to providing the password of the current website, but nothing stops you from pasting that in at any site. There is no danger to the credential db being stolen. The website only has your public key. A website using passkeys can support cross device authentication which allows…
Considering how my bank has changed the sign-in domain three times (as well as some other sites), I consider this a feature, not a shortcoming.
Re: Passkeys were invented by engineers with zero understanding of consumer brain
#784Earlier quoted context omitted.
I print a nice HTML document - each entry has each field/value in a HTML table and each group gets its own header. On macOS I use Strongbox's Print Database capability. On Windows, I'm testing a KeePass plugin I created that does the same thing and more (not quite ready for public release). If I'm still around and coherent, I can re-type it into a KDBX-supporting app by hand (or maybe if I'm lucky only enough entries…
>EDIT: My current printout is 46 pages long. Wow. Roughly how many entries do you have and how do you handle updates? I'm often being asked to change passwords and of course create new login entries.
I don't reprint for every password change. I will for major accounts. I will also immediately print for certain new accounts but not all (e.g. I didn't reprint for my HN account).
The Strongbox printout has the last printed date on it and my KeePass plugin even includes the SHA256 of the KDBX file just to be sure.
Re: Passkeys were invented by engineers with zero understanding of consumer brain
#785Earlier quoted context omitted.
> Amazon won't deliver one to me for at least six days at the earliest, based on their rural delivery estimate. That sounds like an Amazon problem. For 40 USD, yubico.com says that it will deliver a shipment on the next business day to this rather rural house I see in the middle of Foothills Road in Newman Lake, Washington. Also: > Replacing a key is basically impossible. If you know that getting next-day delivery is…
> Newman Lake, Washington You're 21 miles from Spokane. I'm over 120+ north from Syracuse, NY. That's not rural, not one iota. Our Walmart isn't even a Supercenter. > "If you can reasonably afford it" I mean, at nearly $40 for shipping and something like $40-50 a key, I'm not sure I can reasonably afford to buy more than one on the average blue collar American IT worker's wage of sub-$30 an hour. If you'd like, I can…
As you noted in your original post, next-day shipping is a shipping method so expensive that Amazon only offers it in select locations. An honest reader notes that three-to-seven day shipping is 4 USD, and the one-to-four day rate is 8 USD.
> You're 21 miles from Spokane.
No, I'm zero miles from San Francisco. But all sorts of places offer effectively-next-day shipping to SF, so I had to find somewhere by dragging around on Google Maps.
> I'm over 120+ north from Syracuse, NY.
Okay, is
Beaver River Air Field, Eagle Bay, NY 13331
sufficiently rural for you? That's ~200 miles from Syracuse as the crow drives and about 90 as the crow flies. If not, how about 9340 Long Pond Rd, Croghan, NY 13327
or Forest Lodge Sports Club, Honnedaga Lake Rd, Cold Brook, NY 13324
?All of these are still the same price to next-day, one-to-four-day, or three-to-seven-day ship.
Re: Passkeys were invented by engineers with zero understanding of consumer brain
#786The first time I got asked by a site if I wanted to use a passkey I immediately googled what they were and... never really found the answer, not in the 5mins I devoted to being distracting from my task at hand anyway. "magic fairy dust to login to apps." is the most accurate description I've seen. Unlike a password or a TOTP token, I know how those work, I know its my responsibility to keep track of them. If my passk…
Think of it like SSH authorized keys but automated for the web. Instead of storing the keys in a file; it stores them in a hardware security module (yubikey, or TPM). Registration generates an asymmetric key pair between your passkey, and the website. Login is the usual challenge/response process. The biggest step forward is phishing resistance. A fake login page can relay a TOTP code, but not the passkey challenge/r…
Re: Passkeys were invented by engineers with zero understanding of consumer brain
#787Earlier quoted context omitted.
I was talking about the non-resident FIDO keys. “Passkey” term is meaningless unfortunately because FIDO Alliance did not define it initially, it was a marketing term invented by Apple and then re-introduced (or shoved down the throat) by the FIDO alliance. In non-resident keys scenario you don’t store anything and from what I see there is no security downside of using non-resident keys. Loosing both (or multiple) se…
I agree! Indeed, the only advantage to Resident Keys (i.e., Passkeys) is the discoverabillity of them, so you can login without even using a username. It's a shame all of the terminology around WebAuthn/FIDO2 and Passkeys is so loose and badly defined. Honestly, I think OAuth logins are still an ok option for the average user, unfortunately, as I would never recommend someone I love to use Passkeys and put them throu…
Then, Chrome got an update and started hijacking the enrolment process from the operating system and created keys synced to Google Account. This resulted worse UX because authentication now required pulling the Android phone (for those unlucky ones who have it) and confirming the login there instead of doing it right on the computer, uninterrupted.
Then, Apple followed with cloud-only key pairs and then so did the password managers (including Bitwarden Enterprise we were using) and everything become a mess.
The only solution would be to use the key attestation and to only allow specific security keys. Both Chrome and Apple have config knobs to simplify enterprise attestation (a strong assurance, which FIDO authenticator has been used), but neither Windows nor macOS support key attestation for hardware-backed keys (and macOS ignores “platform” claim altogether).
It sucks.
Re: Passkeys were invented by engineers with zero understanding of consumer brain
#788Earlier quoted context omitted.
> Still, I can see a lot of scenarios where this might not work - e.g., the first one I thought of was a public computer at a library where Bluetooth might be locked down; corporate computers or remote servers could also be troublesome. None of my desktop computers support Bluetooth. Neither do my wife’s.
Yes, I mean, that’s also a possibility - or someone didn’t know they needed to screw on the antenna, or it’s otherwise borked. Every PC motherboard (sample size of four, three for me and one for a nephew) I’ve bought in the last five years has had on-board WiFi and Bluetooth though, so I’m curious to know, was that a deliberate choice? (In thinking about it, it’s possible that the motherboards I bought did have non-w…
Re: Passkeys were invented by engineers with zero understanding of consumer brain
#789Earlier quoted context omitted.
That limit is only for a certain Yubikey model, not for all hardware-based fido2 authenticators. > upload their keychains to ms/apple/etc clouds where they can be requested by any gov under the sun for x reasons. If a HSM module (TPM, Apple/Android Secure Enclave) is used the private key is impossible to extract (and upload to a cloud) anyways
> That limit is only for a certain Yubikey model, not for all hardware-based fido2 authenticators. Do you know who offers more? I deliberately chose Yubikey as example as their limit was the highest. Others like Nitrokey etc. support even less.
Re: Passkeys were invented by engineers with zero understanding of consumer brain
#790Passwords+TOTP have that universality going for them that you can always move away to a different password manager/do without one if you ever want. With vaultwarden and that dependency/liability cut off, passkeys have phenomenal UX, especially coupled to a SSO/identity provider like pocketId.