Live data from Hacker News

Passkeys were invented by engineers with zero understanding of consumer brain

twitter.com

791–800 of 813 posts

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#791
post #767

Earlier quoted context omitted.

Why would a key need to be "hardware-contained" to be difficult to phish? My SSH private key is unphishable and it's right there in a file. It's unphishable because I know there's never ever a reason to send it to someone - in a scenario where that would be needed, I'd generate a new key just for that situation.

Desktop operating systems don't have very good separation between programs. If some malware gets access, it will be looking for e.g. ssh keys and using a keylogger to get the passphrase if you encrypted your ssh keys. Tpm protected passkeys are much better protected

That attack isn't phishing

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#792

Earlier quoted context omitted.

how do I back it up and transfer it to a new device? This is relevant because an attacker can also do that.

Buy a new iPhone. Sign into it. Everything is now available. That is the reason: for the average Joe not having exportable passkeys is good. Average Joe doesn't have to do backup. It is all automatic.

So I just have to get the victim to sign into my iPhone?

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#793
post #771

Earlier quoted context omitted.

> You don’t. You don’t store anything at all. Yes, you do. Whenever a website offers to create a passkey, it could end up in any of these: - Samsung's Password Manager (if using a Samsung phone) - Apple's Keychain (if using an iPhone) - Google Password Manager - Your operating system's keychain - A bespoke password manager (e.g., Bitwarden or LastPass) - Your hardware key Most users do not have a security key fob. In…

I have to think people aren't doing any research. Both Android and Apple sync your passkeys to your account. You can toss all your devices in a wood chipper, buy a replacement and still have access to all your passkeys.

So the use of Passkeys is contingent on allowing a major tech firm to spy on you?

I actually do have a Google account, but do not link my (Android) phone to it. I don't have WhatsApp or any other spyware on the device. I do use Telegram, Ankidroid, and a few other apps that I trust. I'm not a fanatic, but I won't enable and abet anybody to follow me around and report all that I do. How my position is considered an extreme position today eludes me, and frightens me as well.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#794

Earlier quoted context omitted.

> Newman Lake, Washington You're 21 miles from Spokane. I'm over 120+ north from Syracuse, NY. That's not rural, not one iota. Our Walmart isn't even a Supercenter. > "If you can reasonably afford it" I mean, at nearly $40 for shipping and something like $40-50 a key, I'm not sure I can reasonably afford to buy more than one on the average blue collar American IT worker's wage of sub-$30 an hour. If you'd like, I can…

> I mean, at nearly $40 for shipping and something like... As you noted in your original post, next-day shipping is a shipping method so expensive that Amazon only offers it in select locations. An honest reader notes that three-to-seven day shipping is 4 USD, and the one-to-four day rate is 8 USD. > You're 21 miles from Spokane. No, I'm zero miles from San Francisco. But all sorts of places offer effectively-next-da…

I'm glad you've wasted that much time trying to argue the shipping factor and I'm glad you get to brag even more that you can afford to live in San Francisco.

I'll take some of your money now, please. I'm scraping together what I can in what some people called "America's Siberia" and am forced to take care of elderly family and have zero escape plan except for working a horribly underpaid IT job here :)

https://cash.app/$meow

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#795

Earlier quoted context omitted.

> Of course it is conceivable to want to directly access the plain text password for reasons you mention, although that would be exceedingly rare (at least for me). It's a daily occurrence for me, because especially because of going through steps A) and B), step C) which is copy-paste is needed to actually transfer the unwieldy, unmemorizable password from the password manager that stores it, into the app that requir…

But that sounds like precisely what standardized passkey integration in the browser and website solves! This is honestly how I think about passkeys: they're a standard API for browsers and websites to integrate with password managers without needing a browser extension to manually look for and fill out text inputs on the page.

> This is honestly how I think about passkeys: they're a standard API for browsers and websites to integrate with password managers without needing a browser extension to manually look for and fill out text inputs on the page.

But it isn't always that simple. I have a work laptop. It has a MDM installed, so I can't trust it. I don't run my personal password manager on it, ever. But occasionally I go to a web site I don't care too much about, whose credentials are stored in my password manager. It's not an issue; I just type that password in. That doesn't work with passkeys.

Then there is backup. If I lost my password store I'd be toast. Which means if the company that manages my passwords took a dislike to me and banned my account, I'm in a world of pain. I deliberately choose a password manager that makes that unlikely, but not everyone knows to do that. Many people use Google, Apple or Microsoft as their passkey manager. These companies have seen fit to ban accounts without warning and no recourse.

My password manager lets me export all my passwords as plain text, so for my passwords this potential for lock-in is a non issue - I just export, encrypt, upload the result to a few places, I'm safe. I can always upload the data to a another password manager. As that doesn't work for passkeys, I don't use them.

Passkeys will become acceptable to me once multiple independent storage providers become available for passkeys, and they allow me to freely choose other certified others as a backup. Until that happens, they only solved half the problem. It looks to be the half that locks their customers into their platform.

PS: this doesn't require much. Just Google/Apple to implement CXS along with government providers, and we are there. But it won't happen any time soon.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#796

Earlier quoted context omitted.

I refuse to be part of an "ecosystem".

KeepassXC is free, open source, and supports passkeys. You can locally store your encrypted password vault wherever you like, and transport it between devices using physical media if you like (or self host your own personal storage synchronization server and sync your passkeys between devices like that). No need to be a part of an 'ecosystem' to use a password manager or passkeys.

I love KeepassXC, I use it for all my passwords.

However, I won't give it things which are meant to represent devices.

People who designed the 2FA model designed with the intention that a password is something you know and a device is something you have.

By putting storing both together you're breaking the assumptions of the people who design these systems.

So I store all my passwords on KeepassXC, everything else has to be elsewhere.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#797

Earlier quoted context omitted.

> I mean, at nearly $40 for shipping and something like... As you noted in your original post, next-day shipping is a shipping method so expensive that Amazon only offers it in select locations. An honest reader notes that three-to-seven day shipping is 4 USD, and the one-to-four day rate is 8 USD. > You're 21 miles from Spokane. No, I'm zero miles from San Francisco. But all sorts of places offer effectively-next-da…

I'm glad you've wasted that much time trying to argue the shipping factor and I'm glad you get to brag even more that you can afford to live in San Francisco. I'll take some of your money now, please. I'm scraping together what I can in what some people called "America's Siberia" and am forced to take care of elderly family and have zero escape plan except for working a horribly underpaid IT job here :) https://cash.…

So it is as I said from the outset:

  > Amazon won't deliver one to me for at least six days at the earliest, based on their rural delivery estimate.
  
  That sounds like an Amazon problem. 
But perhaps even 4 USD is too much for you to pay for faster shipping than what Amazon can bother to provide you. If that's the case, then I offer my condolences.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#798
post #768

Earlier quoted context omitted.

> Every device is supposed to have its own unique private key, stored in TPM, released only when passing the user challenge (biometrics or pin, or a yubikey). I have just shy of 2000 site credentials in Keepass. Let's assume that they were all Passkeys. 1) When I buy a new device, how do I create 2000 new Passkeys for that device? 2) Can I still do that if I don't have access to the old device? Maybe it was destroyed…

1) Install a keepass client and use it for passkeys. 2) See #1 3) See #1 KeepassXC supports passkeys. They suggest a couple mobile apps that also do.

How easy is it to switch off keepass? And how easy is it to export off whatever you imported to? Passwords are simple, just remember the text. Passkeys have alot of uncertainty around this

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#799

Earlier quoted context omitted.

> The weird part is that password managers provide no way for you to copy and paste your passkeys. The main feature of passkeys is that they can't be pasted into a website they shouldn't be pasted in to. That means you can't copy them, by design.

They're just text behind the scenes, so you can copy them if you really want to. KeepassX lets you do it, and got into a kerfuffle about it.[1] It's an impossible design. It's all just obfuscation, most of which is confusing to users. [1] https://github.com/keepassxreboot/keepassxc/issues/10407

> They're just text behind the scenes, so you can copy them if you really want to. KeepassX lets you do it, and got into a kerfuffle about it.[1]

Yes - the kerfuffle is broadly I think the fact that it negates the main advantage of passkeys: people can't be tricked into pasting them into a fake login screen.

> It's an impossible design. It's all just obfuscation, most of which is confusing to users.

I agree - they're explained in a really odd way, and I think that's because they're a technology with multiple interaction patterns, rather than a single thing like a password. E.g. your fingerprint on your Mac is implemented as a passkey, or clicking on a browser passkey is also a passkey, or using a password manager via a different UI is also a passkey, or touching a Yubikey is also a passkey. The underlying mechanism (passkey) probably has been surfaced more than it should've been.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#800

Earlier quoted context omitted.

Why?

Passkeys cannot be stolen. Yes, don't say that what if someone steals my iPhone, PIN, and adds their fingerprint. Let's say eBay asks user to login. With passkey. Press and hold fingerprint etc. login done. Even with laptop. And average Joe doesn't want to maintain a keepassdatabse sync it. Yes, you can always use your own server etc but others have life.

Hiding the underlying exchange of data from the user does not mean the data is unstealable
Post reply on HN