Does anyone here know what privacy/tracking issues are with this standard?
Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
11–20 of 525 posts
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#12Not a great thing to see the big three once again, driving the standards here. You should be worried. But as long as the ridiculous SMS 2FA is removed or replaced by something better, then fine. But we'll see how this goes. From the web side of this standard, this also tells me that Mozilla has no influence anywhere and will be the last ones to implement this standard in Firefox. Oh dear.
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#13Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#14> When you sign into a website or app on your phone, you will simply unlock your phone — your account won’t need a password anymore.
> Instead, your phone will store a FIDO credential called a passkey which is used to unlock your online account. The passkey makes signing in far more secure, as it’s based on public key cryptography and is only shown to your online account when you unlock your phone
So if I was a dumb kid, I could login to my parents bank accounts (or more / worst) if my mom gave me her 4 digit phone password for games earlier?
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#15Anyone got a link to something less hand-wavey and more concrete?
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#16One aspect of FIDO that could still be troublesome is account recovery in case of inadvertent loss of passkey. OOB recovery with SMS or email is considered too weak and the main recommended alternatives are to maintain multiple authenticators (i.e. multiple copies of your passkeys), re-run onboarding processes for new users or just abandon the account.
It's going to be interesting to see how those alternatives play out in real world situations.
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#17“The standards developed by the FIDO Alliance and World Wide Web Consortium and being led in practice by these innovative companies is the type of forward-leaning thinking that will ultimately make the American people easier to track online.
This will be done by linking all online activity to unique personal attributes, i.e. "their fingerprint or face, or a device PIN." It's basically another step towards the China model of total mass surveillance of the population.
[edit: all the justifications for this proposal - aren't they mostly solved by the use of password managers?]
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#18I’m sure people way smarter than me have this figured out, from the Google post: > When you sign into a website or app on your phone, you will simply unlock your phone — your account won’t need a password anymore. > Instead, your phone will store a FIDO credential called a passkey which is used to unlock your online account. The passkey makes signing in far more secure, as it’s based on public key cryptography and is…
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#19I’m sure people way smarter than me have this figured out, from the Google post: > When you sign into a website or app on your phone, you will simply unlock your phone — your account won’t need a password anymore. > Instead, your phone will store a FIDO credential called a passkey which is used to unlock your online account. The passkey makes signing in far more secure, as it’s based on public key cryptography and is…
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#20So their vision of the future is that to do anything online, one MUST have a phone (ahem, portable wiretap)? And they're going to be keeping my secrets for me, for my own good? I'm not sure I'm down with any of that.