Live data from Hacker News

Toward a Passwordless Future

privacyguides.org

11–20 of 70 posts

Re: Toward a Passwordless Future

#12
post #4

So... what happens with passkeys if you lose/break/someone_steals your phone? I'm talking about normal users, without backups.

All of the major implementations sync across all of your devices and use recovery codes as part of the setup process. Apple’s implementation is designed to cover loss of all devices, and I’d assume the others are similar: https://support.apple.com/guide/security/escrow-security-for... The key thing to understand is that passkeys are not intended to be as secure as hardware tokens but to be more secure than traditiona…

We can’t trust users to not re use a password, why do we expect they will go through the effort of storing / understanding recovery codes?

Re: Toward a Passwordless Future

#13
post #6
post #4

Earlier quoted context omitted.

All of the major implementations sync across all of your devices and use recovery codes as part of the setup process. Apple’s implementation is designed to cover loss of all devices, and I’d assume the others are similar: https://support.apple.com/guide/security/escrow-security-for... The key thing to understand is that passkeys are not intended to be as secure as hardware tokens but to be more secure than traditiona…

What if the provider of the major implementation decides to shut you out of your account?

Well, it's true that a password manager is a single point of failure.

If you have two password managers then they can serve as backups for each other. Unfortunately that means you have to register each account twice.

Re: Toward a Passwordless Future

#14
post #6
post #4

Earlier quoted context omitted.

All of the major implementations sync across all of your devices and use recovery codes as part of the setup process. Apple’s implementation is designed to cover loss of all devices, and I’d assume the others are similar: https://support.apple.com/guide/security/escrow-security-for... The key thing to understand is that passkeys are not intended to be as secure as hardware tokens but to be more secure than traditiona…

What if the provider of the major implementation decides to shut you out of your account?

That depends on whether you need to have an active account to use your existing devices. For example, an Apple user would need to migrate before things fall out of sync but they have a full copy on every device.

The fallback path here is what you’d do with any other MFA loss. It’s not a federated login system so you’d be looking at some kind of account recovery process for each of the sites where you used your passkey, just like you would if you lost a Yubikey or changed phone numbers.

Re: Toward a Passwordless Future

#15
post #12
post #4

Earlier quoted context omitted.

All of the major implementations sync across all of your devices and use recovery codes as part of the setup process. Apple’s implementation is designed to cover loss of all devices, and I’d assume the others are similar: https://support.apple.com/guide/security/escrow-security-for... The key thing to understand is that passkeys are not intended to be as secure as hardware tokens but to be more secure than traditiona…

We can’t trust users to not re use a password, why do we expect they will go through the effort of storing / understanding recovery codes?

It’s easier to print things and you have clear instructions telling you why it’s important.

The key here is thinking about relative risk: many people get compromised by reusing passwords or being phished every day compared to the number of people who simultaneously lose all of their devices and recovery codes.

Re: Toward a Passwordless Future

#16

I really don't want to use Passkeys until they can be stored in my password manager of choice on Linux, Android and Windows.

Okay. Maybe discuss this with whoever develops your password manager. The tone of your reply has me thinking that you’re using an open-source password manager. Maybe they’ll accept a PR from you?

Passkeys are supported by my password manager of choice, in the OSs that I care about.

Re: Toward a Passwordless Future

#19

Earlier quoted context omitted.

But if that "buddy account" is 'passworded' by the same passkey device? Getting a new sim card with the same number is easy, you just go to your mobile provider with your ID card, and you're done in five minutes. I mean still... the article mentions a "single point of failure" as a bad thing with other methods, but forgets about it here.

Until the passkey workflow goes sideways for "tech" people I don't think the risks will be acknowledged (if then even). Those of us who don't want the let Google, Apple, or Microsoft manage our passkeys (i.e. pledging our fealty to our lords) will be seen as fringe lunatics. I'll keep my workflow of always visiting sites by typing the URL myself, using a password manager, and TOTP 2FA w/ the secrets saved offline on…

Same here, I don't like passkeys for many reasons. Another reason is that I can't see the key that I'm using. Therefore: What if Bitwarden doesn't pick up the passkey? Tough luck, I'm out of options. I cannot manually create a passkey entry in Bitwarden because it's all hidden magic. If I notice that the password manager doesn't pick up a registration then I just add it myself. Not possible with passkeys.

Re: Toward a Passwordless Future

#20
post #14
post #6

Earlier quoted context omitted.

What if the provider of the major implementation decides to shut you out of your account?

That depends on whether you need to have an active account to use your existing devices. For example, an Apple user would need to migrate before things fall out of sync but they have a full copy on every device. The fallback path here is what you’d do with any other MFA loss. It’s not a federated login system so you’d be looking at some kind of account recovery process for each of the sites where you used your passke…

> The fallback path here is what you'd do with any other MFA loss.

Which, in many cases, is avoid MFA because it's less secure. Yes, less secure because availability is part of security.

And I don't have a better plan to store all those recovery codes than to store all those passwords. So the attacker can still get in with the same effort, but I have to keep getting my phone. No thank you.

Post reply on HN