Live data from Hacker News

Passkeys: A shattered dream

fy.blackhats.net.au

111–120 of 789 posts

Re: Passkeys: A shattered dream

#111

The biggest issue with passkeys is that I just can't trust the companies offering them. They are locked into the platform for reasons that are ostensibly security but often indistinguishable from platform lock-in. If you make a passkey on an Apple device as far as I can tell it will never leave that device, ever, and there is no way to change this. Of course this means you can never be phished for your credentials bu…

[deleted]

Re: Passkeys: A shattered dream

#112
As someone who happily uses Yubikeys, I really don't want to use a Passkey. I want to still use a username/password and the Yubikey. Not just username and Yubikey.

Google tries to force use of passkey now that if you enroll a Yubikey it will now be a Passkey, instead of a second factor. With no option to disable it. I have to run the Yubikey Manager tool and then disable "FIDO2", so that I can force it only be used as a 2nd factor.

Re: Passkeys: A shattered dream

#113
post #97
post #89

Earlier quoted context omitted.

Passkeys are exactly like SSH keys. You should use them exactly like you use SSH keys.

What about storing/backupping/managing passkeys versus SSH keys?

It's the same, you should not store or backup SSH Keys.

Re: Passkeys: A shattered dream

#114

Earlier quoted context omitted.

not to diminish your point, but since at decade or so I'm a more worried about corporate surveillance capitalism than I'm about government surveillance.

With a bit of a change, you can mostly avoid most of those corporations... you lose out on some tech goodies, but you can still live quite normally. You cannot avoid the government.

You can’t avoid these corporations if you want to remain active on the internet. They keep shadow profiles. They sell and share your data from one service to another (I stoped using Facebook for example, but Netflix shared its watch data with Facebook.)

I don’t think it’s possible to avoid them. Confuse them maybe.

Re: Passkeys: A shattered dream

#115

Earlier quoted context omitted.

Just you wait for governments to require platforms to only accept gov-signed keys. I was sceptical about something-you-own auth vs. something-you-know auth from the beginning and recieved backlash from my tech peers for it. I hate to be able to go "told you so" on this one. Lets hope im wrong about the government involvement, but i dont think i will.

not to diminish your point, but since at decade or so I'm a more worried about corporate surveillance capitalism than I'm about government surveillance.

Why? Governments can do so much harm by incarcerating, fining or even killing you.

Don't get me wrong - corporate surveillance can be very annoying, especially in insurance / credit scoring / price discrimination etc, but it seems a comparatively lesser danger.

Re: Passkeys: A shattered dream

#116
Did you know that you can turn every $2 Raspberry Pi Pico clone board into a FIDO2 stick, and even make it Yubikey compatible? https://www.picokeys.com/

Well, not as secure as a commercial key, because the Pico doesn't have encrypted storage, but still much more secure than login/password.

Re: Passkeys: A shattered dream

#117
post #112

As someone who happily uses Yubikeys, I really don't want to use a Passkey. I want to still use a username/password and the Yubikey. Not just username and Yubikey. Google tries to force use of passkey now that if you enroll a Yubikey it will now be a Passkey, instead of a second factor. With no option to disable it. I have to run the Yubikey Manager tool and then disable "FIDO2", so that I can force it only be used a…

Yubikey + PIN works as a very nice passkey

Re: Passkeys: A shattered dream

#118

My biggest issue with passkey is not passkey itself, which, when it works, is great, but more the implementation of it done on most websites. Use a passkey on https://www.passkeys.io and it works great! On google too. But use it on PayPal, it does not anymore. Who’s to blame?

I've added a few passkeys to 1Password. It works pretty well on github.com, and sometimes on google.com. But apparently, passkeys.io bypasses 1Password and asks the OS for passkeys? So passkeys.io doesn't actually work for me, unless I want to store the passkey in the OS keychain. Which I don't, because I don't want to be locked into that.

How can it be that the website decides which password manager I should use to store the passkeys? That's crazy and goes against all intuition.

Re: Passkeys: A shattered dream

#120

The biggest issue with passkeys is that I just can't trust the companies offering them. They are locked into the platform for reasons that are ostensibly security but often indistinguishable from platform lock-in. If you make a passkey on an Apple device as far as I can tell it will never leave that device, ever, and there is no way to change this. Of course this means you can never be phished for your credentials bu…

Bitwarden (& vaultwarden) also offer passkey which seem to work pretty well. I've not had a problem registering both this and my phone on any site.

I've found the Bitwarden to be hit and miss. Some sites work fine with it, others don't work. I haven't debugged it enough to work out whether the problem is on the Bitwarden end or the website end or something else altogether. Given I'm wary of the benefits (or lack of) of passkeys I haven't really looked into it in depth as I have other 2FAs I can use instead.
Post reply on HN