Live data from Hacker News

A Guide to WebAuthn

webauthn.guide

121–122 of 122 posts

Re: A Guide to WebAuthn

#121

Earlier quoted context omitted.

You're wrong. You can manage your own keys. You don't need any big corporation for WebAuthn.

Well, that's assuming that the anti-feature of device attestation doesn't end up being used in the inevitable way that the spec allows: "But attestation is not spoofable. Therefore, if sites launch webauthn support and accept attestations from the current set of token vendors, future vendors may be locked out of the market: Their devices won’t work because their attestations aren’t trusted, and they won’t be able to…

I think the whole attestation thing is generally a terrible idea. It's not impossible to extract data from secure hardware, right now there is not a lot of incentive to do it because it's not going to get you much, spend a month of hardware research to get one user's key, no thanks. But with whole batches of devices having the same private attestation key stored on the device this incentives essentially ransom of security key vendors. I.e. Lets say I am a hacker that spends a month of hardware research finding a vulnerability and extracting the attestation private from a token. Its worth my time because I know this vendor has 100,000+ keys out there that uses this same attestation key. I then request that vendor send me $500,000 in bitcoin or I release the private publicly. The vendor pays the ransom because it's cheaper than recalling 100,000+ security keys. Another issue here is it's not if but when this happens, so when it does how do all of the web sites out there update to block the hacked keys? Lots of web sites never will. Time to rethink the attestation key being stored each token, that's a bad idea.

Re: A Guide to WebAuthn

#122
post #75

Earlier quoted context omitted.

Well, that's assuming that the anti-feature of device attestation doesn't end up being used in the inevitable way that the spec allows: "But attestation is not spoofable. Therefore, if sites launch webauthn support and accept attestations from the current set of token vendors, future vendors may be locked out of the market: Their devices won’t work because their attestations aren’t trusted, and they won’t be able to…

Yes, if a service says "we only support Yubikeys for login", you should boycott them.

The only service I have seen that only allows Yubikeys so far is Vanguard.
Post reply on HN