Live data from Hacker News

Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

fidoalliance.org

121–130 of 525 posts

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#121
post #77

Earlier quoted context omitted.

There's a frequent misconception that hardware keys are no better than, say, a TOTP seed on a secure element of your phone. The core practical difference between a hardware key and that TOTP code on a secure element is the hardware key, when registered with a domain, is programmed with the domain name in it. Lookalike domains - or anything besides the exact domain you registered the key with - fail to 2FA because the…

Doesn't TOTP use current time as part of the challenge? Why couldn't a refinement of TOTP add the domain name as a further element?

That's pretty much what happened here. Obviously it's going to look a bit different afterwards because you have to mathematically tangle the time, key, and domain together. You can't really do that with the six digits of a traditional OTP code.

And like the other reply stated, if you can't mathematically tie them together, you have to rely on the user validating the domain (which you can't).

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#122
post #85

Earlier quoted context omitted.

In the Netherlands the banks provide the iDIN system, so you can authenticate on more sites with the bank provided logins. Each bank has a slightly different system often using bank card and bank card readers and ways to authenticate through authorised banking app on individual mobile phones. - https://www.idin.nl/en/about-idin/ - https://nl.wikipedia.org/wiki/IDIN - (Use translate function in browser to read as ther…

Given that banks usually MUST validate their customers' identity card the opportunities for tracking your users with this must be superb. I'd frankly prefer "insecure" user+pass over all of these guardrails which are 90% about control over the users and 10% about security.

Tracking from bank or both? Anyways, in Latvia we have similar system and it is a convenient way to authenticate within services where you MUST prove you are person X.Y.Z.

For example, some electric company, if you auth via this method, will provide you with contracts, electricity usage graphics for all the sites you own and and other info you must access as a customer. Same goes for recycling company. These usually provide a way to register using email matching whatever email you had in contract (thus linking to real person anyway)

And then for other services where you request some data electronically that they must "register" each request. For example request some extended data on land/house ownership. You can't have that with non-real-life identifiable entity.

So usually login via bank is an login option with companies you either have juridical relationships or you must provide real life identity where you would otherwise have to show passport in real life.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#123
post #33
post #21

Dumb question: why are biometrics being used to replace the password , shouldn't the biometric replace the username ?

A username (or email, same thing really) is required because there needs to be an identity to match a source of auth to.

Why?

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#124
no thanks. I don't want one account that apple/google/whoever can revoke and ruin my online life. fuck that. I'll take my chances with 2FA and passwords. When it finally gets breached (if you haven't been cancelled!) imagine how much one online cracker will able to do. This also allows them unlimited access to follow you all around and see what you do, where you log in, etc.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#125
post #85

Earlier quoted context omitted.

In the Netherlands the banks provide the iDIN system, so you can authenticate on more sites with the bank provided logins. Each bank has a slightly different system often using bank card and bank card readers and ways to authenticate through authorised banking app on individual mobile phones. - https://www.idin.nl/en/about-idin/ - https://nl.wikipedia.org/wiki/IDIN - (Use translate function in browser to read as ther…

Given that banks usually MUST validate their customers' identity card the opportunities for tracking your users with this must be superb. I'd frankly prefer "insecure" user+pass over all of these guardrails which are 90% about control over the users and 10% about security.

We have GDPR and consumer focused regulators in the EU. Our governments are actually out to protect citizens from corporate malfeasances, as opposed to either ignoring it, or out right enabling it.

If a company abuses this data, you have strong forms of recourse available to you as a citizen, and banks are incentivised to remove bad actors, to ensure they don't become embroiled in enforcement action triggered by a 3rd party.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#126
post #39
post #27

Earlier quoted context omitted.

Sounds to be like we're replacing the username and the password, i.e. something you know with username and your phone, i.e. something you have . It sounds like it's still a one factor authentication system, but different.

Follow-up dumb questions: - so what happens if you don't have your phone at time of login? - if I enroll on iPhone, is my identity forever tied to Apple or can it be migrated to Android if I ever wanted to change platforms? - Can Apple/Google/Microsoft ever block/ban my account, preventing me from logging into my bank, etc that use FIDO login?

> - so what happens if you don't have your phone at time of login?

Depends on if they allow you to turn off password+2FA login entirely, which I only see being possible with something like Advanced Protection Program[0] which can already be used to enforce "Only allow authentication with my password+security keys; there is no way for Google Support to remove 2fa; if I lose the keys, the account's lost".

> - if I enroll on iPhone, is my identity forever tied to Apple or can it be migrated to Android if I ever wanted to change platforms?

I imagine they'll say "login to each website" (which you can do via iOS if you use qr android login[1]) then "re-enroll with your new provider", but I hope there will be an actual export/import or migration experience.

> - Can Apple/Google/Microsoft ever block/ban my account, preventing me from logging into my bank, etc that use FIDO login?

Assuming they don't change how Chrome and iCloud keychain currently works, everything synced should stay on your already signed-in devices, so hopefully you can continue to use your devices as authenticators until you can log into each service and register a regular, hardware key for sign-in.

0: https://landing.google.com/advancedprotection/

1: https://www.chromestory.com/2021/12/qr-code-2fa/#:~:text=Her... I personally tried this with my iPhone, and my phone prompted me to use an iCloud Passkey. I was able to confirm that, by enrolling my iPhone as a security key on GitHub, then this 'BLE Webauthn' feature allowed me to sign in to GitHub on my desktop Chrome browser via my phone. Only downside to this is that the desktop must have a bluetooth card, but hopefully motherboards will continue to come integrated with wifi+bluetooth.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#127
post #38

Earlier quoted context omitted.

You just register 2-3 keys. It's not so bad.

Eh, retrieving a key from off-site storage every time you open a new account is a pretty big inconvenience, even for a security enthusiast.

This. For a while I tried to keep a list of accounts I needed to add my offsite key to, and then every year or so I'd retrieve the key, and add in bulk, but that became way too complicated.

While not ideal, I'd be happy if I could register with the public key of my offsite key or something similar. Really I think there should be a way to register a public persona, and add / remove keys from that persona at will.

Or, just let me (somehow) generate multiple hardware devices with a shared seed.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#128
post #72

Earlier quoted context omitted.

>my threat model is me leaving my key in my pants pocket before putting it in the washing machine. "YubiKey Survives Ten Weeks in a Washing Machine" I think you'll be safe! :) https://www.yubico.com/press-releases/yubikey-survives-ten-w...

Source: The people who sell YubiKeys.

I've actually put my Yubikeys through worse. They've always survived :)

These were the larger ones. Not sure how the smaller "nano" ones would perform.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#129
post #21

Dumb question: why are biometrics being used to replace the password , shouldn't the biometric replace the username ?

Fundamentally, if you want to support multiple, unlinked accounts per person you'll still need some sort of "account designator."

If you don't then the biometric marker can just replace both password and username. The reason why the username exists for the password is because it's problematic to guarantee uniqueness of passwords across your users. One is unique and public and the other is not and private.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#130
post #71

Earlier quoted context omitted.

Eh, retrieving a key from off-site storage every time you open a new account is a pretty big inconvenience, even for a security enthusiast.

Right. Some core services get this treatment, like email and important online accounts. For others I rely on reset mechanisms tied to those email accounts if I lose the primary key and haven't had the chance to register the secondary. Every few months I'll sync up anything that has been missed. It's not perfect, but it's a hell of a lot better than TOTP.

I realize FIDO is better than TOTP since it prevents phishing attacks, etc, but as a user, the ability to backup my seeds is extremely convenient.
Post reply on HN