Live data from Hacker News

Passkeys now support external providers

developer.apple.com

121–130 of 185 posts

Re: Passkeys now support external providers

#121
post #71

Earlier quoted context omitted.

By the same token, if the server can be tricked into storing the wrong password, authentication is defeated. However, with passkeys, even downloading the entire database doesn't give the attacker any useful credential information. This is in contrast to today, where a database download gives you salted & encrypted passwords that are (generally) knowable (given enough time). I'll take passkeys over passwords any day.

This is my view as well. I think in the more technical crowds but outside of people who actively deal in identity and authentication daily, there seems to be this fixation on the marketing of passkeys that focuses on the FIDO component, and this muddies the virtues of the specification. Many focus too much on the (potential) MFA use case rather than the idea that we can use effectively the same tech as in Yubikeys (e…

I think that is why it is both good and bad that Apple have effectively taken the lead in the rollout. They are great at UX and keeping an eye out for edge cases and trying to sand down the worst sorts of gotchas. If anyone can make sure that Passkeys feel good to the average user it is probably Apple.

On the flipside, that early lead also led to so many of the misconceptions about Passkeys that people have. People think it by nature has to be a locked, walled garden, because Apple has the lead and loves walled gardens when it has the lead.

I think that's why this newest rollout announcement is such great news (which we knew was coming, but wasn't obvious to some of those misconceptions from Apple being in the lead): complete integration with the larger ecosystem of password apps already in the App Store wild (use your 1Password passkeys just like you can use 1Password passwords), and a UX for grouping passkeys and sharing those groups with other contacts (that also helps with all the misconceptions about passkeys being some sort of crack down on password sharing).

These UX flows would have been great to have seen in the initial rollout to assuage a lot of fears about Passkeys. It is great to see them happening right now while it is still early enough to stop most of the FUD before it starts to get outside of the HN paranoia bubbles and into average consumer ears.

Re: Passkeys now support external providers

#122
post #31

Earlier quoted context omitted.

I would argue that password managers are not a "in every sense a really bad, bad idea" for a lot of reasons. Let's look at password reuse for example. As soon as you have more than a few dozen logins, the possibilities are mostly either reusing one or few passwords, or writing them down. Reusing is objectively bad, and for writing them down, the password manager makes it easy to use a really long and random password,…

Password managers makes the user life easier, at a big price if the master password gets compromised, as all the passwords get compromised at same time, in an unified way that by other methods would require much more specialization and effort for to gather together. If that passwords are stored in internet even worst, one can take for sure those passw-managing servers are juicy targets, it is a countdown until the se…

Just because something is a "first computing directive", that doesn't mean people do it. If you're capable of remembering hundreds of high-entropy passwords, more power to you, but that approach doesn't work for most people. Password managers are better than reusing passwords between services, which in the real world, is the alternative.

Re: Passkeys now support external providers

#123
post #72

Earlier quoted context omitted.

How? you make claims that seem to have no substance. What extra vector does Passkeys add for tracking? I don't see any. Passkeys are an origin-bound login mechanism. Worst case is that somebody places a first-party cookie to keep you logged in after you authenticated with a passkey. which they and will already do today without your consent or without logging in. (First-party session cookies don't even need a cookie w…

With 3rd party cookies going away, companies now need your email address to effectively track you. Tracking you via your email address is actually better than using cookies (for the advertiser) because it works cross-device and cross-browser. Any mechanism that makes it easier to login to sites will promote the usage of email addresses for tracking purposes. Think retargeting and conversion tracking (no longer needin…

> Passkeys = quicker and faster to get a user's email address.

Using passkeys doesn't give a site your email address. The site would have to still ask for your email separately.

Re: Passkeys now support external providers

#124

Earlier quoted context omitted.

If you have 2 factor enabled for each login you get told your account settings are incompatible with Plaid and have to disable 2fah. If it's only enabled for first time logins on a new browser/client Plaid ask you for the code. https://support-my.plaid.com/hc/en-us/articles/9098915502999... I don't know for sure how they do it, but it must just be a thousand custom forms and browser automations for each bank they sup…

As far as I know that’s pretty much what it is yes, a bunch of per-bank scraping systems, which get updated when the bank decides to switch things up. IIRC Yodlee and Mint do (did?) about the same thing, for banks without a formal API.

From my understanding in recent years Mint uses a lot more of the Quicken/QuickBooks semi-formal APIs when formal APIs don't exist. My understanding is that is one of the few, biggest benefits of Mint being bought by Intuit because that 200-pound gorilla has always had a surprising number of special read only APIs and export dump tools from even the quirkiest, smallest banks because of how ubiquitous their tax software is (and how many users would rebel if they didn't have easy access in Quicken or QuickBooks).

Re: Passkeys now support external providers

#125
post #35
post #17

Earlier quoted context omitted.

> Whichever way you look at it, in every sense, password managers are a really bad, bad idea. Okay, how about, the actual problem they solved: Reusing a single, simple password on every site, shared behind an email login. That doesn’t sound like a really, really bad idea.

At what point did password managers invent the idea of using a different password for each account? That is computing basics from the beginning. They didn't solve a problem, they just increased the lottery prize if the master password gets compromised. Every body can continue down-voting, but that fact is not going to change.

No, the lottery prize is exactly the same: Access to every site in the list.

The lottery chances have, however, dramatically changed, from no longer relying on the ongoing security practices of every single website you have ever signed into once being eternally a risk to breaching every single other website you have ever signed into.

Perhaps you alone can remember a cryptographically secure password for every website. But I’d more suspect your downvotes come from the impression you give of apparent inexperience combined with what looks like a child-like propensity to bluster.

Re: Passkeys now support external providers

#126
post #86

Earlier quoted context omitted.

How? you make claims that seem to have no substance. What extra vector does Passkeys add for tracking? I don't see any. Passkeys are an origin-bound login mechanism. Worst case is that somebody places a first-party cookie to keep you logged in after you authenticated with a passkey. which they and will already do today without your consent or without logging in. (First-party session cookies don't even need a cookie w…

Passkeys do not help track people between sites, but if they are used in places that passwords never were, it might increase tracking within a site. Hacker News, for instance, allows non-logged-in read-only usage. If Hacker News decided that Passkeys were so easy for the user that non-logged-in usage would be eliminated, then some degree of privacy would be lost. Personally, I don't think it is that much of a risk. I…

If sites started going Passkey only even for "guest" access, you'd quickly see a rise in Passkey managers that quickly generate throwaway passkeys and you'd also see a rise in "globally shared" anonymous group passkeys, just as people already do today to get around paywalls and some walled gardens with passwords and "phone memberships" at rewards clubs (the notorious Jenny's Number being a common one there). The techniques don't really change that much. Passkeys really don't have any more identifying information than passwords or phone numbers and temporary anonymous passkeys or over-shared passkeys are likely to be a thing in some places as soon as they are seen as necessary.

Re: Passkeys now support external providers

#127
post #93

One thing I don't understand about offering passkey login for your email is how you would go about recovering an account if you lost access to the device which holds your passkey? Google states: "When you create a passkey, you opt in to a passkey-first, password-less sign-in experience.". This seems to imply that you will not be able to use your old password if you ever lost your phone. Do Google still offer backup p…

You can still use your password today on a Google account with passkeys. And account recovery via other means (depending on a lot of things) is still available.

It's too early to completely replace all methods with passkeys, but the hope is that as they gain better support and understanding websites will be able to make other methods rare/exceptional. For exceptional cases such as account recovery, as opposed to day-to-day account sign-in, there is room to apply a lot of other abuse signals and other methods to make it harder for attackers.

More here: https://security.googleblog.com/2023/05/so-long-passwords-th....

Re: Passkeys now support external providers

#128

My method for judging the quality of software: Read the latest release notes, negate every statement, and think to yourself: "They were fine with it being like this until now." Passkeys have been advertised as a superior replacement to passwords, but really fundamental issues remain unaddressed. I have one (1) Windows PC and one (1) iDevice. Can I get these to sync? Will both be able to log me in to a Google Account?…

> I have one (1) Windows PC and one (1) iDevice. Can I get these to sync? Or do I need an Android phone for that? Yes. In Chromium-based browsers, at least. Your browser will display a QR code which you scan with your phone. Your phone will display a list of accounts you can sign in with, you select one, authenticate, and you're logged in. Firefox support isn't here yet.

That's not what I mean by "sync". If I don't have the phone with me, I can't authenticate.

Also, I use Firefox exclusively.

This is precisely what I mean: common scenarios are not yet supported.

Re: Passkeys now support external providers

#129
post #28

Is the whole idea of syncing passkeys a bad idea? Or at least a less secure idea. Someone explained to me that passkeys are hardware backed, each passkey is stored on device and tied to the hardware, so even if someone managed to get access to it, they would also need the hardware to get it to work. These software based keys that can be synced are less secure as a result. Then it just becomes like a password again. I…

Passkeys as a brand include both hardware-backed keys that can't be exported and are device-specific. These can be used for things like 2FA/MFA-type scenarios. They also involve a lot of site-specific keys that may not be hardware-backed and syncable. The neat fun thing is that they can be synced with hardware-backed keys for strong E2E between a user's enrolled devices and only the user's enrolled devices (plus maybe a hard to use recovery key). (That's basically how iCloud's Password/Passkey store and a lot of iCloud E2E in general seems to work.)

Passkeys in general, especially the focus on a lot of site-specific E2E shared ones, are very much "just like a password", but as the sibling comment points out, the switch to PKI alone is a huge security win and would stop a lot of the haveibeenpwned sorts of leaks and the overall attractiveness to crackers to break into various company's password databases, because only having a public key is a lot less useful than a salted/hashed password that might be broken or found in a rainbow table.

Re: Passkeys now support external providers

#130
post #5

Interesting, but can someone tell us what this implies wrt. authorities? If someone gets your iPhone and forces you to press your finger on the TouchID, he gets all your passwords no? While with a general master password you could just pretend to have forgotten it?

In good news, a somewhat recent CBP case recently ruled in favor of Touch ID coercion needing a warrant and may be the start of a wave of change in court precedents to stop authorities from abusing biometric loopholes. One court win does not set a new precedent, of course, but it is hope that change may come.
Post reply on HN