Live data from Hacker News

Passkeys: They're not perfect but they're getting better

ncsc.gov.uk

121–130 of 145 posts

Re: Passkeys: They're not perfect but they're getting better

#121

Earlier quoted context omitted.

> Even without copyable keys, if your friends and family can be tricked into pasting their plain text keys into a scam site, they can be tricked into pasting their encrypted keys and their associated password to a scam site. The point is that data shouldn't really be copyable, but a backup should at least be encrypted. Ideally you don't have or need a key transfer mechanism, because sites have the ability to register…

> I don't want to manually copy my signal cypher-data between devices either! Yes you. Others do. Whenever I switch laptops the first thing to do is copy over all ssh keys. I am not going to roll a new key and add it to 100 servers. A couple of years back I switched password managers, I didn't go over 1000 sites and changed all my passwords, my password manager exported a plaintext file and I had it imported in the o…

> A couple of years back I switched password managers, I didn't go over 1000 sites and changed all my passwords, my password manager exported a plaintext file and I had it imported in the other after a small transformation step.

And, modulo the "plaintext" part, I think this is a reasonable usecase. It's equivalent to the "backup" case. I transfer an encrypted blob between devices and decrypt it locally is reasonable.

> No they don't and if they did they would also understand not to upload their plaintext credentials.

Except that you have already stated that you have done exactly this, and you claim to know what you're doing!

Re: Passkeys: They're not perfect but they're getting better

#122
The problem with passkeys is that device/OS and browser vendors (or more specifically: Apple, Google and Microsoft) are trying to use it as an excuse to lock in users.

There is no reason a passkey can’t be portable - even the so called “device bound” credentials these vendors are claiming prevent export are actually implemented as credentials synchronised throughout their own ecosystems - i.e multi device.

NOTHING in the FIDO2/WebAuthn spec forbids user controlled portability.

It’s just bigtech trying to make it harder to leave their ecosystems - and when passkeys become widely adopted you won’t be able to log into those sites/apps without some form of recovery on a case by case basis should you decide to switch from Apple to android, windows to Mac, etc.

Re: Passkeys: They're not perfect but they're getting better

#124

Earlier quoted context omitted.

> I don't want to manually copy my signal cypher-data between devices either! Yes you. Others do. Whenever I switch laptops the first thing to do is copy over all ssh keys. I am not going to roll a new key and add it to 100 servers. A couple of years back I switched password managers, I didn't go over 1000 sites and changed all my passwords, my password manager exported a plaintext file and I had it imported in the o…

> A couple of years back I switched password managers, I didn't go over 1000 sites and changed all my passwords, my password manager exported a plaintext file and I had it imported in the other after a small transformation step. And, modulo the "plaintext" part, I think this is a reasonable usecase. It's equivalent to the "backup" case. I transfer an encrypted blob between devices and decrypt it locally is reasonable…

When did I say I uploaded my plaintext credentials anywhere? Do you mean the password manager? That's local and open source.

Re: Passkeys: They're not perfect but they're getting better

#125

Earlier quoted context omitted.

It's not really Netflix. Its Microsoft, Apple and Google. So say goodbye to using teams on Linux. Using Microsoft365 on any hardware that is not Microsoft approved. Or logging in to your bank without an iPhone or an android. We will surely complain but the bank will say that we only support secure devices and that means iPhones and Android, and how come you are making a big deal about it just buy one of these two eve…

> Or logging in to your bank without an iPhone or an android. This is already possible (and common!) many banking apps, for better or worse, use device attestation features that require varyingly official copies of android. Were you already complaining about this?

> Were you already complaining about this?

Yes, "we" were, definitely. I already can't freely choose the OS that I have installed on my phone because I'm limited in the apps that I can install. For example many government ID and banking apps will refuse to work on GrapheneOS even though that OS is security-focused and will probably keep you safer than your regular Chinese Android flavor. But it's not sanctioned by a big international corporation so it's a no. Is your argument that we shouldn't complain since it is already happening somewhere ?

What's an "official" copy of Android ? AOSP is supposed to be open-source. "Official" means controlled by a multinational corporation. I'm very puzzled that the reaction to these entities gaining even more power, outside of democratic control, is met with a "oh it may me worse, it may be not" type of reaction.

Would you be ok if for example your government's website to pay your taxes mandated a device with attestation knowing you can only get one from Google, Apple or Microsoft ?

Re: Passkeys: They're not perfect but they're getting better

#126
post #104
post #35

> websites which [...] also want to know how the passkey is being handled by the user’s device to keep their accounts safe This is exactly where passkeys go too far. "to keep their accounts safe" is always the excuse used to reduce the freedoms of users. Web sites have no business deciding how things are handled on user devices but it's precisely what passkeys enable. The boundary of control of a website used to stop…

> Web sites have no business deciding how things are handled on user devices but it's precisely what passkeys enable. On the contrary, their operators can decide whatever they like, but I won't be visiting them if they go the passkeys route. I can live w/o Netflix or Disney just fine. Your PII will leak off their platform anyway.

You'll also have to live without banking, government ID ... The "I don't need those services" rhetoric only goes so far.

Re: Passkeys: They're not perfect but they're getting better

#127
When they first came about it seemed like some websites didn’t work well with them and insisted on using the device password manager. I use BitWarden for everything so didn’t want to get into that - I want to be able to log into things on my personal and work Macs in Chrome, Safari on iOS, etc etc.

Since then though it’s rare I’ve run into issues like that, and the login flow is much better in sites that have adopted it. I did hit an issue in GitHub last week where after logging into things with passkey it then immediately wanted me to MFA which could use the same passkey. But these things are getting rarer.

Re: Passkeys: They're not perfect but they're getting better

#128
post #126
post #104

Earlier quoted context omitted.

> Web sites have no business deciding how things are handled on user devices but it's precisely what passkeys enable. On the contrary, their operators can decide whatever they like, but I won't be visiting them if they go the passkeys route. I can live w/o Netflix or Disney just fine. Your PII will leak off their platform anyway.

You'll also have to live without banking, government ID ... The "I don't need those services" rhetoric only goes so far.

At least where I live, there are no actually important services that can't be done in person.

Re: Passkeys: They're not perfect but they're getting better

#129

Earlier quoted context omitted.

If you are not careful, you'll enter the random chains of characters into a phishing site. But a phishing site can't steal your passkey and forward it to the real site, the passkey will just not work with the phishing site if you try using it there, it's locked to the authentic domain.

That's mumbo jumbo to me so far. What's an authentic domain? How is my passkey locked to it?

The domain that the verifier (the site trying to authenticate you) is at is part of the cryptographic process. If the domain doesn't match (ie you're at a phishing site) then the results of the cryptography won't be valid for the actual correct site, only the phishing site (which gets the phishing site nothing it can use).

Re: Passkeys: They're not perfect but they're getting better

#130
post #126

Earlier quoted context omitted.

You'll also have to live without banking, government ID ... The "I don't need those services" rhetoric only goes so far.

At least where I live, there are no actually important services that can't be done in person.

Yet.
Post reply on HN