Live data from Hacker News

Passkeys: The beginning of the end of the password

blog.google

131–140 of 1001 posts

Re: Passkeys: The beginning of the end of the password

#131
post #94

There is a legal advantage that passwords have that passkeys and FIDO and so on do not have. In civilized countries, no one can force you to hand over a password (as you have a right to not incriminate yourself). That does not hold for property which can be confiscated or even biometric attributes which can be taken against your will legally. Theoretically, passkeys could still offer this advantage if they are stored…

> In civilized countries, no one can force you to hand over a password (as you have a right to not incriminate yourself). Which countries? In the US, the intersection between 5th amendment rights and password disclosure is not complete. You can be forced to disclose a password in certain circumstances here.

And if you don't comply?

With biometric data like FaceId or fingerprint it's easier for them to get access.

Re: Passkeys: The beginning of the end of the password

#132
post #121
post #85

Earlier quoted context omitted.

Call me a cynic but I'm convinced that won't be happening anytime before critical mass adoption of these companies' own solutions, and either defeated acceptance of this new norm or abject incomprehension by whomever remains. "All your base are belong to us"

Yeah I fail to see why google would be incentivized to provide this functionality.

EU provides incentive.

Re: Passkeys: The beginning of the end of the password

#133
post #94

There is a legal advantage that passwords have that passkeys and FIDO and so on do not have. In civilized countries, no one can force you to hand over a password (as you have a right to not incriminate yourself). That does not hold for property which can be confiscated or even biometric attributes which can be taken against your will legally. Theoretically, passkeys could still offer this advantage if they are stored…

> In civilized countries, no one can force you to hand over a password (as you have a right to not incriminate yourself). Which countries? In the US, the intersection between 5th amendment rights and password disclosure is not complete. You can be forced to disclose a password in certain circumstances here.

In Canada it has been upheld that you cannot be compelled to divulge your passwords as it violates the Charter of Rights and Freedoms.

Re: Passkeys: The beginning of the end of the password

#134

> the same way they unlock their devices: with a fingerprint, a face scan or a screen lock PIN I am not a cryptographer: why would a 6-digit screen lock PIN with this system be any safer than a 6-digit numeric password on the web (i.e. not very)?

Many phones block access after too many false PINs, if the web password has the same feature there is no difference.

Re: Passkeys: The beginning of the end of the password

#135
WebAuthN is great, but I can't help but feel that Passkeys are actually a step backwards.

At least on iOS, there is no way of preventing them from being synced to iCloud, which is the opposite of what I want for high-stakes credentials like bank accounts or government e-signatures.

I've tried to raise [1] a related issue (i.e. the inability for relying parties to opt out of credential syncing, if not an explicit requirement to opt in to it) to the W3C WebAuthN working group, but it seems like the working group itself is strongly pro cloud synchronization as well.

Today, Google has sent me an email about their intention to deprecate their (device-bound) iOS authenticator in favor of (iCloud-synchronized) Passkeys, and I guess I'll begrudgingly have to switch to using an external FIDO authenticator instead.

[1] https://github.com/w3c/webauthn/issues/1714

Re: Passkeys: The beginning of the end of the password

#136
post #5

How is this more secure? They say "with a fingerprint, a face scan or a screen lock PIN", but basically all phones let you fall back to PINs if you dont want to do face or fingerprints. Pins are flat out not secure - typically just 4 digits. Yeah its probably better than 80% of people having "password123", but it seems strictly worse than a password + password manager? Or at least just having proper 2FA.

You're forgetting Oyler's Law of Passwords: Humanity will be forced to try each wrong approach to passwords, one at a time and trial-and-error, for all eternity.

Slightly off-topic: If a website will not let me register and complains that my password is too long, they're still storing that in the underlying database as a properly-salted (modern algo) hash, right?

Re: Passkeys: The beginning of the end of the password

#137

Earlier quoted context omitted.

Sure. But am I still locking my ability to access that account permanently to Google? Can I login via Chrome on an Apple/Windows platform and add a passkey there? I’m also a bit worried that this permanently entrenches these as the platform vendors because no one is going to port to a new platform unless you’re already a major tech company (maybe).

Google actually outlines that very scenario near the bottom of their announcement: > Using passkeys does not mean that you have to use your phone every time you sign in. If you use multiple devices, e.g. a laptop, a PC or a tablet, you can create a passkey for each one. In addition, some platforms securely back your passkeys up and sync them to other devices you own. For example, if you create a passkey on your iPhon…

> that passkey will also be available on your other Apple devices if they are signed in to the same iCloud account

I am not sure I like this. Unless the passkeys are only transferred directly device-to-device, each OS vendor's user cloud storage now becomes the keys-to-every-kingdom uber-target.

Re: Passkeys: The beginning of the end of the password

#138
I'm glad most people here are recognizing that this is a stupid, stupid idea.

Here is some simple old-school ammo against it (or perhaps in favor of it, if they were to be so bold) Some good old-fashioned "skin-in-the-game" e.g. Nassim Nicholas Taleb style.

I will gladly use (and pay for!) this, but only with indemnification.

Insure me to the tune of, say, $100,000 in the event of a breach or a problem and not only will I use it, I'll pay for it.

Otherwise, no deal. If e.g. Google wouldn't take this theoretical (or practical) deal, then they are completely full of it.

Re: Passkeys: The beginning of the end of the password

#139
post #94

There is a legal advantage that passwords have that passkeys and FIDO and so on do not have. In civilized countries, no one can force you to hand over a password (as you have a right to not incriminate yourself). That does not hold for property which can be confiscated or even biometric attributes which can be taken against your will legally. Theoretically, passkeys could still offer this advantage if they are stored…

> In civilized countries, no one can force you to hand over a password (as you have a right to not incriminate yourself). Which countries? In the US, the intersection between 5th amendment rights and password disclosure is not complete. You can be forced to disclose a password in certain circumstances here.

This was not my understanding so I looked it up and found this: https://www.reuters.com/business/legal/us-supreme-court-nixe...

Wherein it mentions passwords are considered testimonial and therefore protected by the 5th, but device passcodes were ruled to be exempted under the “forgone conclusion” exception to the 5th (TIL about that).

Is this kind of thing you are referring to?

Re: Passkeys: The beginning of the end of the password

#140
post #135

WebAuthN is great, but I can't help but feel that Passkeys are actually a step backwards. At least on iOS, there is no way of preventing them from being synced to iCloud, which is the opposite of what I want for high-stakes credentials like bank accounts or government e-signatures. I've tried to raise [1] a related issue (i.e. the inability for relying parties to opt out of credential syncing, if not an explicit requ…

How is this different than a password manager with encrypted cloud backup? Your recourse if someone breaks passkeys is legal, not technical. Security must be a balance with functionality, and this is a huge improvement over passwords. (Tangentially, it would be great if we got cryptographic digital identity cards like Estonia has for signatures but that’s more of a long term goal)

Cloud sync (encrypted!) is important because your average user needs that convenience and durability of authenticator.

Post reply on HN