Live data from Hacker News

Passkeys: They're not perfect but they're getting better

ncsc.gov.uk

141–145 of 145 posts

Re: Passkeys: They're not perfect but they're getting better

#141
post #35

> websites which [...] also want to know how the passkey is being handled by the user’s device to keep their accounts safe This is exactly where passkeys go too far. "to keep their accounts safe" is always the excuse used to reduce the freedoms of users. Web sites have no business deciding how things are handled on user devices but it's precisely what passkeys enable. The boundary of control of a website used to stop…

How do you keep out multi-device USB HSM users?

Arbitrarily?

I’ll die on that hill.

Re: Passkeys: They're not perfect but they're getting better

#142

Earlier quoted context omitted.

Apple does precisely this for Apple account, you need to have a hardware attested passkey implementation to authenticate using passkey. Edit: forgot to add Apple account

To your edit: I suppose this is strictly true, but it's relevant that Apple's own devices satisfy the attested hardware requirement. These are the same devices you need to have a full-fledged Apple account in the first place. That's more Apple doing Apple things than anything to do with passkeys, but it is indeed an example of not being able to use KeyPassXC. Will there be more than epsilon cases like that? I still d…

Will there be more than epsilon cases like that?

I anticipate banks, enterprise sso login, etc. doing this.

Post reply on HN