Live data from Hacker News

Tailscale doesn't want your password

tailscale.com

231–240 of 316 posts

Re: Tailscale doesn't want your password

#231
Probably a bit early to rely on this exclusively; for example Firefox support is not there yet (only works if you have ubikey). Apparently they are planning something there. Bitwarden recenly announced that they are implementing support; and there are probably a few others that are going to do stuff in this space.

I do see the appeal for passkeys but I think short term it's probably going to be a support nightmare. The messaging around this is also quite confusing for example. Way too technical to explain to normal users what this even is or how it works and what they need to do.

Also, as others have pointed out, while this is more secure than relying on passwords (given users can't be relied upon to follow most of the sane recommendations for these), it doesn't remove the need for multi factor authentication. A lot of passkey implementations basically rely on some variation of biometrics. Those aren't exactly hacker proof. And of course phones get stolen and lost all the time. Which creates the need for some recovery mechanism as well as a way to revoke passkeys.

Re: Tailscale doesn't want your password

#232

Earlier quoted context omitted.

You need to add multiple passkeys so if one breaks, you can still access the service. Ditto for Yubikeys (which can be added as a passkey), you need more than one so if you lose it you can still access.

I see a lot of claims that passkeys are more secure than passwords with 2fa, but my understanding is that they are strictly less secure. As it stands right now, if someone wanted to compromise a service that I use 2fa with, they'd need to both obtain my physical device, and also get my password. Either one of those things may be relatively easy, but it's harder to do both- especially without my knowledge. With passke…

In my testing, access to your passkey requires your _unlocked_ device (as opposed to a yubikey, which has no on-device authentication)

Re: Tailscale doesn't want your password

#233

I have an honest question, but am afraid that I get downvoted for reasons that perhaps relate to my question: Why is this on top of HN? Is it a novel invention by Tailscale? Are they the first company who’ve done it? Are they used by so many people (like GitHub) that this will have other implications? Does the article go to technical details of their implementation that relates to the dev crowd? Please, educate me, t…

[flagged]

Re: Tailscale doesn't want your password

#234
post #98

There are still a lot of questions I'm not clear with passkeys. How do you recover your keys if you lose your hardware? What happens if you lose your phone and have no extra trusted device? There will be no more phone number, and no more trusted device. Most MFA implementation, which heavily rely on phone number, will no longer work. And, for Yubikey, how do you backup? Do you need multiple Yubikeys? Do you need to m…

if you're someone who uses a password manager already, and is generating unique random passwords for every website, the only appreciable difference between a passkey and what you do today is: - the passkey is never transmitted anywhere when logging in, eliminating the largest attack vectors for stealing passwords - you can no longer manually type the passkey in on random devices that don't have your password manager…

> you can no longer manually type the passkey in on random devices that don't have your password manager on it

This answers a question about them that I've been unable to find a clear answer for anywhere. My passwords are all randomly generated and stored in my password manager. It's cumbersome to type them in on some device without my password manager and I don't do it often, but at least I have the option!

I really don't like the idea that my passwords/passkeys are some thing to just be abstracted away to the point that I have no idea where they are or how to access them manually if needed.

Re: Tailscale doesn't want your password

#235

Earlier quoted context omitted.

>>So, how do you reset your password when you forget it? Well, it depends. But I don't! I can write a password in any amount of low and high tech ways! I have them printed on paper in safe deposit box (my wife is bad with passwords, so this is safety if I should perish:), I have them in a password manager on USB sticks at home in a safe, I have them copied on my NAS and laptop and so on. Whereas passkeys, it seems fr…

You can do this with Passkeys. You can write your Passkey down on a post-it, or memorize it and cross the border with it, or anything you want. This thread has urged me to write a post clarifying some of the misconceptions I always see: https://www.stavros.io/posts/clearing-up-some-passkeys-misco...

That was helpful but there's a difference between "possible" and "feasible in practice for the vast majority of users". Eg, you can theoretically develop your own passkey device as you say, but that doesn't mean most people can.

I'm not sure I really prefer passkeys less than passwords but I do think some of the "misconceptions" aren't really misconceptions, but realistic concerns about what happens in practice. It might be better to be up front about these than dismissive, because that's where the problems in practice develop.

Re: Tailscale doesn't want your password

#237
post #6

I just want to say that Tailscale ROCKS. It installed flawlessly on all of my machines (Linux and Mac), and now I can route to all of them wherever I am. It configures DNS correctly, it routes traffic correctly, and all of my internal machines at my house are routable when I'm out in a coffee shop or library or hotels. It's been more than a year and it's operated flawlessly, never needing maintenance or restarting, i…

I wanted this to be true for me, but on Android it sometimes kills my internet connection (even when turned off) until I force-close it, on Windows it'll hang and consume lots of CPU every few days and on Linux (Ubuntu/Pop) the service sometimes stops and I don't know why. I just have bad luck, I guess.

(On-topic, I would prefer them to to take my damn password please.)

Re: Tailscale doesn't want your password

#238

Earlier quoted context omitted.

I had the same issue with LastPass a few years ago. When I reinstalled my OS they decided to lock me out of my account because they thought I was a different person. The only way through is e-mail verification. Guess where that email's password was stored in? Lost everything. Been using Bitwarden ever since.

Everyone must know two passwords: their password manager's password, and their email password.

It gets even more complicated if you use 2FA with your email provider.

Re: Tailscale doesn't want your password

#239

Earlier quoted context omitted.

You can do this with Passkeys. You can write your Passkey down on a post-it, or memorize it and cross the border with it, or anything you want. This thread has urged me to write a post clarifying some of the misconceptions I always see: https://www.stavros.io/posts/clearing-up-some-passkeys-misco...

That was helpful but there's a difference between "possible" and "feasible in practice for the vast majority of users". Eg, you can theoretically develop your own passkey device as you say, but that doesn't mean most people can . I'm not sure I really prefer passkeys less than passwords but I do think some of the "misconceptions" aren't really misconceptions, but realistic concerns about what happens in practice. It…

But you don't need most people to develop their own Passkey device any more than you need most people to make a phone.

A company will make it, vote with your wallet and buy the one that suits you.

I'm looking forward to BitWarden supporting Passkeys, for example, as that's my preferred way of using them.

Re: Tailscale doesn't want your password

#240

Earlier quoted context omitted.

I don't know about Windows, but if you see the example your Mac is putting it in your keychain app, which is usely available on other devices that are connected to your Apple account. Also if you install a new macbook. Most likely also on your iphone. If you have an Android phone that will be a lot less smoot

I had the impression that Apple stores and syncs them for you, but at no point will give you the option to actually backup or restore (have a copy of the info under your management). Let's say I need to move a credential from my account to my wife's, I guess it's probably not allowed. Or god forbid I change Apple IDs.

You can export your password (from Safari or from the Settings app) to a csv file. Not sure how that handles passkeys, if at all, however. Probably not (yet).
Post reply on HN