Live data from Hacker News

Passkeys were invented by engineers with zero understanding of consumer brain

twitter.com

341–350 of 813 posts

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#341
post #108

Earlier quoted context omitted.

>This is much, much simpler than you think it is. Passkeys are just passwords that require a password manager. The issue isn't what passkeys _are_ (e.g. explaining they are like public/private "ssh keys" and hoping that type of explanation ends the confusion). Instead, it's the workflow around passkeys. The websites show very confusing dialog popups and choices that a lot of normal people will not understand. This is…

sadly it seems like most of the banks I use still enforce antiquated password rules, no MFA and rely on stupid questions most of which can easily be guessed from public records.

Just the other day I was creating an ID on a government web site, which offered a list of security questions such as "Title of your favorite movie" or "Someone that you admired as a child" and the answer was not allowed to have any spaces.

Just absurd.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#342
post #238

Earlier quoted context omitted.

There is security value. A passkey will not work anywhere except the actual website. Fake look a like sites can't get the credentials. Evidently they can trick you into authorizing their device.

Sure? MitM isn't a new kind of attack, and I'd be surprised if the ball-of-wax-and-javascript that is WebAuthn isn't vulnerable to that...

This is one of the key security features of passkeys. I did a little searching and the work around is to do a standard fake website that prompts for your standard credentials. That should be a fairly simple fix. Require access from a new device to be authorized from another source with an explanation that they will never request this info.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#343
post #8

I do not know how to use a Passkey in a way that won’t impede how I log in to systems. I’ve been in tech for 26 years, and I understand the Public/private key behind what a Passkey is. Here’s what I don’t understand: I access a website through at least four different devices (my iPad, iPhone, Windows Desktop computer, and MacBook Pro) and three different browsers on each device (Brave, Firefox, Safari) , and I use La…

I find it abjectly terrifying. Like if I log into your site with a Passkey what happens if my device breaks? What if some big tech company decides to nuke my account for no good reason?

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#344

Earlier quoted context omitted.

> It seems like everyone wants to be _the_ password manager for all your passkeys. Which defeats part of the point of passkeys in the first place in that they are supposed to be device-bound, the private key held in the TPM or secure enclave or whatever other security chip, mathematically non-exportable. Storing all your private keys in a cloud vault still leaves you exposed to potential credential theft if your vaul…

This is exactly all the stuff normal people don't care about. If your system requires any basic intelligence or interest scrap it and go back to the drawing board because you just lost your customers.

I mean, no one ever said it was a good design.

But the original FIDO2 standard wasn't made with consumers in mind in the first place, it was driven by enterprises that wanted high-assurance security. It works in that environment because, well, a big IT department controls it, can support the employees, and you can mandate and control its use.

It was just sort of haphazardly shoehorned onto general users/consumers, prematurely IMO, via synced credentials as a compromise instead of coming up with something better.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#345

Earlier quoted context omitted.

How well does that Yubikey work with an iPhone?

Works just fine, you have to get the one with NFC

You can also plug them in to the USB-C port, works just fine.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#346
post #316

Earlier quoted context omitted.

> In the worst case, banks actually don't make it very hard for seniors to reset your password/passkey; just show up at a branch with photo ID, your bank card, and your PIN, and a teller will help you reset your credentials. They do it all the time. Maybe... I just ran into an annoying scenario where the largest bank in Canada made an administrative error where they mislinked an account belonging to me to my wife's p…

This is more a statement of how awful Canadian banks are than anything else. For anyone unaware we have an oligopoly of five identical banks all of which treat their customers like shit and effectively extract tax from the Canadian population while providing nothing.

> while providing nothing.

You forgot about the endless frustration and annoyance.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#347

I think about this a lot when using our corporate SSO tool. When I hit the button to log into Slack, there are like, 3 popups in succession - the last one ultimately asking for my fingerprint. Then when I give it, there is a flurry of web pages that get loaded and redirects that happen until finally Slack pops up again. There isn't any realistic world in which I check each window to make sure everything is happening…

The point of passkeys is that you don't need to. Unlike passwords, your session cannot be hijacked because the thing that you give your fingerprint cryptographically verified the requester.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#348

I think about this a lot when using our corporate SSO tool. When I hit the button to log into Slack, there are like, 3 popups in succession - the last one ultimately asking for my fingerprint. Then when I give it, there is a flurry of web pages that get loaded and redirects that happen until finally Slack pops up again. There isn't any realistic world in which I check each window to make sure everything is happening…

Aren’t passkeys intrinsically resistant to those attacks? With hardware security keys, the private key remains on the device, never crosses the network, and is cryptographically bound to the site being authenticated.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#349

Earlier quoted context omitted.

How well does that Yubikey work with an iPhone?

iPhones are a lost cause.

Passkeys on my iPhone works awesome.

Too bad for Yubikey. I don't need them any more.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#350

Earlier quoted context omitted.

That is odd, I regularly use my Yubikey on multiple devices, that was the biggest draw.

The Yubikey is the "one device". But most people don't buy Yubikeys so the "one device" is, in practice, a smartphone.

Even then, unless you use one for work, where work can issue you a new one if you lose it, you're going to need (at least) two Yubikeys if you want to go that route, because not having a backup is a bad idea.
Post reply on HN