Earlier quoted context omitted.
If your threat model is "China has backdoored your TPM" then making the TPM more opaque and unauditable doesn't improve the situation. How would you know if your TPM is lying and pretending to still have the original key when actually it has a replacement Chinese one?
The actual attestation process protects against this: program generates random bytes->ask tpm to sign it->on signature return, program asks TPM for its public key->program verifies public key matches that of the signature->verify the public key is cross-signed by the manufacturer's certificate authority. The only attack here would be if Intel or AMD's PKI is compromised, which would certainly be leveraged against ent…
Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
471–480 of 525 posts
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#472Earlier quoted context omitted.
Isn't it better to have one key per device that never leaves the device?
"Security at the expense of usability comes at the expense of security." Technically yeah, device-bound keys are "more secure", but not if that results in people continuing to just use passwords instead because updating your credentials on dozens of sites every time you get a new phone or security key is too difficult. Synced WebAuthn credentials are at least as secure as a properly-used password manager, way more us…
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#473Earlier quoted context omitted.
You can use devices like Ledger that support BIP39 backup allowing you to create duplicate devices any time from a 24 word random seed. Now your one time backup covers all current and future services.
You've recommended "devices like Ledger" many times in this thread. Are there things that support this that aren't cryptocurrency wallets?
Also, BIP39, the only backup spec that exists for FIDO atm, originated in the Bitcoin community where key loss is a very expensive problem that needed an elegant solution.
BIP39 can be used to backup any type of asymmetric cryptographic key that could ever exist in a human friendly way but sadly I am not aware of any vendors implementing it outside of hardware wallets which are general purpose tools
They can be used for PGP and FIDO and password management without using them for cryptocurrency and this is totally valid.
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#474Earlier quoted context omitted.
The actual attestation process protects against this: program generates random bytes->ask tpm to sign it->on signature return, program asks TPM for its public key->program verifies public key matches that of the signature->verify the public key is cross-signed by the manufacturer's certificate authority. The only attack here would be if Intel or AMD's PKI is compromised, which would certainly be leveraged against ent…
With regard to supply-chain attacks, since the TPMs are manufactured in China, they can just make a perfectly "genuine" TPM with a valid, signed key which has their backdoor. The attestation process protects DRM users (media companies) from device owners. It doesn't protect device owners from TPM manufacturers.
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#475Earlier quoted context omitted.
> The point being, the FIDO Alliance reserves the right to blacklist any device that an attacker manages to extract the secret keys from, which has the consequence that 99,999 other people have their devices bricked. 1. By what mechanism can they blacklist a device? A given relying party can choose to use or not use attestation and, if they choose to use it, which certificates to trust. But that's between you and the…
> A given relying party can choose to use or not use attestation and, if they choose to use it, which certificates to trust. True, and a website could decide to issue its own certificates rather than get one from a CA trusted by browsers, but in practice (and potentially one day by law) most sites will defer to the FIDO Alliance to determine which devices are "sufficiently secure". > the FIDO Alliance--which is just…
That’s quite different. In your example, if a website does so unilaterally, client user agents break. In the FIDO case, nobody else knows or cares which authenticators an RP trusts.
More broadly, I don’t get this conspiracy theory. You’re worried…the FIDO alliance will abuse their very limited power to…what end?
> If the private ECDAA attestation key sk of an authenticator has been leaked, it can be revoked by adding its value to a RogueList."[1]
The attestation key, which is shared among all devices? That’s rather different from what you said.
> That specific example may never come to pass, but I don't think we should assume that allowing RPs to put arbitrary conditions on the hardware we use is a power that won't be abused.
RPs already have such power. Today they use it to do things like require password complexity policies. Again, RPs aren’t the FIDO alliance; they’re the actual website you’re logging into.
Your repeated argument here is that websites should not be allowed to impose restrictions on how their users authenticate, which is hard to fathom.
In a previous version of this argument, I remember you essentially arguing that banks and enterprises should not be able to restrict what types of authenticators their employees and customers use.
I get it. You hate attestation. But “my employees must use a fips-certified key” (or “my customers must use a hardware key”) is reasonable and ultimately non-negotiable if you want people to use your protocol.
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#476Earlier quoted context omitted.
Hmm, what opportunities? Genuinely curious what you mean here.
If you use the same public keypair across many unrelated sites, an observer could blah blah blah
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#477Earlier quoted context omitted.
I do NOT want to use my phone. It cannot be considered to be a secure device given the 'network' baseband control chipset will never be owned by the phone's buyer and has full access to the device.
The baseband CPU doesn't have full access on any decent phone.
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#478Earlier quoted context omitted.
You've recommended "devices like Ledger" many times in this thread. Are there things that support this that aren't cryptocurrency wallets?
People have made the same incorrect assumption that fido can't be backed up many times and it is a common misconception that halts adoption of the best security win since TLS. I feel important to correct this in tech circles so we start telling friends and family to setup a solution to the most common account loss problems. Also, BIP39, the only backup spec that exists for FIDO atm, originated in the Bitcoin communit…
But here's the problem: outside of the hype bubbles, cryptocurrency stuff does not have a good reputation. If the only thing that supports this markets itself as a cryptocurrency wallet, that is going to hurt adoption. People generally do not buy devices in which they actively do not want the main feature.
(I did remind myself of DiceKeys[2] while looking through my notes to find [1], but that has its own problems, such as "oh god what are you doing why does this involve OCRing a photograph of dice on my phone".)
[1] https://github.com/solokeys/solo1/blob/4.1.5/fido2/ctaphid.c...
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#479Earlier quoted context omitted.
I don't get the point... If someone steals your fingerprint, he stole your fingerprint. As I explained you can't get the fingerprint from the device\key, it is simply not there. This isn't the problem of the implementation\technology if someone stole your fingerprint. it didn't lead to your biometrics compromised What's easier to do? stealing someone's fingerprint or cracking\guessing their password. Definitely the l…
> What's easier to do? stealing someone's fingerprint or cracking\guessing their password. > Definitely the latter. You sure about that? A properly generated (i.e. random) password won't be cracked or guessed in any reasonable amount of time, whereas a model of your fingerprint(s) can be lifted from any object you've touched and used to create a silicone mold capable of fooling many fingerprint readers. And you only…
Do you even listen to what you're describing here? trailing someone, trying to extract fingerprints? this isn't a Jame Bond movie.
Cyber attacks are common because they are completely digital\anonymous by nature.
Secondly, humans can't remember\generate truly secure passwords, unique for every account they own. they usually rely on a tool like a password manager.
PM are definitely better than weak passwords but are actually weaker than biometrics. they are a central point of failure and have been attacked in the past.
For the average Joe, biometrics are more secure since he is not using such tool anyways.
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#480Earlier quoted context omitted.
I mean you don't have to give it away if you think Google is storing databases of fingerprints for the lizard masters to track you down. FIDO simply wants to make authentication stronger, you can use hardware keys that have a key burnt into them which is unique and much harder to brute-force than passwords. Again according to how biometrics are described in whitepapers\industry, we extract features from the fingerpri…
> that key cannot be reversed to get the original features "As a result, the early common belief among the biometrics community of templates irreversibility has been proven wrong. It is now an accepted fact that it is possible to reconstruct from an unprotected template a synthetic sample that matches the bona fide one." -- Reversing the irreversible: A survey on inverse biometrics https://www.sciencedirect.com/scien…