Live data from Hacker News

Passkeys now support external providers

developer.apple.com

51–60 of 185 posts

Re: Passkeys now support external providers

#51
post #40

Earlier quoted context omitted.

> Safe from server leaks. Because servers only keep public keys, servers are less valuable targets for hackers. It's still an attack scenario to keep in mind. If a server can be tricked into storing the wrong public key, authentication is defeated.

And how might this happen?

account recovery process

Re: Passkeys now support external providers

#52
So far, no one has commented on this large downside of passkeys: that it will promote the ease of sites to require login since it's much easier to generate a passkey than to remember a new password or even store it.

Thus, passkeys lubricate the path towards an ever-increasing login-based society where it becomes much easier to track and monitor your online behaviour. Although it has the benefit of making our existing lives easier by removing the need to remember our banking passwords, it also will bring us further into the realm of technology by making more and more services log-in based.

A greater ease of making a log-in based service means more revenue, more profit for Apple, and a greater integration of technology into our lives. Few people realize this because we have been conditioned to believe that new technology is solely for our benefit.

In reality, Apple is not concerned with our benefit. They are concerned with profit and making technology more efficient to accomplish that end. So although passkeys might seem nice, there is a serious downside to this technology.

Re: Passkeys now support external providers

#53
post #48

Earlier quoted context omitted.

> who the heck would carry a USB key with them?? Why not? I do this. It's no different from any other physical key like a door key, and I keep it on the same keychain too... > The passkey is usable anywhere (signed up on my desktop, hopped over to my laptop and signed in there with the same passkey). I don't see how this conflicts with physical tokens like Yubikeys? The tokens help you "remember" the key like how a p…

> Why not? I do this. Again, you are not the general public. You're a highly technical person. My dad/grandma would never. That's the point.

Are you saying they don't use any physical keys? That would be surprising to me...

I've found it really easy to teach non-technical people how to use U2F tokens. Just tell them it's like a door key but instead of plugging it in and turning, you plug it in and touch. That's all there is. It's been much more intuitive* to my older family members than SMS codes (that sometimes get lost), authenticator apps (that have a huge list of services from which you need to quickly find the one you want and type the code), or password managers (that either cost money or are difficult to set up across devices).

*: I know this because I've never had to do "tech support" for family members that have accounts set up to use U2F tokens, but I have had plenty of calls related to "not getting the SMS code" or "the (insert brand) password manager isn't filling in the password for my account!"

Re: Passkeys now support external providers

#54

I'm totally in if passkeys come without middle men, especially like Google and Apple. Otherwise I'm totally out. No trust in these guys, they are as capricious as Roman emperors and will eventually do their usual stuff: lock in and collusion.

I've got a big problem with the attestation feature even existing in the spec. I know Apple plans to "zero it out" but if that changed sites could lock out non approved devices. I'd vastly prefer it wasn't part of the spec at all rather than relying upon the whims of a single megacorporation. If they ever drop that cover things will gradually become defacto locked to middlemen anyway.

Re: Passkeys now support external providers

#55

So far, no one has commented on this large downside of passkeys: that it will promote the ease of sites to require login since it's much easier to generate a passkey than to remember a new password or even store it. Thus, passkeys lubricate the path towards an ever-increasing login-based society where it becomes much easier to track and monitor your online behaviour. Although it has the benefit of making our existing…

It's also a convenient workaround to synchronize information about your online-behavior, while still being able to state publicly that your browser-history is never processed to profile you.

Upvoting this because it's a view worth sharing (and I'm sure you'll be downvoted just because of your baseless claim that Apple is concerned about something as dirty as profit /s)

Re: Passkeys now support external providers

#56

My method for judging the quality of software: Read the latest release notes, negate every statement, and think to yourself: "They were fine with it being like this until now." Passkeys have been advertised as a superior replacement to passwords, but really fundamental issues remain unaddressed. I have one (1) Windows PC and one (1) iDevice. Can I get these to sync? Will both be able to log me in to a Google Account?…

> I have one (1) Windows PC and one (1) iDevice. Can I get these to sync?

"Why? Where's the profit for us in that case?"

Re: Passkeys now support external providers

#57

Earlier quoted context omitted.

And how might this happen?

account recovery process

Just chiming in to ask -- the immediate need for account recovery is in cases with lost or forgotten passwords. Am I right in assuming that account recovery becomes a much smaller attack surface when using passkeys? Or are there scenarios I'm overlooking?

Re: Passkeys now support external providers

#58
post #40

Of all the recent publications with regards to passkeys, FIDO2, WebAuthn, etc., finally there's one with a simple and concise summary of the benefits: > Strong credentials. Every passkey is strong. They’re never guessable, reused, or weak. > Safe from server leaks. Because servers only keep public keys, servers are less valuable targets for hackers. > Safe from phishing. Passkeys are intrinsically linked with the app…

> Safe from server leaks. Because servers only keep public keys, servers are less valuable targets for hackers. It's still an attack scenario to keep in mind. If a server can be tricked into storing the wrong public key, authentication is defeated.

The point is that a hacker can’t use the public keys obtained in a data breach to access your accounts on other services. This is a common problem when a lot of people use the same email and password for many different sites.

Re: Passkeys now support external providers

#59
post #3

This is a smart move by Apple. Authentication infrastructure is necessarily cross platform. It doesn’t generate revenue for Apple, but the lack of cross platform auth would limit enterprise adoption of Apple products.

> It doesn’t generate revenue for Apple, but it creates lock-in, if all your credentials are in a iCloud keychain, you're encouraged to get a phone that can sync with your ipad, laptop, and desktop. Manually find and re-sync your stuff from firefox-on-desktop to chrome-on-mobile to safari-on-ipad is a major PITA.

And it creates nicely labeled and synchronized information of when and how often a user logged into a eCommerce service/Streaming portal/..., while still being able to state that your browser history is never processed for profiling...

Re: Passkeys now support external providers

#60

So far, no one has commented on this large downside of passkeys: that it will promote the ease of sites to require login since it's much easier to generate a passkey than to remember a new password or even store it. Thus, passkeys lubricate the path towards an ever-increasing login-based society where it becomes much easier to track and monitor your online behaviour. Although it has the benefit of making our existing…

> So far, no one has commented on this large downside of passkeys: that it will promote the ease of sites to require login since it's much easier to generate a passkey than to remember a new password or even store it.

Actually, this ease of use may be beneficial to privacy. Sites don’t need user generated/remembered passwords to require a login, they can just use the sign in with Google/Facebook/Apple buttons. Because it is easier than remembering another password, users will typically use those options. Passkeys is more private than signing in with Google/Facebook/Apple, while also providing more privacy than those options.

Post reply on HN