Live data from Hacker News

Using FIDO keys

777.tf

51–60 of 65 posts

Re: Using FIDO keys

#51
post #6

I use an old Google Titan key, not the bluetooth model but the regular one, as my backup (it was my primary) and a Yubikey 5 for my primary. I like the peace of mind that they give me that no one can steal my password and login to my important accounts, but I found that certain providers only allow a single 2FA to be used, with no backup, so I don't feel good using them there (AWS, what the F?) and also I find that n…

You don't mention which country and thus which government. Some US government sites do accept WebAuthn, and for at least some UK sites it's possible via a third party.

Banks though, yeah they aren't good at this stuff. My safe† bank decided one day to completely up-end how logins work and almost locked me out. My good bank provide a very stupid, proprietary solution but at least it's an actual secure solution.

† Safe in that they're owned by the government, so, if they go bankrupt I have worse problems because now I live in a failed state. Big piles money of money sit in this bank because it's safe, but it's run by clowns who don't understand customer service.

Re: Using FIDO keys

#52
I do use multiple keys and I like them a lot, but there is a big Issue I don't see mentioned a lot: you can't solo it on most services:

- Google forces you to also keep their stupid "verify on another device", where you can't even untrust specific devices without fully logging out - proton apps don't support fido auth - microsoft account only allows it on edge and afaik not at all on linux - and so on..

I think the only service where I can fully disable other 2FA channels is github.

Edit: a word

Re: Using FIDO keys

#53

My colleague and I recently gave a workshop about security keys where we tried to answer questions like: * Why should I use a security key? * What is it used for? * How can I choose one ? * What features should I look for? We did cover FIDO2/Passkeys but also multiple other use cases. Here are the slides if you're interested: https://tome.one/slides/amiet-pelissier-security-keys-worksh...

Very useful! Thanks!

Re: Using FIDO keys

#54
post #9

Earlier quoted context omitted.

Given how the project is going, not even sure if there will be a V3 at some point.

That's actually what gives me confidence. All the hardware manufacturing problems almost ensure a v3 will be designed.

I meant more the lack up updates and communication doesn't really paints a bright future for Solokeys.

Re: Using FIDO keys

#55
post #24
post #18

As much as I want a hardware key, I still struggle with the practicality of having a backup key. I create new accounts on websites quite often, and the idea of having to go fetch my backup key out of a safe to register it (and hope the site allows multiple keys) just feels impractical (“I’ll do it tomorrow”). Not to mention—what if I’m at work, or out and about setting it up on my phone? Am I really going to remember…

What do you imagine a solution here might look like? I don’t know enough about the problem space to truly know, but I feel like I’ve seen versions of this: I can authorize any arbitrary public key for use over SSH, for example; and (based on my memory of YubiOTP) it’s seemed like at least some of these hardware auth protocols work based on using an open serial number or public key to identify the authorized authentic…

I wonder if the actual desire is to be able to buy a set of cloned keys. I.e. instead of having each key be unique, be able to buy a set of N keys with identical private key. Or the ability to create such a set yourself with a special initialization sequence. This would give you your high-availability backup, but means you cannot revoke the first key if lost. So it seems like you'd really have to trust the other hardware protections and PIN/lock features if misuse of a lost/stolen key is a concern.

Periodically, I try to think if there is some other expected UX you might want that is somehow neither cloned nor independent keys. Like some hybrid of secret-sharing and group key schemes. Have a set of N keys which know about each other and can act individually to authenticate for the same identities, including for new identities enrolled by any key in the group, as in the case of a cloned key. But, include some capability for k out of N keys to "vote out" a member from the group in order to revoke the lost key and prevent it from authenticating any of the identities in the future.

I am not a cryptologist, but I can't really imagine any crypto mechanism to actually produce this combination of effects. A fully distributed group registration and authentication effect during normal use, so enrollment via one key can be followed by authentication using another. But at the same time, allowing ejection a member from the group to prevent future misuse. I can only imagine this as a protocol, where every authentication for the group would have to consult some centralized ledger or revocation list for the group membership. It could be decentralized/federated in a sense, but would require some kind of online check with the "latest" ledger state for a given key group.

Re: Using FIDO keys

#56
post #30

Am i the only one concerned about the tendency of putting your identity on hardware you possibly do not own? What a wet dream for the internet controlling fascists when the adoption of "just wield your smart phone" auth would be in place and mandated every where. Nothing compares to the secrecy of passwords.

My identity is already on hardware I don't own, my government ID card. What do you foresee the risks being, and why are these risks only possible with secure authentication?

Your government id card is not widely adopted as method of authentification, i guess. This is where this new pass key approach comes in. My concern is, that this new method might completely replace old fashioned passwords. And once every one is used to have a hardware token, the next step of only accepting or selling government approved devices is a small one. This could could ultimately make anonymity impossible. Because you dont control the hardware or the spec.

Imagine being required to have and use your govID for simply everything, because there is no alternative.

This is not a risk of secure authentification, which passwords can also provide.

$Corps loved to harvest phone numbers as a second factor despite a second fall back email address would be at least as secure as SS7 communication. But phone numbers are tied more strongly to your identity so more valuable for the data brokers.

This is the same thing actually. Tieing identity to something you have and not something you alone know. Something external.

Having a single external dependency for all your identities sounds like a good idea to you? For facists and data brokers it certainly does.

To me, this is an attack on anonymity and i know that i sound paranoid. Lets wait for the enshitening.

Re: Using FIDO keys

#57
post #30

Earlier quoted context omitted.

My identity is already on hardware I don't own, my government ID card. What do you foresee the risks being, and why are these risks only possible with secure authentication?

Your government id card is not widely adopted as method of authentification, i guess. This is where this new pass key approach comes in. My concern is, that this new method might completely replace old fashioned passwords. And once every one is used to have a hardware token, the next step of only accepting or selling government approved devices is a small one. This could could ultimately make anonymity impossible. Be…

You DON’T have to trust any company or government for passwordless authentication. Don’t want to use your phone? Use a hardware key instead. Don’t want to use a hardware key? Use an open source solution like Bitwarden (and it’s not the only one).

At this point, you’re just making shit up about something you don’t understand.

Re: Using FIDO keys

#58
post #57

Earlier quoted context omitted.

Your government id card is not widely adopted as method of authentification, i guess. This is where this new pass key approach comes in. My concern is, that this new method might completely replace old fashioned passwords. And once every one is used to have a hardware token, the next step of only accepting or selling government approved devices is a small one. This could could ultimately make anonymity impossible. Be…

You DON’T have to trust any company or government for passwordless authentication. Don’t want to use your phone? Use a hardware key instead. Don’t want to use a hardware key? Use an open source solution like Bitwarden (and it’s not the only one). At this point, you’re just making shit up about something you don’t understand.

You havent understood my point.

> Nothing compares to the secrecy of password.

Because they are soley internal to you.

Yes, you can generate passkeys at will ... and then you give them away to a usb dongle or HSM, from which some day you might not be able to export them, because vendors love their locked in customers.

I am talking about control and yes, my concerns are speculation but reasonable to me, when you look at pretty much all the recent development. From not-WEI over DRM, to right to repair and on and on.

Re: Using FIDO keys

#59
post #15

This space is confusing. FIDO2, U2F, UAF, CTAP, WebAuth, Passkey, 2FA, … The names frequently change. Aren’t all of them just public key authentication (with the private key in a mini-HSM, and public key either calculated in real-time, or stored, in the HSM, and synced externally)?

Passkeys are the opposite of "private key in a mini-HSM" in that they're synced to a cloud provider.

The goals of this whole thing have shifted, and it's hard to keep track of what was aiming at what goal. It started out as "actually secure 2FA" and now we're at "cloud-synced unphishable password replacements for non-technical users".

Re: Using FIDO keys

#60
post #57

Earlier quoted context omitted.

Your government id card is not widely adopted as method of authentification, i guess. This is where this new pass key approach comes in. My concern is, that this new method might completely replace old fashioned passwords. And once every one is used to have a hardware token, the next step of only accepting or selling government approved devices is a small one. This could could ultimately make anonymity impossible. Be…

You DON’T have to trust any company or government for passwordless authentication. Don’t want to use your phone? Use a hardware key instead. Don’t want to use a hardware key? Use an open source solution like Bitwarden (and it’s not the only one). At this point, you’re just making shit up about something you don’t understand.

> Don’t want to use your phone? Use a hardware key instead. Don’t want to use a hardware key? Use an open source solution like Bitwarden (and it’s not the only one).

You're ignoring the fact that WebAuthn can require attestation, which will remove device choice from the equation.

Post reply on HN