Live data from Hacker News

Passkeys were invented by engineers with zero understanding of consumer brain

twitter.com

541–550 of 813 posts

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#541
post #491

Earlier quoted context omitted.

You generate another passkey is your answer. How do you do that? The exact same way you do today. Why would you need to delete invalid passkeys? You wouldn't.

> You generate another passkey is your answer. How do you do that? The exact same way you do today. How can I do that, if Passkeys are the only option to log in? If I can just use a password to log into a website without Passkeys, then Passkey is useless and doesn't add any security benefit. > Why would you need to delete invalid passkeys? You wouldn't. I sell my old (and no longer updated) phone or PC and don't want…

> How can I do that, if Passkeys are the only option to log in?

It is not feasible to remove password login or some other recovery login method.

> If I can just use a password to log into a website without Passkeys, then Passkey is useless and doesn't add any security benefit.

It isn’t useless, point is you don’t get to type in your password on a device that has passkey generated already, or get phished on a fake web address for example.

> I sell my old (and no longer updated) phone or PC and don't want someone to get access to my account by getting access to the secret keys.

Passkeys are meant to be protected by either PIN or biometrics, however they are also meant to be revocable on the web, at least they are for services i’ve been using with passkeys.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#542
post #524

Earlier quoted context omitted.

> It seems like everyone wants to be _the_ password manager for all your passkeys. Which defeats part of the point of passkeys in the first place in that they are supposed to be device-bound, the private key held in the TPM or secure enclave or whatever other security chip, mathematically non-exportable. Storing all your private keys in a cloud vault still leaves you exposed to potential credential theft if your vaul…

In the Apple ecosystem, passkeys are stored in your iCloud, and access to the passkeys is device bound. So if I generate a passkey on a MacBook, I can then use it from my iPhone as well, because it's encrypted to all my hardware devices.

Replace the word passkey with password in your comment. What’s the benefit of passkeys again?

If you’re not storing the actual private key in the Secure Enclave but only the “access to it” what’s changed from how Apple’s keychain already manages password syncing to iCloud?

The only benefit (and it’s still a decent one) is that some random website breach can’t disclose your private key.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#543
post #341

Earlier quoted context omitted.

sadly it seems like most of the banks I use still enforce antiquated password rules, no MFA and rely on stupid questions most of which can easily be guessed from public records.

Just the other day I was creating an ID on a government web site, which offered a list of security questions such as "Title of your favorite movie" or "Someone that you admired as a child" and the answer was not allowed to have any spaces. Just absurd.

Security questions have always been ridiculous, but I'll especially never understand how "favorite [thing]" ever made it to production anywhere. "Favorite movie" can change multiple times in the same conversation.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#544

Earlier quoted context omitted.

> This is much, much simpler than you think it is. Passkeys are just passwords that require a password manager. This is not true. There are device bound passkeys where the private key is stored in a HSM (TPM2.0, Android SE, or apple SE) instead of a hosted service (iCloud, Bitwarden.com). You can just add multiple Passkeys to a single site to have another backup device should your other one be unavailable.

Speaking about hardware tokens: If I have to go get the backup out of "secure" storage each time I want to add a new Passkey it's not really a backup. The design should have allowed, even if it was just within only the purview of a single manufacturer, a method for the device to export an encrypted dump that could be reloaded onto a factory-new device. Heck, make it a value-added service that the manufacturer has to…

> If I have to go get the backup out of "secure" storage each time I want to add a new Passkey it's not really a backup.

Yes.

> even if it was just within only the purview of a single manufacturer

> Heck, make it a value-added service that the manufacturer has to initiate and tie it to some real-world identity verification.

No.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#545

Earlier quoted context omitted.

This is much, much simpler than you think it is. Passkeys are just passwords that require a password manager. If you lose your passkey, you'll reset your passkey the same way you reset your password, probably with a "forgot my password" email. (But you're not going to lose it, because you use a password manager, and the passkey will be stored there and synchronized to all of your other devices.) The weird part is tha…

I love that you wrote 6 paragraphs and linked to a medium post all without actually answering the question posed by the comment you replied to.

Yes, I did. When you set up a passkey on your phone in your password manager, you'll transfer it to your other device using your password manager.

Either your password manager will automatically synchronize for you, or you can transfer your passkey to another password manager that will do the synchronization, via the finicky app-to-app transfer system (Credential Exchange Protocol). You can transfer from Apple to Bitwarden and vice versa.

The family sharing question was added later, but the answer is: all of the major password managers have finicky family-sharing features for passwords and passkeys.

For passwords, most people don't bother with formal family-sharing features, and just share passwords via copy and paste. For passkeys, you have to use the family-sharing features, which means you and your family member have to use the same password-manager vendor to share those passkeys.

It’s up to you to decide whether protecting yourself from being tricked into exporting your passkeys is worth sacrificing your ability to read them.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#546
post #262

Earlier quoted context omitted.

> there's no a clear explanation there's. it depends on how the site implemented passkeys. I'm using multiple devices and passkeys via keepassXC. I haven't lost access or even got locked out of any accounts. but it's like 2FA, and almost all sites have a clean fallback (backup codes) for 2FA.

How do you sync the KeePassXC file?

I use KeePassXC, just not for passkeys. I used to use Dropbox but now I use Syncthing. I use a strong password and a key file that IS NOT synced.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#547
post #369

Earlier quoted context omitted.

Ok but now do a service that doesn't support that, whether or not it might in the future 'become a pretty common pattern'.

On most websites logging in through QR codes works out of the box for passkeys. You usually click "log in with device" or something like that with every desktop OS. You scan the QR code, click the confirmation button, and you're signed in. It's part of the standard UI of normal operating systems. Might not work (well) if you're on an old computer without decent Bluetooth but everything has Bluetooth these days.

Why does a passkey need bluetooth? For what? Isn't that another vulnerability?

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#548

I’m absolutely floored by some of what I am reading here. Six months before passkeys rolled out there were numerous succinct consumer-friendly write-ups. I sent at least one of these to several non-technical people I knew and they had no problem understanding the benefit and moving to using them where available once they started rolling out.

Would be helpful if you provided at least 1 example

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#549
post #8

I do not know how to use a Passkey in a way that won’t impede how I log in to systems. I’ve been in tech for 26 years, and I understand the Public/private key behind what a Passkey is. Here’s what I don’t understand: I access a website through at least four different devices (my iPad, iPhone, Windows Desktop computer, and MacBook Pro) and three different browsers on each device (Brave, Firefox, Safari) , and I use La…

> and I use LastPass

Oh! No. Please switch to something else. Last pass has had so many breaches, at this point it’s just not worth it.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#550

Okay, I'm a tech nerd I admit it, but for my personal authentication life I find passkeys to make sense. All my passwords and SSH key are already in Bitwarden. When a site starts supporting passkeys, I add that to Bitwarden as well. Now, instead of logging in by auto-filling my username and password, I just press the passkey login button (that hopefully exists) and click on the Bitwarden popup to select the account.…

So what do you use for TOTP? Also bitwarden?
Post reply on HN