Live data from Hacker News

Passkeys will come at a cost

fy.blackhats.net.au

581–590 of 600 posts

Re: Passkeys will come at a cost

#581
post #263

Earlier quoted context omitted.

> Losing your 2nd factor shouldn't block you from accessing your accounts indefinitely. You’re absolutely right and also you don’t have to worry. Everyone who operate auth of any sort will be forced on day one to have reasonable recovery. Nobody is gonna lock customers out because you lost their super-secret private key. In practice, it goes back to email recovery for 98% of services. This will remain true with passk…

> In practice, it goes back to email recovery for 98% of services. This will remain true with passkeys. My understanding is that passkeys are really intended for the non-technically-skilled users. So then, how will passkeys succeed with that audience? A high percentage of them already routinely use password recovery mechanisms rather than keeping track of their passwords. That's an established habit. If they can keep…

Yeah. They’d only switch if it’s discoverable and easy, (perhaps their browser + the website presents the option).

Also, the “forget password” flow itself has opportunities for happy-path improvements that are much more simple than passkeys. I have thought for a long time we should embrace that and lean into it, perhaps change it to a better “magic link” type of flow.

Re: Passkeys will come at a cost

#582
post #235

This is a bit unrelated to the harder crypto stuff but my mom called me freaking out she couldn’t get into her gmail. It turns out Google auto registered her new android phone with a passkey and made that the default Google login with a confusing passkey based interface (expecting her to know to click the second option to login via password or understand wtf a passkey is was too much IMO). It turns out when it said “…

Yep, this is how Comcast is for me. I never get the notification for the "registered device" even though it's a newish popular phone. I don't trust passkey because It relies on a certain device, instead of something you can just write down or save to a browser use on multiple devices.

If I lose my phone, I can't get into my email to do anything else.

Re: Passkeys will come at a cost

#583
post #73

Any form of authentication based on "something you have, but can also lose" is fundamentally broken. Either I'll lose access if I lose the device, or their superior security doesn't matter because the weakest link has to be somewhere else.

Wouldn't this include passwords? People lose those all the time.

The proof will be in the pudding, but I suspect that widespread adoption of passkeys will make account lockout less common, rather than more, for the vast majority of people.

Re: Passkeys will come at a cost

#584
post #291

Earlier quoted context omitted.

Maybe not for us, but for the vast majority of users, they'd pick not having to remember a username OR password for sure.

It’s also make pickpocketing a lot more lucrative if you can grab someone’s wallet and have immediate access to their bank account.

I had never considered this. Somewhat terrifying IF no biometric/pw attached. I expect most people will store on phone, thus it won’t be a huge issue.

Re: Passkeys will come at a cost

#585
post #263

Earlier quoted context omitted.

> Losing your 2nd factor shouldn't block you from accessing your accounts indefinitely. You’re absolutely right and also you don’t have to worry. Everyone who operate auth of any sort will be forced on day one to have reasonable recovery. Nobody is gonna lock customers out because you lost their super-secret private key. In practice, it goes back to email recovery for 98% of services. This will remain true with passk…

>I’m also a little worried about public computers, shared devices, borrowing etc. Not everyone has a personal $1000 phone. This whole “my own device” assumption is a first world bias, and the experts should know better. Exactly. That's why I'm in favour of SMS based auth for really important services like banking and government services. Your phone got broken/lost? Most providers offer replacement sims immediately or…

SMS is monumentally insecure and any suggestion to use it as an auth factor (much less a recovery mechanism) is wildly irresponsible. Not only is SIM swapping as easy as convincing the teenager at your local phone store that you lost your phone and want to pay his commission when buying a new one, but the SMS protocol itself is unencrypted and you can MITM, or just straight up spoof it with a few grand worth of equipment (see "stingrays" for the professional version of this). This _abolutely_ happens all the time in the EU too.

Re: Passkeys will come at a cost

#586

Earlier quoted context omitted.

Is it ? Looking at this for instance, we're still around 1 USD per GB for a reliable storage chip: https://www.amazon.com/Kingston-Industrial-32GB-microSDHC-Ad...

How much space does a key take though?

Enough that it's an issue when you want to store them in a highly secure way ?

I doubt that the yubico limited the number of useable keys and space available per protocol by sheer spite or trying to upsell larger "pro" versions that they never made. Using more space for encryption and other mechanism is probably a part of this, then it depends on how they allocate space (segmenting by category of data would totally be plausible for instance)

Re: Passkeys will come at a cost

#587

Earlier quoted context omitted.

No, the idea is to turn _every_ device into your passkey, and also at least one cloud provider of your choice.

And for those of us who choose no cloud providers at all?

There's an API for passkeys managers. I'm sure you'll figure something out that matches your criteria.

Re: Passkeys will come at a cost

#588
post #17
post #2

That's a rather uncharitable take on the situation. I'll propose an alternative: If you want to take advantage of the new auth standard that will eliminate weak passwords and password reuse (thereby preventing 99% of casual account break-ins), you'll have to spend $30 to upgrade off the legacy yubikey you've been coasting on since 2013.

Why should I be forced to upgrade? Non-resident keys also eliminate weak passwords and password reuse. Using resident keys only add marginal improvement (ie. you can plug in a key and the service knows which account it belongs to), and that doesn't seem like a good justification to deprecate all the existing authenticators in use today.

The number of existing old yubikeys is absolutely miniscule compared to the number of people who aren't using any keys yet.

Re: Passkeys will come at a cost

#589

Earlier quoted context omitted.

The same is true for physical keys for cars, houses, lockers, etc., which is why people have an intuition to test out keys to make sure that they work.

Most people aren't going to do that for the standby keys. And while they test out the real keys, they mostly don't go from working to not working because someone did a garbage collection/unused keys pass or failed to update some field or deleted something on a server.

Yup. Instead they stop working because of rust, corrosion, wear & tear, or heat distortion from improper storage...

There seems to be an obsession that if a digital key doesn't comprehensively solve all problems, it's terrible, despite the empirical evidence that people are fully capable of using physical keys despite their limitations.

Re: Passkeys will come at a cost

#590

Earlier quoted context omitted.

I mean, if you're using a key to get in to countless physical things, then you have the same problem.

Do you have countless homes?

I do not.

None of the locks for my home are on a network where you can broadcast key updates either.

I also tend not to have one key that can access my house, my car, my safety deposit box, my safe, my bike, my locker, etc.

Post reply on HN