Live data from Hacker News

Passkeys now support external providers

developer.apple.com

61–70 of 185 posts

Re: Passkeys now support external providers

#61

So far, no one has commented on this large downside of passkeys: that it will promote the ease of sites to require login since it's much easier to generate a passkey than to remember a new password or even store it. Thus, passkeys lubricate the path towards an ever-increasing login-based society where it becomes much easier to track and monitor your online behaviour. Although it has the benefit of making our existing…

Each website gets a unique key. They are not signed or rooted in any trust. You can still pick any username you want for the account. What passkeys do is replace OTP and MFA. They live along SSO and do not replace it.

Re: Passkeys now support external providers

#62

So far, no one has commented on this large downside of passkeys: that it will promote the ease of sites to require login since it's much easier to generate a passkey than to remember a new password or even store it. Thus, passkeys lubricate the path towards an ever-increasing login-based society where it becomes much easier to track and monitor your online behaviour. Although it has the benefit of making our existing…

It's also a convenient workaround to synchronize information about your online-behavior, while still being able to state publicly that your browser-history is never processed to profile you. Upvoting this because it's a view worth sharing (and I'm sure you'll be downvoted just because of your baseless claim that Apple is concerned about something as dirty as profit /s)

Apple is making filthy amounts of money just from hardware and app sales.

All of their attempts at targeted advertising have been rounding errors at best.

And they know that complete unbreakable privacy is the place where Google (an ad company) can never ever fully follow no matter what kind of lip service they do in their keynotes about privacy.

Re: Passkeys now support external providers

#63

So far, no one has commented on this large downside of passkeys: that it will promote the ease of sites to require login since it's much easier to generate a passkey than to remember a new password or even store it. Thus, passkeys lubricate the path towards an ever-increasing login-based society where it becomes much easier to track and monitor your online behaviour. Although it has the benefit of making our existing…

How? you make claims that seem to have no substance. What extra vector does Passkeys add for tracking? I don't see any.

Passkeys are an origin-bound login mechanism. Worst case is that somebody places a first-party cookie to keep you logged in after you authenticated with a passkey. which they and will already do today without your consent or without logging in. (First-party session cookies don't even need a cookie wall. They're considered "necessary" processing)

Re: Passkeys now support external providers

#64
post #53

Earlier quoted context omitted.

> Why not? I do this. Again, you are not the general public. You're a highly technical person. My dad/grandma would never. That's the point.

Are you saying they don't use any physical keys? That would be surprising to me... I've found it really easy to teach non-technical people how to use U2F tokens. Just tell them it's like a door key but instead of plugging it in and turning, you plug it in and touch. That's all there is. It's been much more intuitive* to my older family members than SMS codes (that sometimes get lost), authenticator apps (that have a…

The difference is that I can know with significant certainty that shoving my house key in a random lock won't copy the form of my key and send it to a 3D printer where a thief will get it and use it to access my house.

How can I know that won't happen when I use my USB dongle on a random coffee shop public computer?

Re: Passkeys now support external providers

#65

So far, no one has commented on this large downside of passkeys: that it will promote the ease of sites to require login since it's much easier to generate a passkey than to remember a new password or even store it. Thus, passkeys lubricate the path towards an ever-increasing login-based society where it becomes much easier to track and monitor your online behaviour. Although it has the benefit of making our existing…

It's also a convenient workaround to synchronize information about your online-behavior, while still being able to state publicly that your browser-history is never processed to profile you. Upvoting this because it's a view worth sharing (and I'm sure you'll be downvoted just because of your baseless claim that Apple is concerned about something as dirty as profit /s)

Passkeys are stored in your encrypted iCloud keychain. Apple doesn't see or process what websites you're logged into on their servers.

Re: Passkeys now support external providers

#66

So far, no one has commented on this large downside of passkeys: that it will promote the ease of sites to require login since it's much easier to generate a passkey than to remember a new password or even store it. Thus, passkeys lubricate the path towards an ever-increasing login-based society where it becomes much easier to track and monitor your online behaviour. Although it has the benefit of making our existing…

> passkeys lubricate the path towards an ever-increasing login-based society where it becomes much easier to track and monitor your online behaviour

This trend is already in motion thanks to the deprecation of 3rd party cookies and Apple's restriction of device identifiers, etc, on iOS.

For most advertisers these days, the only way to run retargeting campaigns or measure conversions is with 1st party data. That means people are no longer relying on cookies at all for much of their conversion tracking. Instead, email addresses are used.

This is (I think) an unintended side effect of stripping away cookies.

At least with cookies, you could delete them locally. But now so much tracking is done with first party data, cookies are playing much less of a role. And of course there's not an easy "delete all first party data" button in your browser because the data is (obviously) held outside the browser.

Re: Passkeys now support external providers

#67

So far, no one has commented on this large downside of passkeys: that it will promote the ease of sites to require login since it's much easier to generate a passkey than to remember a new password or even store it. Thus, passkeys lubricate the path towards an ever-increasing login-based society where it becomes much easier to track and monitor your online behaviour. Although it has the benefit of making our existing…

It's a thought provoking angle you have here for sure. However, am I right that the implication of this direction of thinking is that we should stay with our current ways of doing authentication simply because them being too hard to use puts up a natural barrier? That some of the ways in which they are broken are intrinsically good?

Re: Passkeys now support external providers

#68

So far, no one has commented on this large downside of passkeys: that it will promote the ease of sites to require login since it's much easier to generate a passkey than to remember a new password or even store it. Thus, passkeys lubricate the path towards an ever-increasing login-based society where it becomes much easier to track and monitor your online behaviour. Although it has the benefit of making our existing…

How? you make claims that seem to have no substance. What extra vector does Passkeys add for tracking? I don't see any. Passkeys are an origin-bound login mechanism. Worst case is that somebody places a first-party cookie to keep you logged in after you authenticated with a passkey. which they and will already do today without your consent or without logging in. (First-party session cookies don't even need a cookie w…

If it is easier to do something, more websites will do it. Passkeys make it easier to make new logins, so more websites will do it. Just like seatbelts make people drive more dangerously.

If more websites require logins, they can track you more easily, simple as that. It has nothing to do with the engineering aspects of passkeys, and everything to do with the fact that technology which makes logins easier will encourage more login-based services.

You need to step away from the engineering details and look at things sociologically.

Re: Passkeys now support external providers

#69
post #57

Earlier quoted context omitted.

account recovery process

Just chiming in to ask -- the immediate need for account recovery is in cases with lost or forgotten passwords. Am I right in assuming that account recovery becomes a much smaller attack surface when using passkeys? Or are there scenarios I'm overlooking?

It’s mostly how sites will likely still allow full account recovery with just sms-based authentication, making account recovery the weakest link. It’s still required, though, in case someone e.g. signs up with a passkey on their Windows desktop then forgot to enroll one on their phone before taking a vacation.

Re: Passkeys now support external providers

#70

So far, no one has commented on this large downside of passkeys: that it will promote the ease of sites to require login since it's much easier to generate a passkey than to remember a new password or even store it. Thus, passkeys lubricate the path towards an ever-increasing login-based society where it becomes much easier to track and monitor your online behaviour. Although it has the benefit of making our existing…

> So far, no one has commented on this large downside of passkeys: that it will promote the ease of sites to require login since it's much easier to generate a passkey than to remember a new password or even store it. Actually, this ease of use may be beneficial to privacy. Sites don’t need user generated/remembered passwords to require a login, they can just use the sign in with Google/Facebook/Apple buttons. Becaus…

You are ignoring the other side of the equation: more sites with logins.
Post reply on HN