Live data from Hacker News

Passkeys: A shattered dream

fy.blackhats.net.au

651–660 of 789 posts

Re: Passkeys: A shattered dream

#651

Earlier quoted context omitted.

Edit: everything I say below is not just wrong, but confidently wrong... "Communicate over bluetooth" doesn't mean anything. What app or BT device would they be using? How would a PC communicate with a YubiKey over bluetooth? I have no idea where you got this strange concept from, but registering multiple passkeys from multiple devices on the same account on a site requires no communication between the devices - it o…

That's how it works. You open Google Chrome on Linux, press "Log in with PassKey", scan QR with iPhone, then iPhone contacts Google Chrome via bluetooth to do its crypto magic (which doesn't work 50% of times) and may be it'll work. No idea how Yubikey works, never used it.

Wow, I stand corrected, sorry. This seems entirely absurd, so much extra complexity is crazy.

Re: Passkeys: A shattered dream

#652
post #196

Earlier quoted context omitted.

You can always use passkeys like Yubikey or others which are much more multi-platform.

This isn't a viable option in practice, because Passkeys use "Resident Keys". This means the credential needs to be stored on the Yubikey - which has a limited number of key slots. Need to log in to more than 25 (I believe) websites? Tough luck!

Use a better token. YubiKey is the most popular one, not the best one by a long shot. My (cheaper) alternative supports 300 resident keys per each hardware key.

Re: Passkeys: A shattered dream

#653
post #196

Earlier quoted context omitted.

This isn't a viable option in practice, because Passkeys use "Resident Keys". This means the credential needs to be stored on the Yubikey - which has a limited number of key slots. Need to log in to more than 25 (I believe) websites? Tough luck!

Use a better token. YubiKey is the most popular one, not the best one by a long shot. My (cheaper) alternative supports 300 resident keys per each hardware key.

What do you use?

Re: Passkeys: A shattered dream

#654

Earlier quoted context omitted.

1Password is a closed-source, cloud-hosted service. At any time, for any reason, they can close and delete your account, leaving you high and dry. Self-hosted, multi-device password managers are the only real solution. Thankfully, Vaultwarden and KeePassXC fill this role perfectly. Now if we could just get the other providers that require insecure email/SMS 2FA to follow suit, that would be great...

I wonder if BitWarden doesn't support passkeys too. BitWarden is open source to a large degree and even provides an (open source) server for self-hosting.

It does, works great. Not sure about vaultwarden's support for it though.

Re: Passkeys: A shattered dream

#655

Earlier quoted context omitted.

I'm curious as to why the number of slots is so small. Surely this is not some kind of fundamental limitation on what's possible (or cheap) with hardware?

Because yubikeys were designed long before passkeys become a thing. And hardware people love cutting cost to the bare bone to save one cent of $50 device.

That's the thing, though - did it save even one cent? How much more would it have cost to have 10x slots? 100x?

Re: Passkeys: A shattered dream

#656
Authentication has become incredibly complicated for normal users.

I work in cybersecurity and need to think hard and draw diagrams to understand how modern authentication systems work (modern = something more than passwords). The implementation part is hidden from users but they only understand "password". Sometimes "fingerprint". Anything above that is really tough.

While Passkeys are an interesting development, it will take time before they are part of the authentication routine of standard users.

Re: Passkeys: A shattered dream

#657

Earlier quoted context omitted.

Agreed. I self hosted the key 100 bitcoin in like 2010. Machine crashed. Oops.

That's a fundamental problem with cryptographic security: you cannot trust people to manage your keys for you (because due to lack of regulation preventing that companies have this bad habit of pulling the rug under their customers' feet) but you cannot trust yourself doing that either, because you can, and will, make mistakes.

I've always wanted a decentralized solution that lets me trust my friends instead.

Re: Passkeys: A shattered dream

#658

Earlier quoted context omitted.

Agreed. I self hosted the key 100 bitcoin in like 2010. Machine crashed. Oops.

That's a fundamental problem with cryptographic security: you cannot trust people to manage your keys for you (because due to lack of regulation preventing that companies have this bad habit of pulling the rug under their customers' feet) but you cannot trust yourself doing that either, because you can, and will, make mistakes.

My rule of thumb is if for some reason you need to use crypto keys that can't be easily replaced, you need to have a safe at the bank with the keys stored in 2 differente media formats, that are recreated every year.

I don't trust many people to do that.

I have everything encrypted and self hosted and I sometimes wonder what I would do if I was suffering from amnesia after an accident for example. And having a note somewhere telling me I have a safe in bank X is the only solution I have found.

Re: Passkeys: A shattered dream

#659
post #623

Earlier quoted context omitted.

Then don’t change phone OS, or put your passkeys in a third party password manager.

Or... use passwords and 2FA which we have been using forever and for years respectively.

Why is that better? It's the same thing as a passkey managwer, but twice the work.

Re: Passkeys: A shattered dream

#660

Earlier quoted context omitted.

You are able to share an Apple passkey to any nearby Apple device at any time using AirDrop. Passkeys can also be used cross-platform during sign in via an NFC/Bluetooth handshake initiated by QR code. Additionally, passkeys are just a synced-via-cloud implementation of FIDO2, an open standard that has other implementations you may feel more comfortable using. For someone who requires being able to sign in to, say, G…

But what happens if I as an iPhone user want to switch to Android next year? Can I move my Apple passkeys?

"We do not support competitors' products."
Post reply on HN