Live data from Hacker News

Passkeys for Infrastructure

goteleport.com

71–73 of 73 posts

Re: Passkeys for Infrastructure

#71
post #32

I wish SSO providers were able to hook into this Passkey mechanism. Instead of storing Passkeys in iCloud for sync instead we could store them at the SSO provider

I'm with you here and have been parroting this in just about every Webauthn thread on HN, except maybe with the exception that I think it's password manager vendors who are more interested -- several of them have joined the FIDO alliance in the past year. I think having an open sync fabric that is vendor agnostic will be important going forwards. Users have a multitude of devices, usually not from the same vendor, an…

> The risk is that password manager vendors will end up implementing virtual authenticators backed by software instead of a secure element like a Yubikey, Secure Enclave or TPM.

Why are you saying that would be a risk? I want that to happen, so that I'd be able to back up my passkeys on my own terms.

Re: Passkeys for Infrastructure

#72
post #37

I see a few obstacles with Passkeys as-implemented: * They effectively entrust the keys to your entire digital life to (right now) either Google or Apple. Account compromise, or a ToS-related suspension, becomes catastrophic. * Domain changes happen (acquisitions, rebrands, etc.), and there is no way to share or migrate passkeys between domains. Right now the best you can do is a highly manual process involving the u…

> Right now none of the Passkey syncing providers support anything like that (and I feel like they won't, because it'd be a huge vector for scams). Within the Apple ecosystem Passkeys can be shared with contacts through AirDrop (no other methods are presently allowed). The Passkey is then copied directly from your Keychain to your contact’s Keychain.

Yep, and this is the worst of both worlds. You don't get the security benefit you would if the keys were stored in non-exportable hardware, and you also don't get the freedom to move them to a different ecosystem.

Re: Passkeys for Infrastructure

#73

Earlier quoted context omitted.

you get a system where you can finally own your own identity and the first thought you have is to how to reaquire that dependency on a for-profit entity

The opposite. Now there is just one hardcoded SSO provider: Apple iCloud. Which means you're stuck to one provider. I'd like this to be opened up. Open spec for being able to sync passkeys

It’s Apple, Google, or Microsoft now and soon to be 1Password and others. None of those are hard-coded on the sites using it - the concern is that you can’t port keys between, say, iOS Safari and Windows Edge but you can already register keys from both because it’s not SSO but rather a different PKI scheme.
Post reply on HN