Live data from Hacker News

Passkeys: A shattered dream

fy.blackhats.net.au

701–710 of 789 posts

Re: Passkeys: A shattered dream

#701
Good riddance. Any system that limits my options as power user I will not promote. Lots of services only let you enroll single passkey and "hardware attestation" would only make it even bigger lock-in.

I like passkeys as idea for stonger security, but author somehow thinks that discrimination against devices is a good idea.

Sorry, no. Just no. I dont want my bank or paypal require me to use iPhone in order to login to my account.

Re: Passkeys: A shattered dream

#702

Earlier quoted context omitted.

Having the passwords in the cloud is useful though. Before, if you wanted to use your vault across multiple machines, you had to store your vault in someone else’s cloud. This simplifies the process.

Incorrect. 1P orginally offer direct LAN syncing among machines.

And dropbox etc. based

Re: Passkeys: A shattered dream

#703

The biggest issue with passkeys is that I just can't trust the companies offering them. They are locked into the platform for reasons that are ostensibly security but often indistinguishable from platform lock-in. If you make a passkey on an Apple device as far as I can tell it will never leave that device, ever, and there is no way to change this. Of course this means you can never be phished for your credentials bu…

The platform lock in attempt is wild, my initial experiences with Passkeys were great on iOS and Safari, either getting pushed to touch-id or scanning a QR with my phone. But then in Chrome I couldn't get into GitHub because chrome would only push me to use their manager and wouldn't offer a QR code. Seeing this more and more with Chrome, like Credit Card numbers used to just save and autocomplete in browser but then…

The lock in is intentional, security theater touted as a feature in the shitty, ambiguous spec. Unfortunately, the folks who contribute to the spec are more concerned about threatening projects that have the audacity to use common sense instead: https://github.com/keepassxreboot/keepassxc/issues/10407 (and https://github.com/keepassxreboot/keepassxc/issues/10406)

Re: Passkeys: A shattered dream

#704

Every time I see a long inscrutable discussion about Passkeys, I see a weird avoidance of the "something you know" part of security. Here in the US, courts and law enforcement have every right to get your username, fingerprint, retina scan, face ID, whatever. But they don't have the right to extract something from your brain. Unless I'm missing something basic (which at this point, I don't think is my fault since thi…

> But they don't have the right to extract something from your brain. Most folks store passwords in password managers and don't use their brains to retrieve them.

Most folks do not do this. Although they should be.

Re: Passkeys: A shattered dream

#705

Earlier quoted context omitted.

Great, so we are back to passwords then

No, because passwords are just something-you-know (one factor) while a passkey that’s protected with a password is both something-you-have and something-you-know (two factors)

So like a password manager?

Re: Passkeys: A shattered dream

#706

The biggest issue with passkeys is that I just can't trust the companies offering them. They are locked into the platform for reasons that are ostensibly security but often indistinguishable from platform lock-in. If you make a passkey on an Apple device as far as I can tell it will never leave that device, ever, and there is no way to change this. Of course this means you can never be phished for your credentials bu…

You can normally create multiple passkeys across different devices for the same login.

Re: Passkeys: A shattered dream

#707

Earlier quoted context omitted.

with an excellent response to that warning here: https://news.ycombinator.com/item?id=39706876

Yep, I agree with that response completely. That whole thread is a great read about the reality of the passkey situation, and what it will take to really make it great.

The entire passkey situation is pretty telling that the spec was created with just vague promises that export would be handled at a later date.

Re: Passkeys: A shattered dream

#708
post #271

Earlier quoted context omitted.

This is why I’m not interested in passkeys unless I can use it with my password manager (which I probably can at this point). It would also be nice to see the spec for these specifically address lock-in and provide anti-lock-in measures.

The idea of a passkey is that it's bound to a device, and you can have more than one passkey. Think of a YubiKey, just that you can use your Phone or your PC instead. You basically have designated hardware that is always allowed to just login to your account...

Then why can it be backed up to the cloud?

Re: Passkeys: A shattered dream

#709
post #705

Earlier quoted context omitted.

No, because passwords are just something-you-know (one factor) while a passkey that’s protected with a password is both something-you-have and something-you-know (two factors)

So like a password manager?

No, because a password manager still just stores passwords (one factor!); if someone got that password they can get in

The whole point of a passkey is that it’s something you have, not know:

- you can’t guess it because it’s a really long encryption key

- you can’t phish it because using a passkey does not give the passkey to the site, it just proves that you have the key (typical priv/pub key auth)

- you can’t steal it because passkeys are meant to never be moved from the device — it’s supposed to be impossible to extract them, as they’re supposed to live on a secure enclave type chip that is impossible to extract from

So, no, not like a password manager

Re: Passkeys: A shattered dream

#710

Earlier quoted context omitted.

The platform lock in attempt is wild, my initial experiences with Passkeys were great on iOS and Safari, either getting pushed to touch-id or scanning a QR with my phone. But then in Chrome I couldn't get into GitHub because chrome would only push me to use their manager and wouldn't offer a QR code. Seeing this more and more with Chrome, like Credit Card numbers used to just save and autocomplete in browser but then…

> and shut down my Google Pay account I never knew I had Google loves that nonsense, don't they? It's as though they think so highly of themselves that they cannot imagine they might not be strictly doing us all a favor by signing us up for their services. Fifteen years later, I still have friends occasionally sending messages to a GMail address I never asked for, never used, and didn't even know about for most of a…

As shitified as the world wide web has gotten over the last few years, that's almost a feature these days.

Now you have lots of chaff / ablative / imposter emails to divert away all the robo-mailers, spear fishers, destitute princes, and the like. Even the tiniest little mistake and the email goes to one of a million diversion accounts.

Side Not-a-joke: On this topic, I also really hate two-factor authentication you don't sign up for, don't want, yet are forced to add to your account, because Google Play is too much of SCIF to just let you log in. Even more security theater for the most basic activities. Now I need two-factor every time I try to use GitHub. Ugg.

Post reply on HN