Live data from Hacker News

Emailing a one-time code is worse than passwords

blog.danielh.cc

771–780 of 816 posts

Re: Emailing a one-time code is worse than passwords

#771

Earlier quoted context omitted.

Is this not the protocol we're talking about? https://w3c.github.io/webauthn/#sctn-attestation It seems pretty clear that "where possible" parties besides the user are provided with information about the user (ostensibly about their device, but who knows what implementers will use this channel for)... so they can make a trust decision. It's going to end up being a root-of-trust play, and those create high value targe…

Just because an API or protocol has a certain capability, does not mean it is implemented for all use cases. Folks seem to be hung up on the term "attestation" being in the response of a create call. If you look inside that object, there is another carve out for optional authenticator attestation, which is not used for consumer use cases. I will keep repeating what I've said in the other comments. There is no credent…

OK, so suppose you and I were bad guys. You work on the code that interfaces with the TPM on a windows device, and I work at an insurance provider and write code that authenticates users.

Suppose we hatch a conspiracy to take our users out of the "consumer synced passkey system". And into one where you can use the authentication ritual as a channel where you can pass me unique bits re: this user such that we can later compare notes about their behavior.

What about passkeys prevents us from doing this? How do we get caught, and by whom?

Re: Emailing a one-time code is worse than passwords

#772

Earlier quoted context omitted.

There is already an example of Microsoft selling passkeys with their own "secure (tm)" stamp on them, and not accepting anything else just a few comments down. Even if there wasn't already an example, it's easy to turn control into a revenue stream at a later time.

That is for their enterprise SaaS, and has an obvious profit motive (I.e. bundling). Do you think Chrome is going to start charging for using their passkey storage and then kick all the other apps off Chrome? > Even if there wasn't already an example, it's easy to turn control into a revenue stream at a later time. I think you’ll have to justify or qualify this a bit. If Google forces every website on Chrome to have…

Saying "oh that's enterprise" is just moving the goal posts.

Chrome has already started kicking off extensions, see ublock.

I can't divine the future about how they will further their income streams.

Re: Emailing a one-time code is worse than passwords

#774
post #740
post #698

Earlier quoted context omitted.

And I come back to: if it would never work, why not drop support? "We pinky promise" is just not good enough.

> if it would never work, why not drop support? Because passkeys are designed to replace passwords across multiple different service contexts, that have different requirements. Just because there's no reason to use it for one use case doesn't mean it's not actually useful in a different one. See things like FIPS140 (which everyone ignores unless they're legally required not to). Can you sketch out for me the benefit…

> Can you sketch out for me the benefit of a public-facing service deciding to require passkey attestation? What's the thought process?

A misguided administrator is very likely to think "They can't use a malicious device to access our service".

What's the benefit for a private service?

Re: Emailing a one-time code is worse than passwords

#775

Earlier quoted context omitted.

That is for their enterprise SaaS, and has an obvious profit motive (I.e. bundling). Do you think Chrome is going to start charging for using their passkey storage and then kick all the other apps off Chrome? > Even if there wasn't already an example, it's easy to turn control into a revenue stream at a later time. I think you’ll have to justify or qualify this a bit. If Google forces every website on Chrome to have…

Saying "oh that's enterprise" is just moving the goal posts. Chrome has already started kicking off extensions, see ublock. I can't divine the future about how they will further their income streams.

No it’s not. My goalpost from the beginning was “show me an example where there wasn’t a clear monetary incentive for restricting user freedom”. That one has a monetary incentive (make our paying customer for product X also buy product Y).

As for blocking things that block ads; if you can’t see the monetary incentive for Google there then I don’t know what to tell you.

I didn’t ask you to divine the future. I said “I’ve not seen them do X without trying to get Y” (a statement about the past), and you still haven’t given me a remotely credible example.

Re: Emailing a one-time code is worse than passwords

#776
post #65

Earlier quoted context omitted.

The problems of Passkeys are more nuanced than just losing access when a device is lost (which actually doesn't need to happen depending on your setup). The biggest problem are attestations, which let services block users who use tools that give them more freedom. Passkeys, or more generally challenge-response protocols, could easily have been an amazing replacement for passwords and a win-win for everyone. Unfortuna…

I want to like passkeys but I haven't had any success getting them to work. Every time I click on "sign in using passkey" both my browser (Firefox or Chrome, on Android/Win/Mac) and Bitwarden are like "no passkeys found" and I'm never given an option to create one. I feel like I'm doing something stupidly wrong or missing a prompt somewhere, or maybe UX is just shitty everywhere, but if I, a millennial who grew up pr…

Not just you. Browser support is horrid for physical passkeys, very hit and miss.

Depends on the brand of the passkey i think.

Re: Emailing a one-time code is worse than passwords

#777

Earlier quoted context omitted.

"The State is always more difficult and dangerous to deal with than a private company." Ridiculous.

Of course it is. Google can ban me (really just one specific digital instance of me) from their services. The government can throw me in jail, take all my property, fine me whatever amount they want, etc.

The State is significantly less interested in your activities than Google, regardless of whatever hypothetical you'd care to spin.

Re: Emailing a one-time code is worse than passwords

#778
post #658

Earlier quoted context omitted.

"The State is always more difficult and dangerous to deal with than a private company." Ridiculous.

a state has a monopoly on force, you've obviously never lived under a regime which actively wants to harm you.

Odds are neither have you.

Re: Emailing a one-time code is worse than passwords

#779

I just deleted my gofundme because they kicked me into this cycle today. Somehow I've managed to have an account there and make contributions over the years, but now they wanted my phone number and an MFA code to proceed, and there was no opt-out. I went through it but then deactivated my account. I need less of this in my life, and gofuneme is not essential to my life. I'm in the rental market right now, and Zillow…

Ticketmaster did the same. They don't accept Google Voice numbers, yet my only number is Google Voice. The number tied to my SIM is an implementation detail that changes depending on where I am, but it's the only way I can get into that account now. My choices are to not go to events that are ticketed by them, or accept that I'll probably be locked out whenever I change SIMs.

SMS is literally the least secure form of authentication, because numbers expire after mere weeks, and get re-assigned shortly, within months, because of number shortage in many area codes.

Nothing like this could happen with any mainstream mail service like Gmail, where it's officially advertised that the accounts could never be reused.

The worst part about SMS is that not only is there the potential to be locked out permanently, but also you never know whether or not the service would allow login or password reset via SMS, thus, you never know if you're opening yourself to account takeover.

Post reply on HN