Live data from Hacker News

Passkeys: They're not perfect but they're getting better

ncsc.gov.uk

81–90 of 145 posts

Re: Passkeys: They're not perfect but they're getting better

#81

Earlier quoted context omitted.

Tim Cappalli is thoroughly misguided throughout that discussion, but he's not threatening anything. Okta lets users require attestation, but it will never, ever force attestation on anyone.

Tim's not threatening, but he is saying quite clearly that sites on the internet (Relying Parties) might just not accept Passkeys from KeePassXC: > The unfortunate piece is that your product choices can have both positive and negative impacts on the ecosystem as a whole. I've already heard rumblings that KeepassXC is likely to be featured in a few industry presentations that highlight security challenges with passkey…

Correct, individual sites could make that choice. They won't, but they could. (Love the mention in the linked comment of Netflix and Disney, two services that don't even support proper MFA.)

We're completely on the same side, to be clear. I just have zero fear of KeePassXC (which I sometimes use with Okta!) being blocked by anything consumer-facing.

Re: Passkeys: They're not perfect but they're getting better

#82
post #75

Earlier quoted context omitted.

I've seen this argument many times, but I don't understand it. Can you explain a scenario where this would be an issue? So, Netflix makes me log in with a passkey that comes from their own hardware, instead of my password manager. What's the danger there, beyond the fact that this seems to me extremely unworkable because I'd just never sign in?

The danger is that you now can no longer use netflix without they're approved hardware? Of course, that's essentially already the case with netflix, but this becomes dicey when services that actually matter take this approach. And then suddenly you're debanked.

No, we're talking about logins, not usage. Can someone explain to me a case where logging in only with an approved authenticator would be problematic?

Re: Passkeys: They're not perfect but they're getting better

#84
For me, passkey's have made it when I can pay several different, independent providers to store them for me, and authorise the devices I can put them on.

To expand on that a bit, I don't have a problem with banks or whoever insisting they be stored securely. That means I don't have a problem win the inference that they don't trust me to store or even see my own keys.

What I do have a problem with is not being able to back them up. Which means I have a problem with Apple, Google or even Bitwarden handing me out a free they can take away at any time.

Fix that, so I can have store my identity(ies) at multiple providers, and I happy.

Re: Passkeys: They're not perfect but they're getting better

#85

Earlier quoted context omitted.

Tim's not threatening, but he is saying quite clearly that sites on the internet (Relying Parties) might just not accept Passkeys from KeePassXC: > The unfortunate piece is that your product choices can have both positive and negative impacts on the ecosystem as a whole. I've already heard rumblings that KeepassXC is likely to be featured in a few industry presentations that highlight security challenges with passkey…

Correct, individual sites could make that choice. They won't, but they could. (Love the mention in the linked comment of Netflix and Disney, two services that don't even support proper MFA.) We're completely on the same side, to be clear. I just have zero fear of KeePassXC (which I sometimes use with Okta!) being blocked by anything consumer-facing.

Apple does precisely this for Apple account, you need to have a hardware attested passkey implementation to authenticate using passkey.

Edit: forgot to add Apple account

Re: Passkeys: They're not perfect but they're getting better

#86
post #13
post #5

Losing your device and not having any passwords is like losing your fingerprints. >Device loss scenarios >Users are largely unsure about the implications for their passkeys if they lose or break their device, as it seems their device holds the entire capability to authenticate. To trust passkeys as a replacement for the password, users need to be prepared and know what to do in the event of losing one – or all – of t…

Just not having the right device with you is crippling. IMO Passkeys need more work. I'd really like to see accounts support multiple passkeys. I'd prefer biometrics that are device independent. I just don't like the idea of replacing something someone can steal (a password) with something else someone can steal (a phone).

> I'd really like to see accounts support multiple passkeys

Most accounts seem to. Personally, I think I've only found one or two out of around 25 that I've added passkeys to that would not let me add more.

Re: Passkeys: They're not perfect but they're getting better

#87
post #77
post #24

Until passkeys can pass the test of "my non-technical friends and family don't call me for help about them", passkeys aren't ready. Vendors keep making assumptions about how users behave which are not safe assumptions, and that keeps blowing up the interactions of non-technical users. (I'm sure there's an "assumptions developers make about user accounts" blog out there somewhere.) For example, my family has had to ca…

By that metric, passwords are even less ready, as I seem to always have to field calls for passwords getting stolen or compromised or accounts getting phished. I guess we're back to faxing ID.

I have a non-technical father with dementia, and passwords+TOTP are almost frictionless for him, with minor exceptions. We are able to share around passwords and TOTP codes without any problems so I can properly monitor his online activities to keep him out of trouble. He’s a cranky old guy with almost zero trust, so having to input all that stuff satisfies him that security is being employed.

Passcodes just freak him out.

Re: Passkeys: They're not perfect but they're getting better

#88
post #23

Earlier quoted context omitted.

> I read about Passkey comittee being against open source passkey managers during start of this year (can't reference it, sorry) but with open source password/key managers already supporting passkeys, i don't think it turned out to be true. Here's an Okta employee threatening to use the attestation (anti)feature of passkeys to block open-source implementations, because they allow you to export your passkeys: https://…

That's the whole point of this exercise. If export is possible it's not secure against local compromise in the way that's needed.

That's not quite correct. This can easily be seen by simply considering that the people who developed the passkey standard are also developing a passkey import/export standard which is nearly done and implementations are appearing in the field already.

For example Apple's Passwords app on MacOS/iOS/iPadOS 26 now supports export and import of passkeys to/from other apps that support that standard. I don't know if any other apps have yet actually released such support.

Re: Passkeys: They're not perfect but they're getting better

#89
post #87
post #77

Earlier quoted context omitted.

By that metric, passwords are even less ready, as I seem to always have to field calls for passwords getting stolen or compromised or accounts getting phished. I guess we're back to faxing ID.

I have a non-technical father with dementia, and passwords+TOTP are almost frictionless for him, with minor exceptions. We are able to share around passwords and TOTP codes without any problems so I can properly monitor his online activities to keep him out of trouble. He’s a cranky old guy with almost zero trust, so having to input all that stuff satisfies him that security is being employed. Passcodes just freak hi…

I think Github is basically the only good passkey implementation right now. The ideal flow should be:

* Click login button

* Window pops up asking you which passkey you want to use, you click the one you want

* You're in

Anything on top of that is just added friction, and I haven't seen many sites get it right.

Re: Passkeys: They're not perfect but they're getting better

#90
post #32

Earlier quoted context omitted.

lock-in to which vendor? Passkeys support transfer to any vendor you want.

Is it really "any" vendor, or is it just the big ones? Can you transfer your Apple passkeys to KeePassXC?

Not yet. Apple supports export using FIDO's Credential Exchange standard. KeePassXC is working on adding that.
Post reply on HN