Live data from Hacker News

Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

fidoalliance.org

91–100 of 525 posts

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#91

So their vision of the future is that to do anything online, one MUST have a phone (ahem, portable wiretap)? And they're going to be keeping my secrets for me, for my own good? I'm not sure I'm down with any of that.

It's literally the opposite. You "must" have a cryptographic device (a dongle) that is only doing that one thing, authentication. Doesn't have a built in radio (unless for NFC, if you want it), doesn't have any microphone or camera, doesn't store any data beyond what's needed to authenticate, doesn't communicate except to authenticate - bi-directionally, so phishing is no longer a thing, or at least it's a lot harder…

> It's very hard to make a privacy case against FIDO.

With username and password, I have full control over my privacy in a very easy to understand fashion: If I randomly generate them I know I cannot be tracked (as long as I ensure my browser doesn't allow it by other means).

With those keys I have a opaque piece of hardware which transfers an opaque set of data to each website I use and I have NO idea what data that is because I do not manually type it in. I need to trust the hardware.

Sure, I could read the standard, but it very likely is complex enough that it is impossible to understand and trust for someone who has no crypto background.

And I also have no guarantee that the hardware obeys the standard. It might violate it in a way which makes tracking possible. Which is rather likely, because why else would big tech companies push this if it didn't benefit them in some way?

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#92
post #55

The weakest link in security is always going to be humans. Account compromise is is more often a human problem than a technological one (spamming requests, password reuse, simple passwords, (spear) phishing, direct social engineering, etc). If I'm understanding correctly, they're aiming to reduce multi-factor auth back down to a single factor that's "easier" than passwords. Easier to use. Easier to social engineer a…

“The weakest link in security is always going to be humans.”

This is not true whatsoever.

Humans will always be a weakness for sure. But hardly the “weakest”, and hardly “always”

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#94

I don't trust Google or Apple to be my main authentication provider, or to manage syncing my private key. Their customer service is terrible and they are way too arbitrary on locking folks out. I would trust my bank (well, my credit union.) I can go see them in person if I need to and they take my lawyer seriously, they also take security seriously, they're properly regulated, and ultimately they're my main concern i…

There is no comparison between Google and Apple customer support, and they should not be mentioned in the same sentence. Google support is nonexistent. With Apple, I can chat online or get in person support. They are more like a bank.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#95

I don't trust Google or Apple to be my main authentication provider, or to manage syncing my private key. Their customer service is terrible and they are way too arbitrary on locking folks out. I would trust my bank (well, my credit union.) I can go see them in person if I need to and they take my lawyer seriously, they also take security seriously, they're properly regulated, and ultimately they're my main concern i…

This announcement isn't about that and neither provider is asking to sync your private key. In fact the opposite is true: with FIDO2, you're in much greater control of your account security because authentication creds are now on a hardware token versus as bearer credentials you type and an adversary can steal and replay. Many of us believe we're very good at protecting our passwords, but this isn't true in reality a…

Except it kind of is - the way I read this is "Apple/Google will turn your phone into a hardware FIDO token, but will use iCloud/whatever to reduce the huge painpoint of having more than one hardware token and keeping them all in sync"

I really love the idea of FIDO and making sure that my authenticator only authenticates to sites that I've approved, but having multiple keys right now is a huge pain, but I'm not excited about "just sign up for Apple and that pain goes away" because I sure as hell don't trust Apple not to cause me pain in the future.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#96

Earlier quoted context omitted.

It's literally the opposite. You "must" have a cryptographic device (a dongle) that is only doing that one thing, authentication. Doesn't have a built in radio (unless for NFC, if you want it), doesn't have any microphone or camera, doesn't store any data beyond what's needed to authenticate, doesn't communicate except to authenticate - bi-directionally, so phishing is no longer a thing, or at least it's a lot harder…

> It's very hard to make a privacy case against FIDO. With username and password, I have full control over my privacy in a very easy to understand fashion: If I randomly generate them I know I cannot be tracked (as long as I ensure my browser doesn't allow it by other means). With those keys I have a opaque piece of hardware which transfers an opaque set of data to each website I use and I have NO idea what data that…

> Which is rather likely, because why else would big tech companies push this if it didn't benefit them in some way?

They switched to this internally a long time ago which basically eliminated phishing attacks against employees. There are security teams inside those megacorps that have a general objective of reducing the number of account takeovers, and non trivial resources to accomplish that. Not everything is a conspiracy.

Also, I am sure you will be able to stick to just passwords for a pretty long time while the world moves on to cryptographic authentication. I'm not being sarcastic here.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#97

I don't trust Google or Apple to be my main authentication provider, or to manage syncing my private key. Their customer service is terrible and they are way too arbitrary on locking folks out. I would trust my bank (well, my credit union.) I can go see them in person if I need to and they take my lawyer seriously, they also take security seriously, they're properly regulated, and ultimately they're my main concern i…

This announcement isn't about that and neither provider is asking to sync your private key. In fact the opposite is true: with FIDO2, you're in much greater control of your account security because authentication creds are now on a hardware token versus as bearer credentials you type and an adversary can steal and replay. Many of us believe we're very good at protecting our passwords, but this isn't true in reality a…

> neither provider is asking to sync your private key.

Yes, they are. According to the white paper linked in the press release:

Just like password managers do with passwords, the underlying OS platform will “sync” the cryptographic keys that belong to a FIDO credential from device to device.

https://media.fidoalliance.org/wp-content/uploads/2022/03/Ho...

Ars Technica had a better write-up of these announcements back in March: https://arstechnica.com/information-technology/2022/03/a-big...

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#98

I don't trust Google or Apple to be my main authentication provider, or to manage syncing my private key. Their customer service is terrible and they are way too arbitrary on locking folks out. I would trust my bank (well, my credit union.) I can go see them in person if I need to and they take my lawyer seriously, they also take security seriously, they're properly regulated, and ultimately they're my main concern i…

This announcement isn't about that and neither provider is asking to sync your private key. In fact the opposite is true: with FIDO2, you're in much greater control of your account security because authentication creds are now on a hardware token versus as bearer credentials you type and an adversary can steal and replay. Many of us believe we're very good at protecting our passwords, but this isn't true in reality a…

No post body was provided.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#99
post #38

I've resisted switching to a hardware key because I know that I'm going to break it, and that seems like a huge pain in the ass. I really want to be able to make a couple of backup keys, or maybe put another way, I want to be able to put the private key on the device myself, I don't necessarily care that the key is generated on the device and never leaves the device. I don't care if that slightly reduces my security…

You just register 2-3 keys. It's not so bad.

The services I interact with that support WebAuthn usually only allow you to register one key. Backup and recovery is a confusing puzzle for most of these services.

Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard

#100
post #3

Not a great thing to see the big three once again, driving the standards here. You should be worried. But as long as the ridiculous SMS 2FA is removed or replaced by something better, then fine. But we'll see how this goes. From the web side of this standard, this also tells me that Mozilla has no influence anywhere and will be the last ones to implement this standard in Firefox. Oh dear.

Mozilla is a member ( https://fidoalliance.org/members/ ), so I doubt they'll be the left to their own devices. They'll probably lack the manpower to implement the additions well (I mean, you can't even paste a URL to an IPv6 address in Firefox for Android, which is one of the most basic features of a browser), but then again they already have Firefox Sync and a working WebAuthn system.

[deleted]
Post reply on HN