7 ms·
I don't trust Google or Apple to be my main authentication provider, or to manage syncing my private key. Their customer service is terrible and they are way to
by throwaway52022 4y ago
I don't trust Google or Apple to be my main authentication provider, or to manage syncing my private key. Their customer service is terrible and they are way too arbitrary on locking folks out.
I would trust my bank (well, my credit union.) I can go see them in person if I need to and they take my lawyer seriously, they also take security seriously, they're properly regulated, and ultimately they're my main concern if someone stole my credentials, so I'd like them to be on the hook for protecting my credentials.
- 0daystock 4y agoThis announcement isn't about that and neither provider is asking to sync your private key. In fact the opposite is true: with FIDO2, you're in much greater control of your account security because authentication creds are now on a hardware token versus as bearer credentials you type and an adversary can steal and replay. Many of us believe we're very good at protecting our passwords, but this isn't true in reality and FIDO2/U2F standards objectively make accounts more secure precisely because they remove humans from the equation.
- throwaway52022 4y agoExcept it kind of is - the way I read this is "Apple/Google will turn your phone into a hardware FIDO token, but will use iCloud/whatever to reduce the huge painpoint of having more than one hardware token and keeping them all in sync" I really love the idea of FIDO and making sure that my authenticator only authenticates to sites that I've approved, but having multiple keys right now is a huge pain, but I'm not excited about "just sign up for Apple and that pain goes away" because I sure as hell don't trust Apple not to cause me pain in the future.
- toomuchtodo 4y agoYour average user is more concerned about losing their password than they are about authenticator sovereignty. Moving towards cryptographic primitives for auth versus shared secrets is a net benefit versus current state. > but having multiple keys right now is a huge pain, but I'm not excited about "just sign up for Apple and that pain goes away" because I sure as hell don't trust Apple not to cause me pain in the future. Compromise is necessary, and probably a bit of regulation from government to enforce good outcomes from exception handling. Passkeys need to be stored and managed somehow, and your average user does not want to do that, just like they don't want to run their own mail server, syncthing instance, or mastodon instance. EDIT: (HN throttling, can't reply) @signal11 You can already be locked out of all of those accounts without recourse.
- signal11 4y ago> Your average user is more concerned about losing their password than they are about authenticator sovereignty Right up to the point when they’re locked out from their Google, iCloud or Facebook accounts with little recourse or appeal. And then they discover it’s not just Google, a whole host of other services don’t work. And it does happen, and I for one don’t want to wait for legislation to mitigate this blatant attempt at yet more centralisation. Better to not centralise in the first place.
- zozbot234 4y agoMany authenticator apps allow you to extract and back up the private key yourself, with no involvement of any 3rd party. But it's a totally optional workflow and you're never asked for that private key while authenticating, so the mass phishing and spear-phishing attacks seen with passwords are still infeasible.
- judge2020 4y agoThis is a net benefit over synced passwords, which everyone already trusts them to do. You haven't been forced to use a (syncing) password manager over a physical password book in the past, and you won't be forced to use Passkeys[0] or the Android equivalent in the future; hardware security keys will still be usable since this announcement is about embracing the FIDO Standard. 0: https://developer.apple.com/documentation/authenticationservices/public-private_key_authentication/supporting_passkeys https://developer.apple.com/documentation/authenticationserv...
- mbrubeck 4y ago> neither provider is asking to sync your private key. Yes, they are. According to the white paper linked in the press release: Just like password managers do with passwords, the underlying OS platform will “sync” the cryptographic keys that belong to a FIDO credential from device to device. https://media.fidoalliance.org/wp-content/uploads/2022/03/How-FIDO-Addresses-a-Full-Range-of-Use-Cases.pdf https://media.fidoalliance.org/wp-content/uploads/2022/03/Ho... Ars Technica had a better write-up of these announcements back in March: https://arstechnica.com/information-technology/2022/03/a-big-bet-to-kill-the-password-for-good/ https://arstechnica.com/information-technology/2022/03/a-big...
- eMGm4D0zgUAVXc7 4y ago
- deleted 4y ago[deleted]
- epistasis 4y agoNot at all, because before anybody could take your account away from you if you did not accurately compare two visual strings, potentially in Unicode. By replacing that operation, which humans can not perform reliably, with computer operations, users are no longer subject to others taking control of their account. It is wonderful.
- dwaite 4y agoThis announcement is partially about the platform-integrated authenticators being made into 'virtual' authenticators backed by a platform vendor-specific cloud ecosystem. So for example, a credential registered on an iPhone may be synchronized over iCloud Keychain to work to log in my Mac via TouchID. This is something which has always been as part of the model - an authenticator is just an abstract thing that represents an authentication factor, generates keys for a particular use, and doesn't share private keys outside its boundaries. This announcement possibly marks a transition where sites supporting Web Authentication (with a bring-your-own-authenticator model) will go from seeing 90%+ hardware-bound authenticators to seeing 90%+ platform-integrated, synchronizing authenticators. Bundled into that prediction is a hope that this (and other proposed changes) will lead to a 10x increase in adoption.
- jurmous 4y agoIn the Netherlands the banks provide the iDIN system, so you can authenticate on more sites with the bank provided logins. Each bank has a slightly different system often using bank card and bank card readers and ways to authenticate through authorised banking app on individual mobile phones. - https://www.idin.nl/en/about-idin/ https://www.idin.nl/en/about-idin/ - https://nl.wikipedia.org/wiki/IDIN https://nl.wikipedia.org/wiki/IDIN - (Use translate function in browser to read as there is no English version And besides that we have also a government provided login system which can also even work with your ID card. But mostly works with government systems and health insurance companies. - https://en.wikipedia.org/wiki/DigiD https://en.wikipedia.org/wiki/DigiD - https://www.digid.nl/en https://www.digid.nl/en
- eMGm4D0zgUAVXc7 4y agoGiven that banks usually MUST validate their customers' identity card the opportunities for tracking your users with this must be superb. I'd frankly prefer "insecure" user+pass over all of these guardrails which are 90% about control over the users and 10% about security.
- jve 4y agoTracking from bank or both? Anyways, in Latvia we have similar system and it is a convenient way to authenticate within services where you MUST prove you are person X.Y.Z. For example, some electric company, if you auth via this method, will provide you with contracts, electricity usage graphics for all the sites you own and and other info you must access as a customer. Same goes for recycling company. These usually provide a way to register using email matching whatever email you had in contract (thus linking to real person anyway) And then for other services where you request some data electronically that they must "register" each request. For example request some extended data on land/house ownership. You can't have that with non-real-life identifiable entity. So usually login via bank is an login option with companies you either have juridical relationships or you must provide real life identity where you would otherwise have to show passport in real life.
- avianlyric 4y ago
- epistasis 4y agoThere is no comparison between Google and Apple customer support, and they should not be mentioned in the same sentence. Google support is nonexistent. With Apple, I can chat online or get in person support. They are more like a bank.
- londons_explore 4y ago> they also take security seriously, Despite what most people think, banks are often a really long way behind on security. Banks don't care about security of any individual customer, merely security of the bank as a whole. That means if 0.01% of customers lose all their funds due to credential stuffing, it isn't an issue - the bank will just refund them if needed. Unlike say ssh with key authentication, where it would be a total failure if 0.01% of attackers were allowed to login without the key.
- maxwelldone 4y ago> Their customer service is terrible Let me add my recent experience in the bucket. Few days ago I upgraded my legacy Workspace account to a business account. (I was in a time crunch; couldn't evaluate alternatives.) I enter my debit card details in the checkout and got a generic error message asking me to "try again later." Thought there was something wrong with their service and tried the next day. Same error. After some 15 minutes of searching forums, turns out debit card is not supported in my country on account of SMS based TOTP, which doesn't work for subscription services. (If they could mention it in the haystack of their help pages, why can't they say that right when I signup?) Anyway, more searching led to an alternative. There's an option to request invoiced billing where I would get a monthly bill & pay - debit card works here. Clicking that option took me to form. Filled it, got a call from a sales guy few hours later. Sadly, he had no clue about my problem, despite being from my country. On top of that he told me he's from a different team and don't deal with sales queries (WTF. Then why did he call me?). Told me he'd email me some options and, at that point I wasn't hopeful. Thought he would send me some stuff I had already seen on their forums. On seeing the said email, my disappointment sank even lower. The generic mail had absolutely nothing to do with my issue and the help urls were totally unrelated. I just ended up using my friend's credit card to complete the transaction. I'm seriously considering moving elsewhere. Is product management this pathetic at Google? I'm sure if you went for a PM interview they'd judge you nine ways to Sunday. For what? Everything Google does seems like it's built by three robots in a trench coat collaborating unsuccessfully with other robots in trench coats.
- rootusrootus 4y ago> I'm seriously considering moving elsewhere. I recently moved my family's legacy GSuite service over to Fastmail, and it seems like they've carefully planned for this exact scenario. Account setup on each device is as simple as downloading a configuration profile with a QR code. And Fastmail has a built-in option to authenticate to your old Google account and pull all your mail over to the new account, preserving all the details, and then keep sync'ing until you're ready to turn the old account off. I thought I was going to have to sync things myself. Nope! Took all of five minutes to set up my account and sync. Couple weeks later I deactivated the old GSuite accounts. And now I'm a customer again, which feels good, even though it means spending actual money.
- mavhc 4y agoI wouldn't trust my bank to not give my account to someone pretending to have forgotten my password
- deleted 4y ago[deleted]
- deleted 4y ago[deleted]