5 ms·
As far as I understood, FIDO pretends to change the login/password security model to one based in biometrical data like fingerprint or faceid. But, didn’t we al
by soci 4y ago
As far as I understood, FIDO pretends to change the login/password security model to one based in biometrical data like fingerprint or faceid. But, didn’t we all agree that “biometrical
data is a login and not a password”? How can FIDO be more secure than different passwords per website or service?
- fuzzy2 4y agoThat's not quite correct. FIDO is using public key cryptography. To not transmit secrets. On an authenticator, the private key could be (locally) secured using Face ID or whatever, even just using a PIN.
- jillesvangurp 4y agoBecause there is no way to enforce those passwords are actually different or not endless variations of the same easy to guess password. Users have been doing all the wrong things with passwords ever since they were invented. I actually caught my father with an actual notebook of all the key passwords a few years ago and introduced him to Bitwarden. A burglar could have gotten access to pretty much everything with that notebook.
- alaricus 4y agoMost of my accounts are unimportant and nothing would happen if they stolen or hijacked. I totally write down those passwords somewhere. The important ones are not in writing anywhere (like bank logins). There is no reason to pretent all accounts are similarly important or that the same security policies should apply.
- warkdarrior 4y agoNot quite right. FIDO2 uses a public/private key pair to authenticate you to a website. The private key is stored on a device you control. The device could be something like a Yubikey, which does not authenticate you, or like a mobile phone, which typically authenticates you using a biometric. In any case, the website sees a FIDO2 authentication request from you based on the private key, not on your biometric.
- vbezhenar 4y ago> didn’t we all agree that “biometrical data is a login and not a password” No? For many years almost every smartphone on the market ships with fingerprint reader or face recognition acting as an alternative to pin-code.
- r00fus 4y agoWell, the assumption is that ownership of the device and ability to unlock it (face | fingerprint | passcode) present 2 factors for authentication of the FIDO local keychain. Passwords are time-tested and failed approach. They rely on user using different passwords for each system. Most people suck at passwords. Just look at your parents (or youngsters - your grandparents) - they probably suck. We probably would at their age also, except we use tooling like password managers that are still frustratingly difficult for non-techies.
- boudin 4y agoPasswords have their problems but this will not make things more simple so I really doubt it will be more secure in the end. If it's adopted it will just change attack methods. On my side, I do not trust any company mentioned in the article and do not use any of their product. If i'm required to have anything to do with them, I'll just be locked out (and I don't think I'll be the only one)
- darkwater 4y agocan we stop with this ageism? There is plenty of teenagers or people in their 20s or 30s with ludicrous passwords. Unless you are a techie, passwords are chores and nobody wants to do complex chores.
- r00fus 4y agoAgreed, let me restate - most non-techies really suck at passwords. The rest of us are probably overconfident in our own op-sec. Regardless I stand firm that passwords are a poor authentication standard, and the time is nigh for us to move on.
- diffeomorphism 4y ago> As far as I understood, FIDO pretends to change the login/password security model to one based in biometrical data like fingerprint or faceid. No, not really. Much more commonly it is a security token (like a yubikey) or a TMP in another device. https://en.wikipedia.org/wiki/FIDO_Alliance https://en.wikipedia.org/wiki/FIDO_Alliance > How can FIDO be more secure than different passwords per website or service? By generating these "passwords" for each website and service and each time you use them.
- AnonHP 4y ago> No, not really. Much more commonly it is a security token (like a yubikey) or a TMP in another device. If you see this reply within the short edit window, did you mean TPM (and not TMP)? I don't know what a TMP is in this context.