3 ms·
I agree that this is an important next step in making WebAuthn accesible enough to supplant passwords. Note that once you're recovering your password, you've al
by sebk 4y ago
I agree that this is an important next step in making WebAuthn accesible enough to supplant passwords. Note that once you're recovering your password, you've already lost access to your end-to-end encrypted data like keychain, and that's a good thing. It's still a solvable problem, and there are three things that I'd like to see in this area.
a) The ability to share passkeys across vendors, including the ability to implement a "sync fabric" as some folks in the WebAuthn working group have called it, so it's interoperable beyond the major vendors.
b) For these vendors to strengthen their own log in experience. Apple only allows their own TOTP implementation and SMS fallback to authenticate to iCloud. I'd like to use WebAuthn exclusively here, so I could back up access to my now-precious Keychain that holds all my FIDO credentials with a YubiKey.
c) A better story about backing up security keys. Implementing a) would give us that. Devices that can be initialized with a given seed like some common hardware crypto wallets would give us that, albeit not without introducing changes to the threat model -- you have to store the seed and input it somehow -- and hhttps://www.yubico.com/blog/yubico-proposes-webauthn-protocol-extension-to-simplify-backup-security-keys/ https://www.yubico.com/blog/yubico-proposes-webauthn-protoco... would give us that as well.
- politelemon 4y agoThe external dependency, for there to be organizations managing implementations for this 'sync fabric' makes the whole thing quite tenuous and subject to political manoeuvring and other unforeseen factors that come with maintaining hosted solutions. Based on past observation of large tech companies, I just cannot see this happening: > so it's interoperable beyond the major vendors. (though of course time will tell.) Instead I only see this good-faith initiative being turned into a tool to further promote user lock-in to respective ecosystems and platforms.
- sebk 4y agoI don't disagree that it will be hard, but I think that ultimately all that is needed for this to be possible is a standard TPM API that lets you export key material wrapped in a public key (corresponding to another TPM, presumably) only if it's signed by the TPM itself. This would let implementers build something equivalent to Apple's circle of trust (https://support.apple.com/guide/security/secure-keychain-syncing-sec0a319b35f/web https://support.apple.com/guide/security/secure-keychain-syn...), and use the new API to share 'Passkeys' between devices. Whether having an open syncing fabric is enough for vendors to want to interoperate with it I don't know, but if they ship TPM comformant hardware, you as a consumer would have the option to use either fabric. I glossed over a lot of details and the implementation might not end up looking like that, but I believe something similar would be sufficient to kickstart the effort.
- dwaite 4y ago> The ability to share passkeys across vendors, including the ability to implement a "sync fabric" as some folks in the WebAuthn working group have called it, so it's interoperable beyond the major vendors. This is a bit of a new challenge, because websites that consume authentication sometimes need to be able to reason about that authentication's strengths and risks. The models we use for this today, built around countering risks through multiple factors, are not set up to map to these new credentials which are abstracted by software and don't represent a single of the factors strongly. It may be better to have third party sync fabrics that are cross platform, like a 1Password or Lastpass or Bitwarden, and indicate this so that the quality of the authentication can be reasoned about.