4 ms·
Passkeys are definitely the future, and I think will eventually eliminate a lot of phishing attempts and other insecurity caused by passwords. I'm hoping that w
by cmdli 4y ago
Passkeys are definitely the future, and I think will eventually eliminate a lot of phishing attempts and other insecurity caused by passwords. I'm hoping that we will eventually see transferable, secure identities that you can use to log in anywhere, rather than having to constantly create account credentials for everything.
As a side note, if you want to try out passkeys now and don't want to tie it to your device, I would like to plug my solution, Bulwark Passkey (https://bulwark.id https://bulwark.id). It's open source, allows you to export your credentials if you want, and supports all browsers since it emulates a virtual USB device.
- postalrat 4y agoIMO having devices that can be cloned will always be a weakness. Backup devices work fine.
- judge2020 4y agoThe threat vector for your passkeys being stolen is the same as current passwords, that's true (because they're just in some syncing database), but it solves many issues that are the leading cause of account compromise these days, mainly phishing and reused passwords.
- hedora 4y agoSo, for me, there is no real upside, other than not needing to click "generate password" in my password manager. What downsides are there? E.g, will it work on rooted phones? Will apps start adding mandatory pin numbers on top (like they do for biometrics), or will Google/Apple's app stores disallow it? How do I "log out" to avoid tracking without being implicitly logged back in? What happens if I routinely wipe my browser settings? Can I use some other person's computer to login in a pinch? (Such as when my phone is off network?) In principle, browser and os vendors could work through all these "niche" use cases, but I'll be pleasantly surprised if they actually did.
- notlukesky 4y agoWhen did you release it and how is it coming along? Is there any resistance from the physical usb crowd for FIDO?
- cmdli 4y agoI released it a week ago. It's moving along pretty well! The USB emulation method works well, as it can support any browser. So far, I haven't gotten too much push back from the more hardcore security crowd, since I'm upfront about the fact that it is a software implementation. Personally, I think that the main blocker for adoption of passkeys is ease of use, as if you can't transfer your credentials either off of your device or away from your Apple/Google/etc account, then I think it will be a hard sell to users.
- mawise 4y agoGood on you for offering another passkey solution! I really want more non-Google/Apple options. I'll check it out.
- lenova 4y agoHeya! I just tried installing Bulwark on my Windows 10 machine. Install went fine, but when I try to run the app, I get the Admin privilege prompt, and then.... nothing. No sign of the program crashing, or any kind of error. Any ideas? Thanks!
- cmdli 4y agoAh, that is odd. If you don't mind, could you go to %AppData%/Bulwark Passkey and taking a look at main.log or device.log and see if you see any errors in there? I would really appreciate it! Edit: I was able to reproduce the issue; it looks like WebView2 (which Bulwark Passkey relies on) is already installed on Windows 11 but not on Windows 10. I released a new version on https://bulwark.id https://bulwark.id that has that WebView now embedded in the app itself, would you mind downloading that and seeing if that works? Thank you for the report!
- pabs3 4y agoApparently it is possible to make WebAuthn phishable: https://mjg59.dreamwidth.org/62175.html https://mjg59.dreamwidth.org/62175.html https://news.ycombinator.com/item?id=33810984 https://news.ycombinator.com/item?id=33810984
- SahAssar 4y agoThat's only for sites acting as a oauth2 authorization server, right?
- wharfjumper 4y agoThat seems interesting. What's the license? I couldn't see that in the repo [1] 1. https://github.com/bulwarkid/bulwark-passkey https://github.com/bulwarkid/bulwark-passkey
- xanthine 4y agoThe actual 'brains' repo is [1], which is MIT licensed. [1] https://github.com/bulwarkid/virtual-fido https://github.com/bulwarkid/virtual-fido
- cmdli 4y agoMy apologies; I open-sourced VirtualFIDO awhile ago but only open-sourced the actual frontend (Bulwark Passkey) about a week ago, and I forgot the license. It should be MIT licensed now.