5 ms·
That is really cool, thanks for a detailed writeup. I try to pay attention to the WebAuthn spec and did not realize this was possible. I suspect that for most
by justsomeadvice0 4y ago
That is really cool, thanks for a detailed writeup. I try to pay attention to the WebAuthn spec and did not realize this was possible.
I suspect that for most people, WebAuthn (esp with synced passkeys) is going to actually make the CI part of CIA possible for end user content on the internet. In practice it solves the UX around key management and device syncing issues - it passes the "your grandmother can use it" test IMO.
The web3 concept was caught up in cryptocurrencies and constraints around distributed systems; but extending asymmetric cryptography to end users is what should be worked on, as it allows improving most systems without financial or performance overhead. mTLS certs approached the issue but the UX never got there, and cannot be used outside of site authentication.
- AlbertVAustin 4y ago> it passes the "your grandmother can use it" test IMO. Indeed, but note that having the token is still rare. It'd be good if browsers exposed TPMs via WebAuth since they're more common on consumer-grade hardware. And also the "minor" thing that having only one strong authenticator makes it super-easy to lose own data just in case the authenticator breaks etc.
- cormacrelf 4y agoThey do. At least Apple implements WebAuthn for Touch ID and Face ID on both its mobile and laptop platforms, using Safari.
- jrockway 4y agoWindows also has this; they call it "Windows Hello".
- deleted 4y ago[deleted]
- justsomeadvice0 4y ago> And also the "minor" thing that having only one strong authenticator makes it super-easy to lose own data just in case the authenticator breaks etc. This is why I mentioned "esp with synced passkeys". WebAuthn can use - but does not necessarily require - hardware-backed keys. iCloud passkeys are an example of an implementation of "soft" keys that are both transparently backed up and synced across the user's devices. Their interfaces are designed to make them difficult to leak (I'd imagine you'd need root+SIP turned off, or a really good OS bug), but are to my knowledge resident in device memory. This is tradeoff for usability. Grandma is never going to be able to use yubikeys to log into things, let alone set one up.