5 ms·
The blogpost manages to not explain what they actually intend to do, but I assume it means WebAuthn PRF. The general idea is nice and it works, but it's hindere
by sebk 4y ago
The blogpost manages to not explain what they actually intend to do, but I assume it means WebAuthn PRF. The general idea is nice and it works, but it's hindered by the fact that sync fabrics aren't interoperable or pluggable.
Let's say you have an iPad, a Windows PC, and an Android phone, and you set up your 1Password account using a Passkey (0Password?) in your iPad, and now you want to set it up on your Windows PC... except there's no way to sync your Passkey from the Apple sync fabric to the Microsoft sync fabric, so you need some sort of shareable secret between those from which an encryption key can be derived -- a password + secret key. After that set up the encryption key you just derived can be wrapped with a key generated from the Microsoft sync fabric prf and the process starts again with Android. You've managed to unlock all your devices using WebAuthn, but you didn't manage to get rid of the password, and if you decide to change it, then you're in for the whole ride again.
The blogpost also reads Use your phone to unlock 1Password on your Mac, PC, and in the browser, so I assume the way to get around the sync fabric problem they envision using is relying on your phone's sync fabric, and relaying the encryption key through hybrid transport, then prompting you to store a Passkey in that new device, which is still a hassle but you don't need a master password for.
It is critical for the health of the ecosystem that OS vendors adopt APIs so that third-party vendors can plug-in TPM-backed sync fabrics that work across manufacturers. Several third-party vendors have joined the FIDO alliance, so I'm hopeful.
- alyandon 4y agoSo far all I've seen mention of is MacOS, Windows, iOS and Android. Where will Linux running on older non-TPM hardware platforms fit into this ecosystem?
- sebk 4y agoFor _using_ WebAuthn, Linux without a TPM has the option of using a hardware key like a Yubikey or Nitrokey, or a virtual authenticator like what 1Password proposes here: https://www.future.1password.com/passkeys/ https://www.future.1password.com/passkeys/ For _syncing_ WebAuthn passkeys, then virtual authenticators that sync over the wire like 1Password above is the only option. Using virtual authenticators means that your key material is in-memory alongside the OS and all running apps. That's why it's so critical that OSs expose pluggable sync fabrics; so that vendors like 1Password, or even YubiCo, can implement sync fabrics that roam through whatever hardware the current platform happens to have available.
- alyandon 4y agoHrm... how would these master keys get stored securely on Linux without a dedicated TPM? It seems that all these methods seem to want to desperately replace "something I know" with "something I have" that can break, get lost/stolen, etc. That is not a very enticing scenario for me.
- kosherhurricane 4y ago> except there's no way to sync your Passkey from the Apple sync fabric to the Microsoft sync fabric This is by design. > so you need some sort of shareable secret between those from which an encryption key can be derived No, you just authenticate with your iPad passkey (using qr code), and then generate a new passkey on your Windows PC, which will now sync between your windows devices. So no sharing of secrets between sync-clouds is needed, just one time sideways authentication. I'm guessing 1password is just another passkey that they store/sync.
- sebk 4y ago> This is by design. I know, and I don't like being forced to make this tradeoff. This protects the hardware vendors, and inconveniences me. It might leave everyone else unprotected, if the alternative ends up being using virtual authenticators like this: https://www.future.1password.com/passkeys/ https://www.future.1password.com/passkeys/ > No, you just authenticate with your iPad passkey (using qr code) I also know this, as the paragraph immediately after the one you quoted says. It's also a hassle. It makes me have to have one device to register others, and it makes me have to maintain several sync fabrics, which I don't want to have to do. To clarify a bit, I don't want Passkeys in Apple's sync fabric to sync with Microsoft. What I want is the ability to have a third-party Passkey manager that can leverage TPMs and Secure Enclaves to generate, export, and import its own key material across devices from different manufacturers. Exactly like how 1Password envisions its future Passkey offering, but backed by hardware.
- kosherhurricane 4y ago> it makes me have to maintain several sync fabrics Yes, that's the con. That's why 3rd parties like 1password exist. Of course, they have to fight to get their plugins into the Big 3, as the Big 3 want you to use their systems. But also the pro is that if you lose access to your sync fabric X (security breach, account closure), you can still use sync fabric Y. It's like backup fido2 tokens. I think the security benefit of passkeys outweigh the small vendor lock-in they might create.
- 4y ago