9 ms·
Oh, what could go wrong! Why is there no discussion on users losing their private keys? Ask all those cryptocurrency users who lost their private keys. Now don
by _448 3y ago
Oh, what could go wrong!
Why is there no discussion on users losing their private keys? Ask all those cryptocurrency users who lost their private keys. Now don't tell that there are crypto wallets/vaults that manage private keys; there are many ways key can be lost even when using wallets/vaults.
We engineers live in a different world, disconnected from the regular users who have no clue what public-private keys are!
- jeroenhd 3y agoThe standard mantra for physical key-based 2FA has always been "register two keys and keep one in a safe", which seems doable for important accounts (like banks and government stuff) but no way am I going to get a key out of my safe when I want to order a replacement part on JoesDiscountDishwasherParts.biz. I really wish there was a way to register your backup key through your primary key. Luckily, FIDO2 can fix a lot of these problems. People who don't have significant security needs can use a trusted service (currently Apple, Google, and a few small companies) rather than a physical device. Lose your phone? As long as you can get your account onto a new one, you can still access all of your stuff. Once this type of auth will take off, I can imagine a business model for a FIDO2 company that focuses on customer service. The only problem with the system right now is that if you can't log in to your Apple/Google/whatever account, there's no recovery. Try contacting customer support and see how long it takes until they just block your number, because there is nothing they can do. Having a business where you can go to a physical office and show up with ID so you can get your account back would solve this problem. Recovery would still be a massive pain, but it's better than spending years on a legal battle like some people trying to get their pictures back from their cloud providers after getting locked out.
- nmca 3y agoWait - the way this works is you have a backup key, if you lose your primary you replace it using your backup. NB this is only needed when you move to a new device with a new secure enclave too, so at no point is this pizza situation likely.
- Semaphor 3y agoYeah, but you need to add all those secrets to your backup key. So you need to get it out every time you register somewhere.
- GTP 3y agoI have to admit that I don't own an hardware security key. But since those let you use public key cryptography to login, you could at least theoretically use the same public key for multiple services. Whether the FIDO2 protocol lets you do that or not, I admit I don't know.
- donmcronald 3y agoThe keys are baked in to the devices and are tamper proof. So two devices means you have two different public keys. I use YubiKeys for accounts I consider important and they're a pretty huge hassle compared to a password manager. I'm also scared to get rid of any of the old ones I've got just in case they're linked to an account I forgot about.
- GTP 3y agoI thought you could generate a key on your PC and store it inside the YubiKey, are you sure it isn't possible?
- donmcronald 3y agoIt’s possible, at least for GPG. I’m not sure about WebAuthn. Regardless, generating the key right on the device is the most secure way of doing it. It’s also hard to manage keys you’re loading yourself. Once I loaded a private key onto my YubiKey and accidentally failed to backup the private key because I used the wrong syntax when I exported it. I didn’t even realize until I got a new YubiKey and went to load my GPG keys onto it. I was only using it for signing, so it wasn’t a huge deal, but if I’d been using it for encryption / decryption it would have been a disaster.
- deleted 3y ago[deleted]
- tzs 3y ago> Having a business where you can go to a physical office and show up with ID so you can get your account back would solve this problem. I've wanted something similar, combined with a tree approach to account recovery where the effort for recovery can vary depending on the importance of the account. Say I lose access to my McDonald's account. That's not a very important account. It just contains some reward points that would get me some discounts at McDonald's. That account would be a leaf on the recovery tree. It's parent node would be my email account, currently at Fastmail. Recovery of my McDonald's account would just require responding to a recovery email McDonald's would send to my email. My email account is much more important. Its parent node would be my domain name, currently registered at Namecheap. Recovery of my email account at Fastmail would involve demonstrating to Fastmail that I control my email domain. My domain name is so important, since it is in the ultimate recovery path for so many descendant nodes, it would probably have at least two parent nodes (I didn't say anything about the tree having to be a binary tree). They would be businesses that can verify my ID in person using government documents like my passport, and provide a way for me to prove that identity to third parties. Banks would be good candidates to run such a business. Post offices would also be good candidates. The protocol between the root verifiers and their direct child nodes could be a zero knowledge protocol so that the child node doesn't get your real identity and the root verifier doesn't know who the child node is. All the root needs to learn is that you are being verified for some site, and all the site needs to learn is that you are the same person who set up the account. Such a zero knowledge protocol could also be good for age verification, which more and more jurisdictions are requiring from some sites. With such a protocol between the age verifiers and the sites you could have age verification without giving up anonymous accounts.
- Zababa 3y ago> My domain name is so important, since it is in the ultimate recovery path for so many descendant nodes, it would probably have at least two parent nodes (I didn't say anything about the tree having to be a binary tree). If your domain name can have multiple descendant nodes and multiple parent nodes, is that still a tree?
- tzs 3y ago
- donmcronald 3y ago> Luckily, FIDO2 can fix a lot of these problems. People who don't have significant security needs can use a trusted service (currently Apple, Google, and a few small companies) rather than a physical device. And from the article: > “If I'm Google implementing passkeys, I cede a lot of control to Apple if my user is on an Apple device, I cede a lot of control to Microsoft if the user is on a Windows device, I cede a lot of UX control to Android and browsers,” To me it sounds like Google, Microsoft, Apple, etc. seizing the last bits of control away from the average person. Everyone will be absolutely beholden to a few big tech companies. Using a fake name or birthday on accounts will be unthinkable because a locked account will mean losing access to your life and the only way to get it back will be to verify your identity which better match the info you provided initially. We used to have outrage over things like using real names and now we've somehow fallen to the point where everyone is going to mindlessly accept a scheme that could easily morph into verified identities managed by private companies. Participating online will require a verified identity and everything you do will be mapped back to it.
- jareklupinski 3y agoshout out to all my friends celebrating their 123rd birthdays this year, according my Apple/iCloud shared calendars (1900 cohort)
- TheNewsIsHere 3y agoYubico has proffered a standard enhancement designed to enable FIDO keys to “automatically” enroll a paired backup when you enroll a primary key. They wrote about it here in 2020: https://www.yubico.com/blog/yubico-proposes-webauthn-protocol-extension-to-simplify-backup-security-keys/ https://www.yubico.com/blog/yubico-proposes-webauthn-protoco... I’m not clear on whether it has gained any traction, and it’s not something I see a lot of my peers in security aware of.
- lll-o-lll 3y agoPasskey is a concept that even the majority of tech enthusiasts seem not to have groked as of today. The thing that google/Apple have brought to the table is cloud backup of your private keys (yes, you should have lots of questions about how that is managed). This should enable disaster recovery/device transition for people using a phone as one of their passkeys. You’d probably add a fingerprint from your laptop for convenience, and if that laptop is all you have then no disaster recovery for you. However, to be fair, if people have one of something it’s going to be a phone. If you use google or android, then those keys are backed up into the cloud “securely”. Those keys are also “secured” on the device. Not as good as HSM, but if you dig into the details it’s probably much more solid than you’d expect.
- donmcronald 3y ago> The thing that google/Apple have brought to the table is cloud backup of your private keys (yes, you should have lots of questions about how that is managed). Absolutely. I keep my BitLocker keys in my Microsoft account because it's a simple solution that provides good enough security for me. If someone wants access to my data they have to get the key and my disk. I understand it and I'm satisfied with how it works. With passkeys, having a cloud backup doesn't even make sense to me. If I'm using a YubiKey or a TPM, the private key can't be extracted to back it up, so what do they back up? Do I have to opt in to a weaker system to get cloud backups? At the very least, I should be able to designate trusted parties (parents, siblings, kids) where at least one of them has to approve the recovery of a cloud backup. Microsoft, Google, etc. shouldn't be able to access it at all. I trust my family, not big tech.
- lll-o-lll 3y agoApple, as an example, promise that your keys are end-to-end encrypted and not viewable by Apple themselves. https://support.apple.com/en-au/HT213305#:~:text=Recovery%20security&text=Passkeys%20can%20be%20recovered%20through,and%20other%20data%20it%20contains https://support.apple.com/en-au/HT213305#:~:text=Recovery%20.... Should you trust Apple? Is this secure enough if a password can still be used that recovers all these keys? Ultimately there is always a convenience/security trade-off. The “passkey” concept has it right for the 99% of users case (in my opinion). For that 1%, it’s still WebAuthn, so nothing stops you from using a Yubikey with a second safe-held Yubikey for disaster recovery.
- justsomehnguy 3y ago> We engineers live in a different world No. Some of us, engineers, live in a world where 512b RSA is mandatory to order a pizza. Most of us are sane.
- techwiz137 3y agoI noticed that you seem to have some negative views towards cryptocurrency users and not their ability to store and keep their private keys safe.
- cornholio 3y agoA web password is effectively a private secret, that can be used, for example, to derive a ECC keypair, but this secret is passed around in plain text between your device and the target site or service. It might be encrypted on the wire, but it must be known by both. So any system that replaces web auth passwords is, worst case, just as bad as a password from a key-ownership perspective. Such a system also has the potential to be much better than a password, for example your auth secret is only entered on a secure keyboard (thumb reader, etc.) and used locally on a device you own, which then handles all auth tasks.
- zarzavat 3y agoThe question is how do you recover it when you lose it? For a password I just click the “I forgot my password” link, I get an email with a link to click, and my account is recovered within minutes. I have recovered 15 year old accounts this way. If you can’t do that with passkeys, then the system is doomed to failure because people lose their credentials and devices all the time.
- cornholio 3y agoSurely a system where you have a single point of trust and key backup is better than the current mess of using a single password on multiple sites, like most people do. And no, the solution to that is not security education, people don't change and a system that expects behavioral changes without enforcing them is simply an insecure design. The truth of the matter is that passwords are insecure and problematic for the vast majority of non-technical people.
- dvzk 3y agoYou authenticate to a cloud escrow provider using any of your account's other associated devices. If you have none, because Yellowstone erupted while you were away, and someone also yoinked your phone in the ensuing chaos, then you input either (A) your device's passcode and an SMS code, or (B) a recovery key. If you have neither, then you use an established recovery contact. If those steps didn't work, then it's not too late to visit Wyoming.
- NikolaNovak 3y agoI am in IT but not this side and I must admit I do not grok this move... At all. I don't understand the risk to Benefit story. It seems (possibly incorrectly) to put all my eggs into one basket - whether phone (which annoys the heck out of me as it is NOT my primary device) or some cloudy account I'm supposed to trust with my life. It also seems to impose geographical dependencies (I want to check my email at my friend's but my phone is at home which is precisely why I want to use their computer etc). It also seems to bring terrifying consequences of losing some ethereal items nobody (regular) understands how to safekeep. I feel like I'm an old grouch who wants things to stay the same... And that's kinda the case :-)
- loloquwowndueo 3y agoThe device is not mandated to be a phone. A hardware passkey is also an option. You carry the keys to your home everywhere, don’t you? And you take good care of them? Why would carrying a webauthn-compliant hardware key be any different?
- pqs 3y agoIf I lose the keys to my house, I break the window, enter the house and change the lock. If I use my digital keys, It's over.
- brookst 3y agoHow many times have lost your house keys and needed to break the window and change the lock?
- horsawlarway 3y agoTwice in college, where I needed to have a roommate let me in. Once at my first home, where I climbed in through the bathroom window (this was a PITA - it was some 12 feet off the ground and just barely big enough to get through. Once at my current home, where I just used the porch door that I literally never lock. ---- And I'm actually pretty good about not losing my things. But over a 20 year span, I would have been permanently locked out of digital accounts 4 times if you want to play this game. For me, that's a complete non-starter. So recovery flows will HAVE to exist. At that point, we're right back to where we are now, where I'm much less worried that someone is going to crack the salt+hash of my password, and I'm much more worried that someone will call customer support and pretend to be me.
- dvzk 3y agoCryptocurrencies are a spectacularly bad counterexample. If password-derived private keys had ever become commonplace, the ensuing theft would have absolutely dwarfed the losses from lost wallet keys. I'm not sure if there's even a comparable instance of successful widespread public-key cryptography adoption.
- jrm4 3y agoOne. Hundred. Percent. I have always maintained that 3rd party password managers were a bad idea because now you've got three parties heavily involved instead of two. For most, this is that but worse -- you have essentially have three parties, and the least savvy is the one with the most to lose (maybe the ONLY one with something to lose) -- and is now the one with even less understanding and control. Across the board, getting rid of passwords is a stupid idea. I get that what we have now isn't great, but this is way worse; I am certain this fails repeatedly and badly, unless we do the thing we haven't yet done, which is real cost/penalty/liability for the 3rd parties who get it wrong.
- gwbas1c 3y ago> Why is there no discussion on users losing their private keys? I think that's best handled through some iteration: We don't need to flip a switch and make the whole world change to this system overnight. Instead, we could roll it out in managed environments, like companies and schools with IT departments. I suspect that, for consumers, something like a (the horror!) government agency could handle this. Or a bank. Or your ISP. Or your phone service provider. Or the AAA (who handles passport and license renewals in the US.)
- madbury 3y agoI run a company that cracks passwords for people that have lost the passwords to their crypto wallets. Since the early days in Bitcoin people have been talking about backing up their private keys, and the methods of doing that have become simpler and simpler. Yet we talk to people every day that didn't realize that they can't just "contact Bitcoin" and ask them to reset their password. Some platforms for creating "secure" backups of wallets apparently had back doors built in (BitcoinPaperWallet dot com I'm looking at you!) A non-trivial portion of the population (based on my personal experience) is struggling with mental health issues and true analytical weaknesses that make it really hard for them to understand what's happening, or correctly recall what did happen. Is all of that really compatible with moving secrets into the background (instead of remembering passwords)?