5 ms·
> What it does is promotes further centralisation, because most users will use one of the big providers. Because there are no easy non-centralised solutions (t
by throwaway2056 3y ago
> What it does is promotes further centralisation, because most users will use one of the big providers.
Because there are no easy non-centralised solutions (that works for Average Joe)?
Remember
Average Joe cannot
- backup keepass
- 3-2-1 backups using ZFS
BTW, if so many average Joe's lost google accounts then there would be outrage and great chaos (like ticketmaster etc). So some people lost Google accounts - true. Same some people list U2F key.
> the tech industry, including the tech press, n
Pragmatism will win.
This reminds me of IRC vs WhatsApp (or Signal). People want things to be simple.
- danShumway 3y ago> People want things to be simple. As a reminder, if you ask what the best way is to back up a Yubikey, the advice is: - Buy a second Yubikey - Store it in a separate physical location, preferably within a fireproof safe - Whenever you make a new account, set yourself a reminder to go get your second Yubikey, log in with the first Yubikey and then go through whatever process the site has (on a site-by-site basis without a consistent UI) and add the second Yubikey as another credential. - Then go back to whatever secondary location you've chosen and put the second Yubikey back. - And then repeat that process every single time you make a new account. In contrast, dragging a KeePassXC vault into a Dropbox folder one time and just leaving it there and using it from Dropbox is incredibly simple and I feel like pretty much anyone is capable of doing that.
- cyphar 3y agoIf you don't need a proper second factor, just set up TOTP and store it in KeePassXC. There is little benefit to a WebAuthn/FIFO "key" stored in your password manager over a password manager with your TOTP stored in it -- almost all of the benefits of WebAuthn (making phishing much harder) already exist with password managers that auto-fill. There are usecases where you need proper multi-factor authentication, and in those cases you are either a professional (meaning you can handle backups yourself) or you're working for a large company where the management of the keys is done by IT and normal workers don't have to care about it.
- danShumway 3y agoI disagree that a proper key-based solution wouldn't have security benefits (auto-fill doesn't always work and is more vulnerable to phishing). But I also really want to be clear here that we are not talking about multi-factor authentication in the long run. The explicit goal of Google/Microsoft/Apple is to get rid of passwords. Passkey is designed as a replacement for passwords. It's not a replacement right now, but that is the intention, they are not thinking about having a Yubikey as a second-factor for login.
- cyphar 3y agoWhen I said "auto-fill", I was referring to auto-fill with a browser extension where the website is checked. Yes, the FIDO method is even nicer from a technical perspective, but from a security perspective they are similar. But of course, you can be phished into copying your password into a phishing site. So there are benefits, but it's not a huge difference in this one specific context (no physical token, using a password manager with a browser-extension-based auto-fill).
- throwaway2056 3y agoYou are lucky if you find a mum with 3 kids or cafe owner or a fruit seller using TOTP in keepassXC. Do you know they would prefer a phone (not laptop/desktop)? They dont have laptop.
- cyphar 3y agoThe HN article we are commenting on is about a PR to add a feature to KeePassXC.
- throwaway2056 3y ago> Buy a second Yubikey I can (as a geek) but this is a problem for average Joe or a single mum with 2 kids. This is the reason even banks or <your employer> incl. Federal places uses Cisco DUO not an opensource solution. Most things are for average customer. passkeys are great - Assuming a person keeps one password (either Apple or Google OK) - Phishing for them is reduced - No need to squeeze brain for was it username or email address (for login field) - Most phones have fingerprint (even < $60 in developing world too with Android) - Passkeys work from Android 9 onwards - At the end some one needs to compromise.
- danShumway 3y ago- And they can't move ecosystems. - And logging into your bank requires a proprietary device. Let's be clear about what we're "compromising" about. If passkeys are going to be a replacement for passwords (and Google/Microsoft/Apple are very up-front about the fact that they want passkeys to be a replacement for passwords) they have to handle all of the use cases. But even if that wasn't the case and they could just target the general consumer, the downsides here are not just for techy people. The platform lock-in will absolutely affect ordinary people as well. It'll mean that when your family member that doesn't know to make backups loses their iPhone, the only way to get those keys back will be to buy another iPhone.
- throwaway2056 3y ago> ecosystems A majority don't. A majority use their phones/banks rather than analysing ecosystems. > It'll mean that when your family member that doesn't know to make backups loses their iPhone, the only way to get those keys back will be to buy another iPhone. That is acceptable solution. Buy and then move on with life. Everything will be back after your shell out $$ (android). But with local will the family member send the hard disk or USB disk containing keys to recovery? Which recovery company? Will they be honest? Whereas if you want to new phone - all works then easy. People want simplicity. Really thats it. (Again it may be sad for those that don't want to carry phone but the world is designed for average user). BTW, why do you thing banks are using proprietary device. Ask the HN -er to - make it possible using U2F or TOTP keys (QR code) - the same HN-user likes to implement flashy APP - so that they - track, help whatever
- fn-mote 3y agoTicketmaster outrage has exactly the same effect as complaints against Google. Average Joe has no idea whatsoever how to complain and get noticed. That's like saying "If shoplifting were so common there would be police in every store." Nope, it's just the cost of doing business. Cloud backup works for average users. That includes keypass. Heck, even HN users do it that way. The only difference is that we have 16 word DiceWare passwords and key files on YubiKey devices. The scariest problem to me isn't centralization, it's a lack of recourse when things go wrong.
- throwaway2056 3y ago> tcketmaster IIRC, nothing changed. Take for example practices of PayPal or VISA etc. Nothing changed. > Cloud backup works for average users. That includes keypass. Heck, even HN users do it that way. The only difference is that we have 16 word DiceWare passwords and key files on YubiKey devices. Sorry most HN users are the ones building closed systems. Sure, they work in FAANG for 10 years - get enough $$$M then sure complain things are NOT open. > it's a lack of recourse when things go wrong. but does it happen outside of banking etc. Most average Joe does not keep 10 year old email like a geek. They keep moving on. I am a 20 year veteran of linux user. Sadly and frustratingly - There is no easy open solution for google drive or docs - Dont ask average Joe to do hosting/nextcloud etc - I wish some one like FSF, Linux foundatation built some products that are usable (like firefox phone). Even during firefox phone sales, I found most of the EU devs were using for their daily use iPhone or expensive Samsung Galaxy. It is ridiculous to tell others to use 512MB or 1GB firefox phone when they used state of art - Even recently I wanted to implement something like Codeberg at a large University. No help from their side.
- signal11 3y ago> BTW, if so many average Joe's lost google accounts then there would be outrage and great chaos (like ticketmaster etc). So some people lost Google accounts - true. Same some people list U2F key. They don’t “lose” Google accounts or Meta accounts or whatever. They’re locked out. In many cases, it appears lockouts can be triggered even by external events, including bad actors. Most companies are famously opaque on how lockouts happen, but there’s enough affected users out there to start forming some hypotheses. Your argument is that the failure rate is so small, it doesn’t matter. “We’ll worry about it when the failure rate increases.” This is what lack of accountability looks like, because you’re completely oblivious to the human consequences of even one failure. Organisationally, companies like Google or Meta want billions of users, and want to manage the keys to their users’ digital universe, but don’t want to put in decent redressal processes for when things go wrong. It’s not a tenable situation. Either the public will need to reevaluate how much they can trust big providers, or big providers might find legislation or legal action directing them to do better.