6 ms·
Is it the _goal_ of FIDO to get rid of passwords? If it is, I am against this industry group. Passwords should always be kept as a valid authentication method
by throw7 3y ago
Is it the _goal_ of FIDO to get rid of passwords? If it is, I am against this industry group.
Passwords should always be kept as a valid authentication method.
The OP brings up a point about not having access to the private key... I agree with that. If I don't have access to the private key (like I currently do with ssh) then it's dead in the water to me.
- cyberax 3y agoWith passkeys the private keys are accessible. They have to be, because they need to be synced across devices. The OS will try to protect these keys by putting them in a protected process, with all kinds of safeguards. But in the end, the private keys will still be available. FIDO also supports device authenticators, where the private key (by design) never leaves the hardware. These devices can be used for the true 2FA.
- growse 3y ago> Passwords should always be kept as a valid authentication method Why? > If I don't have access to the private key (like I currently do with ssh) then it's dead in the water to me. You don't have 'access' to the private key for any well designed HSM either. And there's nothing in the passkey spec that says you need to put the private key in at inaccessible place.
- effie 3y ago> Why? Because access by password provides unique abilities to the person who knows the password.
- drdaeman 3y agoHow losing a private key is different from losing a password? Memorable passwords should be either an exception (like master passwords) or a device-specific thing. And private keys do not have to be locked to a HSM. If this really matters, private keys can also be memorized if they were derived by a KDF, using a seed phrase.
- deleted 3y ago[deleted]