3 ms·
> who the heck would carry a USB key with them?? Why not? I do this. It's no different from any other physical key like a door key, and I keep it on the same k
by jabbany 3y ago
> who the heck would carry a USB key with them??
Why not? I do this. It's no different from any other physical key like a door key, and I keep it on the same keychain too...
> The passkey is usable anywhere (signed up on my desktop, hopped over to my laptop and signed in there with the same passkey).
I don't see how this conflicts with physical tokens like Yubikeys? The tokens help you "remember" the key like how a physical door key helps you "remember" the bitting (which is the real authentication info).*
Just like passkeys, U2F can also be done using a virtual U2F device if you so choose (https://github.com/bulwarkid/virtual-fido https://github.com/bulwarkid/virtual-fido). And presumably you could create an off-device portable token to store passkeys...
The real problem at the end of the day is just consistent adoption. There's still a ton of 2FA services that don't accept U2F and only use SMS or email codes...
*: This is a simplified take on things but at a high level that's what's happening.
- francislavoie 3y ago> Why not? I do this. Again, you are not the general public. You're a highly technical person. My dad/grandma would never. That's the point.
- jabbany 3y agoAre you saying they don't use any physical keys? That would be surprising to me... I've found it really easy to teach non-technical people how to use U2F tokens. Just tell them it's like a door key but instead of plugging it in and turning, you plug it in and touch. That's all there is. It's been much more intuitive* to my older family members than SMS codes (that sometimes get lost), authenticator apps (that have a huge list of services from which you need to quickly find the one you want and type the code), or password managers (that either cost money or are difficult to set up across devices). *: I know this because I've never had to do "tech support" for family members that have accounts set up to use U2F tokens, but I have had plenty of calls related to "not getting the SMS code" or "the (insert brand) password manager isn't filling in the password for my account!"
- theshrike79 3y agoThe difference is that I can know with significant certainty that shoving my house key in a random lock won't copy the form of my key and send it to a 3D printer where a thief will get it and use it to access my house. How can I know that won't happen when I use my USB dongle on a random coffee shop public computer?
- MayeulC 3y agoA random lock (or a street-level camera FWIW [1]) would be better positioned to extract enough data to reproduce the key. U2F tokens are "Trusted Platform Modules" of sorts. The keys themselves are never visible to the devices you plug them in. They are capable of answering challenge/responses, and having the URL part of the challenge prevents phishing[2]. I am much more comfortable not typing any password on a public computer. [1]: https://www.wired.com/2015/09/lockpickers-3-d-print-tsa-luggage-keys-leaked-photos/ https://www.wired.com/2015/09/lockpickers-3-d-print-tsa-lugg... [2]: https://en.wikipedia.org/wiki/Universal_2nd_Factor#Advantages_(and_disadvantages) https://en.wikipedia.org/wiki/Universal_2nd_Factor#Advantage...
- UncleMeat 3y agoOkay. How is that different from a password? How can you know that when you type your password into a random coffee shop public computer that the computer isn't running a keylogger and sending your credentials to criminals?
- jabbany 3y agoThis is exactly what U2F protects you from! You can actually safely plug U2F tokens into random computers and rest assured that the keys inside cannot be cloned. This provides security guarantees above and beyond that of physical keys! In fact, an untrusted computer can't* even MITM the authentication process of U2F, unlike with SMS codes! (Of course, an untrusted computer could fake the UI to try and exfiltrate other info from you, but that's beyond the scope of authentication itself.) The worst a malicious client can do to a U2F token is to fry it :-) *: There's some asterisks here, but if you want to know the details check out the U2F spec or this https://www.yubico.com/blog/creating-unphishable-security-key/ https://www.yubico.com/blog/creating-unphishable-security-ke... for a more accessible explanation. Banking-grade U2F/similar tokens actually behave like hardware crypto wallets and will show the auth request metadata on an internal screen, in case the device you are plugging into is completely untrustworthy.