6 ms·
I don’t understand why someone would want to store all their credentials with one of the large tech companies. It seems like this makes it really easy for law e
by marcrosoft 3y ago
I don’t understand why someone would want to store all their credentials with one of the large tech companies. It seems like this makes it really easy for law enforcement to grab access to all accounts easily.
- kccqzy 3y agoWhen you use passkeys with either Apple's iCloud Keychain or Google Password Manager, the key material is end-to-end encrypted. Law enforcement cannot get your passkeys through these two big tech companies.
- marcrosoft 3y agoSo your keychain is symmetrically encrypted with a password and they don’t store that?
- woodruffw 3y agoAmong other things, yes[1]. [1]: https://support.apple.com/guide/security/escrow-security-for-icloud-keychain-sec3e341e75d/web https://support.apple.com/guide/security/escrow-security-for...
- QhwyF3AxE 3y agoThis is a great point. And to respond to the other part of the parent comment about storing "all their credentials with one of the large tech companies" — you don’t even need to do that, if you don’t want to. Apple just extended their Credential Provider API such that passkeys can now be synced using external providers, meaning password manager apps can save and offer passkeys on iOS, iPadOS, and macOS. So you can choose to sync your passkeys with whatever your favorite password manager is. See this page: https://developer.apple.com/passkeys/ https://developer.apple.com/passkeys/ And Google announced a similar API a month or two ago. See the section titled "Passkey support for Android apps" on this page: https://developers.google.com/identity/passkeys/supported-environments#android-passkey-support https://developers.google.com/identity/passkeys/supported-en...
- rjzzleep 3y agoYou guys conveniently ignores the fact that Apple and Google are still the gatekeepers in that scenario.
- iknowstuff 3y agoHow so
- doublepg23 3y agoYes you need to trust your operating system developer to some extent. If your threat model includes not trusting the company that writes the source code to your OS…don’t use computers I guess?
- devsda 3y agoThe concern is not about trust but gatekeeping the providers. For example in the case of email, you generaly dont worry about google reading your email but we should definitely be concerned if gmail allows send & recieve from only few domains or providers it chooses.
- __MatrixMan__ 3y agoSuppose one does trust their OS developers. And they want to use some passkey-protected service. Does that service also have to trust the OS developers? Correct me if I'm wrong, but I'm under the impression that services can decide whose passkey implementations to trust. Seems like that should be up to the user, not the service.
- ptman 3y agoThe user picks the passkey, don't they? Android, Apple or Microsoft. Or Yubikey, or another token.
- shawnz 3y agoBut no more than they are the gatekeepers of your password when you use their keyboard software, right?
- akomtu 3y agoe2e encryption is one forced update away from being plain text.
- kccqzy 3y agoI trust big tech companies more than I trust startups or smaller tech companies. I have faith that neither Apple nor Google would do that. This is a personal belief based on chatting with Apple and Google employees. You don't have to agree.
- pcthrowaway 3y agoRegardless of how much you trust them, the fact that they can force a decryption of these keys (and selectively, per-user, no less) means that you are not in custody of your own authentication identity. Add to that, they can be legally compelled to take such a measure (and I'm sure they will in due time). Compared to using, say, KeepassXC with a unique, secure password per vault. Now you can sync on iCloud or google drive, but neither Google nor Apple can decrypt the vault; the keepassXC maintainers presumably could make a malicious update (which you'd still have to accept, since the updates aren't forced on you), but that would also affect the security of everyone using KeepassXC (and potentially be much more harmful to the economy and society as a whole than the government is willing to accept in order to get intel on an individual person of interest)
- n0zmer 3y agoKeepassXC has a ways to go still before I can trust it. I just attempted to use it again, after a few years, and syncing the DB across google drive randomly caused all of my entries to be erased. No recovery, nothing. just opened the DB one day and all of my saved notes and passwords went poof. It's a know bug, but the fact that it still exists really shows how much the devs care about making it a really rock solid alternative. I've never had this issue with Google passwords, 1password or any other provider.
- pcthrowaway 3y ago
- jojobas 3y agoUntil law enforcement asks them to make an exception for you in a sealed court decision.
- notatoad 3y agoFor apple, yes. but as i understand it, your passkeys are not synced or stored in google password manager, they are only stored on device and never synced through or stored on google servers.
- lern_too_spel 3y agoWhen Apple or Google control the endpoints (the password manager apps on your devices), they can get the keys at the ends if they really want to.
- croes 3y ago>Law enforcement cannot get your passkeys through these two big tech companies. Of course they can, just not from the stored cloud data. But that's just software. One little patch and your cloud sync is without E2E.
- Double_a_92 3y agoWhat is it encrypted by? Or asked differently, what does the user need to have to decrypt it on all their devices? And how can we know that Apple & Co. don't also have access to that? It's not like Law enforcement hacks into your connection, they just force the company to hand out your data.
- jplona 3y agoI think it depends on your threat model. For my personal accounts, I'm more concerned about the risk from badly-managed auth than law enforcement. So from that standpoint, using an established big tech company makes sense. Other people may place different weights on various threats.
- raxxorraxor 3y agoThen we are at passwords again where I can happily exclude both. Convenience might be an advantage, but I don't see me using such an auth solution for my private accounts.
- owlninja 3y agoI lean this way...I know policeman bad and government bad, but 99% of us will pass away and only our family and friends will remember we existed.
- crawshaw 3y agoPut your passkey on a yubikey if you like.
- woodruffw 3y agoPasskeys are WebAuthn under the hood; they don't store your credentials with a large company any more than using a hardware token stores your credentials with Yubikey. Apple does some additional trickery to synchronize credentials between devices, but they get away with this because their devices have contained dedicated silicon for sensitive data management for years[1]. They have some user-facing documentation on how their passkey implementation is synchronized between devices without any secret disclosure here[2][3]. [1]: https://support.apple.com/guide/security/secure-enclave-sec59b0b31ff/web https://support.apple.com/guide/security/secure-enclave-sec5... [2]: https://support.apple.com/en-us/HT213305 https://support.apple.com/en-us/HT213305 [3]: https://support.apple.com/guide/security/keychain-data-protection-secb0694df1a/web https://support.apple.com/guide/security/keychain-data-prote...
- crote 3y agoExcept that passkeys are treated as both a password and token at the same time. They are the sole thing needed to access a website, so you are absolutely storing your credentials with a large tech company.
- lukeschlather 3y agoApple can synchronize the passkey between devices. As far as I understand I cannot. So I don't really understand how this can be said to be a hardware security token. It seems pretty clear that it is as far as I am concerned, but that Apple has nothing constraining them from copying my passkeys. Which seems like the worst of both worlds.
- iknowstuff 3y agoYou can use 3rd party password managers to sync your passkeys however you please. Apple has no access to keychain data: https://support.apple.com/en-us/HT213305 https://support.apple.com/en-us/HT213305
- lukeschlather 3y agoCould you give an example? That support article doesn't mention anything about it. I do recall reading something about that recently, but I read the article and it it made no mention of what syncing passkeys actually means. It sounds like theoretically I could write an app that uses the same APIs Apple uses to sync encrypted credentials between TPMs. But "however you please" sounds suspiciously like "however you please, as long as you don't sync it to anywhere Apple can't vouch for the safety of the keys." Which again, seems like the worst of both worlds.
- throwawaysleep 3y agoAs a law abiding citizen, my willingness to put in extra effort to avoid law enforcement is pretty low.