6 ms·
I'm pretty sure the goal here is to turn your phone into your passkey, _and nothing else_. Everything written in that article makes sense if you keep that in mi
by runiq 3y ago
I'm pretty sure the goal here is to turn your phone into your passkey, _and nothing else_. Everything written in that article makes sense if you keep that in mind.
- microtonal 3y agoApple opened up OS integration for other applications. 1Password is currently doing beta testing of their Passkey implementation. Besides that, the whole idea of Passkey (in contrast to what this blog claims) was that the key material can be synced between devices, so I am not sure how only the phone would be 'a passkey'. iCloud Keychain syncs my Passkeys between all my devices, including to my MacBooks.
- katbyte 3y agoare there many places that use passkey yet? i've not encountered one, or rather not seen a place to make use of it
- tiltowait 3y agoThis website has a list of sites allegedly supporting passkeys: https://passkeys.directory https://passkeys.directory I say "allegedly", because a few of them (Paypal, eBay, a couple others) have never once offered to let me use a passkey. Sites I know, off the top of my head (because I used them in the past 24 hours): * Porkbun * Google * GitHub (if you enable the preview feature) I know I've used more, but I don't have an easy way of searching for them.
- dcow 3y agoeBay and Paypal do, though I don't know how to get it to prompt you to configure a passkey...
- wkat4242 3y agoPayPal only started offering it two weeks so so that's probably why. Ebay I don't know, haven't used that in many years
- katbyte 3y agothanks, do have an account at a couple listed there so might have to give it a try on an unimportant one
- jabbany 3y agoThe problem with cloud-sync-based managers like the iCloud Keychain is bootstrapping. Since you need to be able to log in to the services themselves to provision access to the passwords. This makes travelling a bit risky, since it's not that hard to lose/break/have your devices stolen during a random trip. This makes it immensely hard to recover, since you cannot just hop onto a public terminal and authenticate (which might involve entering 2FA codes etc that you cannot get anymore). This is why physical tokens are still quite useful. They're rather unattractive to thieves, don't require its own Internet connection to work, and they're relatively small and cheap so you can get a bunch them to stuff in various places increasing your chances of having one still available to you.
- froggit 3y ago"It's easy to lose devices when you travel so just get a shit ton of devices. If you're a big enough of a fuckup to lose them all then you've got bigger life problems anyway." I like good advice that, upon hearing it, seems obvious enough it can be misinterpreted as a dig at one's competence. I'm much more likely to follow it and get my ass saved (I'm the kind of medium grade fuckup that would lose all but one of them).
- thrashh 3y agoKnowing ahead of that problem, you can plan a solution though? Everything I have is cloud-synced and even if I lose my phone right now in a random country, I definitely know how I can recover all my 2FA tokens and logins from a random terminal (or preferably a new boxed phone) -- I DO have to remember some passcodes which I otherwise never use but that's not too hard. If Google or Apple implements this, they can design a solution too.
- jabbany 3y ago> I DO have to remember some passcodes which I otherwise never use but that's not too hard. Right, but you're giving up a lot of security to do this, since it implies with these rare passcodes someone else could also bootstrap your logins. With HW tokens, you don't have to worry about recovery passcodes being leaked/hacked (the recommended procedure today is to print out the recovery codes and destroy digital copies).
- jabbany 3y agoThis is a terrible idea though. I had the misfortune of getting into a cycling accident which broke my phone display (completely lost display output and touch input), and it meant I lost access to all my OTP 2FAs for a couple of days (which is actually kind of scary). I was able to fix it myself by getting parts and going through an ifixit guide (right to repair anyone? ;-), after which I promptly exported my 2FA seeds to (1) a backup phone (2) KeePass, which apparently supports them, who knew... and (3) a QR code on a printed piece of paper.
- livueta 3y agoMaybe I'm getting tinfoil-y here, but I think the horribleness is the point: consider how eager Apple in particular is to get people fully enmeshed in their services ecosystem. You're a lot less likely to try to roll your own backup, or otherwise exit the walled garden, if doing so means your entire auth story is irredeemably fucked. The thing that strikes me about this whole story is that during a lot of the initial discussions of passkeys, a common point brought up on the anti-lockin side was the ability to use non-phone providers like yubikeys. If the actual implementations make this less viable, as discussed in the article, then that shifts power towards lock-in.
- yellow_postit 3y agoNot tin foil — Apples privacy pushes (in some markets) are based on driving up lock in and benefiting their ads and apps. Any consumer benefit is a second order impact.
- thoradam 3y agoTin foil — third parties can be passkey providers: https://blog.1password.com/apple-passkey-api-wwdc/ https://blog.1password.com/apple-passkey-api-wwdc/
- danShumway 3y agoI'm pretty nervous about Passkeys for exactly these reasons, and I'm still not at the point where I feel comfortable advocating for them, but I'm forced to admit that if anything, Apple has (so far) arguably done the best job of any of the major tech companies at discouraging vendor lock-in with Passkeys. Blocking attestation requirements, opening up 3rd-party providers earlier, and (I'm not sure if it's released yet) committing to search. I even saw recently that they're releasing Chrome/Edge extensions for Windows to sync keys. Do I trust it? Ehhh... I still can't generate passkeys on Linux as far as I know, so I'm definitely not going to be using them any time soon no matter what. There are still articles like this pointing out abusable features that I'm not sure should even exist in the first place. And it's honestly just going to be a while for me to get over the weird amount of advocacy that so drastically misunderstands what portability even is in the first place (no, 1Password does not make passkeys portable, standardized export/import formats as a requirement for certification make passkeys portable). But I think the signs are that Apple is caring a lot more about avoiding vendor lock-in than Google/Microsoft are right now, which is a very weird thing for me to say.
- donmcronald 3y agoThat's exactly what's happening. Is it really shocking that a collaborative standard is designed to benefit the entrenched big tech companies at the expense of users and would be competitors? Funny how the standards never "accidentally" favor the user. > This leaves few authenticator types which will work properly in this passkey world. Apples own passkeys, Android passkeys, password managers that support webauthn, Windows with TPM 2.0, and Chromium based browsers on MacOS (because of how they use the touchid as a TPM). All of those platforms, with the exception of password managers (which will be forbidden by the vendor lists), also have the compute needed to evolve the system into authorized actions that, IMHO, will eventually lead to devices where specific actions within apps are allowed / disallowed and enforced by the systems that are being sold as authentication (for now). As soon as those tech companies get an encryption / signing key they effectively control (via requests as the relying party), there's going to be a lot of incentive, and ability, for them to seize even more control over our devices.
- SebastianKra 3y agoNo, the idea is to turn _every_ device into your passkey, and also at least one cloud provider of your choice.
- JohnFen 3y agoAnd for those of us who choose no cloud providers at all?
- SebastianKra 3y agoThere's an API for passkeys managers. I'm sure you'll figure something out that matches your criteria.
- silon42 3y agoI fully expect to lose access to all accounts where this is a requirement... I also missed the "Linux" authenticator section.