4 ms·
> We found that Linux and Firefox users struggled to use passkeys, as those platforms don’t yet have strong support for passkeys. > As a result, we decided to
by dilippkumar 3y ago
> We found that Linux and Firefox users struggled to use passkeys, as those platforms don’t yet have strong support for passkeys.
> As a result, we decided to enable cross-device registration of passkeys. That means, you can register a passkey on your phone while you’re using your desktop. The passkey lives in the phone, but users can connect it to their desktop and set-up and authenticate through the desktop’s browser. This enables Linux and Firefox users to set up passkeys.
This has always been the real no-go for me when I was implementing auth.
I looked into supporting passkeys and found that they're basically useless unless you can make some strong guarantees about who/what can access the keys stored on the device. Linux and the various BSDs can not do this today (and likely will ever be able to do this well given that someone can always recompile a malicious OS that pretends to be another well-trusted OS).
If a user needs to reach to their phone to log into something on their laptop - that's never going to be really secure. It's only a matter of time before everyone starts having "We will never ask for you to log in through your phone, don't do this if someone asks you to" warning labels and respawn the entire industry of anti-phishing mechanisms for this new attack vector.
- butz 3y agoDid any Linux distro showed any interest to implement Passkeys? Ubuntu and Fedora are probably most likely to do something about it first. Ubuntu already has encryption that uses TPM chip.
- hex-m 3y agoIf you mean "FIDO2 platform authenticator", this project looks promising: https://github.com/AlfioEmanueleFresta/xdg-credentials-portal https://github.com/AlfioEmanueleFresta/xdg-credentials-porta...
- kevincox 3y ago> and likely will ever be able to do this well given that someone can always recompile a malicious OS that pretends to be another well-trusted OS I don't understand your concern here. Do you mean an evil-maid style attack? At some point you need to trust the user to keep their device secure. A Windows can also have malware.
- wkat4242 3y agoLinux supports Yubikeys though, in Chrome and Firefox. It's a really secure way of using the same mechanism that is passkeys. I'm even using it on my FreeBSD desktop.
- BillinghamJ 3y agoAll forms of FIDO2 authentication do fundamentally rely on being able to trust the browser to not misrepresent the "relying party" (the RP, aka the registered domain, github.com in this case) They are phishing resistant, even when using the cross-device QR code thing, but that does rely on some base level of trust in the user agent At the end of the day though, if the browser is the malicious actor, there's simply nothing you can do. That is not a realistic or defensible scenario in most threat models Passkeys do represent an enormous improvement in security for users, including in the scenario you've highlighted I know in traditional auth setups, that kind of situation does tend to invite additional concerns, but (again assuming you trust the user agent) FIDO2 still provides full protection when that's happening