3 ms·
I might regret this but I have an (almost finished) draft of a paper on Passkeys, it is available, with comments enabled (which will be turned off if vandalism
by kseifried 3y ago
I might regret this but I have an (almost finished) draft of a paper on Passkeys, it is available, with comments enabled (which will be turned off if vandalism becomes a problem) at:
https://docs.google.com/document/d/1eBjQDWkbqXJSL4GRrAdTUcAx2mVRA9YeTJKr2JgnT0U/edit?usp=sharing https://docs.google.com/document/d/1eBjQDWkbqXJSL4GRrAdTUcAx...
TL;DR:
============
Major insights in this paper:
Passkeys level up security, and while Passkeys make some tradeoffs concerning security vs. usability, they do not introduce any new attacks and make many existing attacks much harder or impossible (e.g. brute forcing attacks or credential stuffing)
Passkeys will bypass the hurdle of getting people to start using password managers, and will likely result in the widespread use of biometrics to secure Passkeys
Passkeys can potentially make account sharing harder once attestation is supported, something a lot of service vendors are in favor of. Passkeys are also easier to deploy and reliable due to optional device synchronization, which should reduce the need for account recoveries and lower support costs
Passkey client support in both software and secure hardware tokens is widespread and available now on most platforms, browsers and most third-party password managers
Passkeys are being deployed by major vendors (e.g. Google https://blog.google/technology/safety-security/passkeys-default-google-accounts/ https://blog.google/technology/safety-security/passkeys-defa...)
============
Conclusion:
No new significant risks or attacks are introduced from the threat model perspective. From a usability and reliability perspective, Passkeys are infinitely better than passwords. Finally, from a support perspective, chances are that if you currently use a system to manage your passwords, it already has Passkey support. For high-security applications, you can also choose to use your hardware token.
Web applications and websites are becoming increasingly critical to everyday life (banking, healthcare, education, shopping, etc.). We must improve security across the board and get rid of old and insecure things like usernames and passwords. The world has also changed, and virtually everyone has a smartphone, something unimaginable even ten years ago, let alone twenty.
Simply put, in every situation where you use a password, you should upgrade to a Passkey if possible.
- drdaeman 3y ago> one common strategy is via displaying a QR code The problem with Passkeys is not that it's not possible, but that the standard is lacking any guidelines for things like this. There is no interoperability in general, it's accidental at best. And this is concerning. Same goes for a lot of aspects that are attributed to Passkeys as "this can be solved this way", but in no way documented (in a way promoted by any major vendor), let alone standardized, let alone be required by some standard to be "Passkey-compliant". In short, I think this can be summarized as "Passkeys lack proper standardized best practices document, encouraged by renown parties". It is wrong to hand-wave at some specific implementation and say that because that implementation is okay, the whole standard is fine. ---- Also, you may consider adding another concern, "authenticator must be physically present to be registered". This limits ability to add new devices (which was not an issue with other systems, such as TLS client certificates). In simple terms, one cannot add a Yubikey that lies in a safe in a secure vault under a mountain, they must have it at hand, when they're online. This Passkeys/Webauthn limitation leads to people having significantly greater difficulty adding backup options, contributing to higher chances of getting locked out (temporarily or permanently) that it could've been, would Passkeys be designed differently. ---- Both things don't explicitly introduce any new weaknesses, compared to passwords. But the problem with Passkeys is that they're here to stay for a long while. So a push towards "you must fix this before it's too late" petitioning collective FAANG (who are the only entities that were able to push asymmetric crypto to web, no grassroots movement was able to do this - many attempts were made and all had died in oblivion) is extremely important.