4 ms·
Why do you believe that introducing support for passkeys inherently makes the situation worse? If you don't trust them, you're not forced to use them; tradition
by metafunctor 3y ago
Why do you believe that introducing support for passkeys inherently makes the situation worse? If you don't trust them, you're not forced to use them; traditional methods still exist.
In any case, you should have multiple methods. It could be passkeys on multiple devices. It could be TOTP, plus recovery codes in a safe. Passkeys are just one more method.
For the longest time, the gold standard for authenticating people has been tamperproof hardware with keys that cannot be copied. Except iPhones actually have credible biometrics on top of that. Much better than Yubikeys, for example. Of course you always need to have at least one backup device or other method in case your primary device is lost. Now that this is finally making it's way to the “normal people”, it's suddenly a “run away screaming” scenario? Come on.
- pseudalopex 3y ago> If you don't trust them, you're not forced to use them; traditional methods still exist. I predict this will not be true always.
- noahtallen 3y agoYes, the security industry is probably going to shift massively to Passkeys over the next few years. Phishing is a massive issue for enterprise security, and Passkeys basically completely fix it. IMO, this also means the problems with Passkeys will get fixed pretty quickly. And given I can already store my Passkey in 1Password and then use it on every device I currently use (including Firefox on mac/windows and iOS Safari), it's honestly not a huge problem. I think passwords are a much bigger problem for people. Simple/re-used passwords are still incredibly common-place, and too many people don't realize how big of a problem that is. Once you incorporate a password manager so that you don't need to remember passwords... Passkeys via a password manager should be even easier to use, given you don't have to rely on browser extensions auto-detecting input fields.
- tharkun__ 3y agoHow do you secure 1Password? With a passkey? See the loop? Or a password? Wait, didn't we want to get rid of passwords? How is that any better? The kinds of people with reused passwords all over the place won't use 1Password. And if you do use 1password to actually generate strong passwords you don't need passkeys and it works on all kinds of services without those having to support passkeys.
- Nathanba 3y agoit's better than a password because good passwords pretty much require to be generated by password managers in this day and age. Which means you can't actually remember them anyway, yet a password is still hackable or guessable Theoretically of course but not really, I've had some fairly long passwords of mine hacked somehow. I assume because a service stored them in plaintext and then got hacked. Make it 40 or 50 characters long, it doesn't matter: It's still just text and it can be stolen from you by remote, digital thievery somehow. The promise of passkeys is that this cannot happen anymore, they'd have to steal your physical device AND your way of unlocking that device. Sure you still need a master password to unlock your password manager but like I mentioned above: You now need this any way because you need a password manager no matter what.
- tharkun__ 3y agoFrom the Last Pass blog about a recent incident: Cloud-based backup storage – contained configuration data, API secrets, third-party integration secrets, customer metadata, and backups of all customer vault data. All sensitive customer vault data, other than URLs, file paths to installed LastPass Windows or macOS software, and certain use cases involving email addresses, were encrypted using our Zero knowledge model and can only be decrypted with a unique encryption key derived from each user’s master password. As a reminder, end user master passwords are never known to LastPass and are not stored or maintained by LastPass – therefore, they were not included in the exfiltrated data. https://blog.lastpass.com/2023/03/security-incident-update-recommended-actions/ https://blog.lastpass.com/2023/03/security-incident-update-r... In other words, the thieves went to the bank vault a d stole your safety deposit box but can't access it because they need your key, which only you posses. If I can store my passkeys in 1password (or lastpass etc) then nobody needs access to my physical phone. They just need access to my password manager's password. I agree that for many many people password managers are way better than alternatives. But they don't magically make everything safe. It's like MFA. "it is all safe now because we will send you a code via SMS" and the people fall for social engineering attacks that make them disclose the code the attacker just had the bank send to them. I doubt such people will be a le to safely use a password manager or passkey for that matter. Passkey are just new enough that we have not had widespread news about how crooks were able to find the weak link(s). Probably on the human side again like in many cases.
- pseudalopex 3y ago> IMO, this also means the problems with Passkeys will get fixed pretty quickly. Apple and Google do not quickly fix things when users have no alternative in my experience. > And given I can already store my Passkey in 1Password and then use it on every device I currently use (including Firefox on mac/windows and iOS Safari), it's honestly not a huge problem. For you. You believe the criticisms are dishonest?
- veeti 3y agoIf passkeys evolve by enterprise requirements it sounds unlikely you'll be able to ever properly export your keys. Instead, you'll get forced attestation to make sure you're not using Linux or some other untrustworthy platform.
- hypothesis 3y ago> If you don't trust them, you're not forced to use them; traditional methods still exist. Still being the operative word. Consider situation with running banking apps without hardware attestation, etc
- eduction 3y agoMuch easier to have spare yubikeys than a spare biometrically secure smartphone. Perfect is the enemy of good.