6 ms·
A main idea of passkeys is that the private keys are bound to hardware and cannot be copied. Using the private key is subject to biometric authentication. Thi
by metafunctor 3y ago
A main idea of passkeys is that the private keys are bound to hardware and cannot be copied. Using the private key is subject to biometric authentication. This eliminates a whole category of issues where the private key could get stolen.
So no, writing down the SSH private key is not the solution. The solution is to trust multiple private keys, each stored within tamperproof hardware.
This is also why, as a service provider, I'd like to see some device attestation. I want to know that the keys being used here are not written on a fucking piece of paper.
- hypothesis 3y ago> This is also why, as a service provider, I'd like to see some device attestation. I want to know that the keys being used here are not written on a fucking piece of paper. This is precisely why user should run away. Service provider is moving liability to end user and washing their hand away, while user gets screwed if anything happens during vacation.
- 0cf8612b2e1e 3y agoIt sounds like I am up the creek if all of my devices are gone. With a bank, if I lose paperwork, they will have a process in place for me to prove my identity. BigTech will shrug if my phone-locked passkey becomes inaccessible.
- FireBeyond 3y ago100%. The effort and hassle for Google et al to invest in robust support mechanisms (backend and people) for passkeys makes it highly unlikely. No doubt you'll get the standard boilerplate email responses, if you are even that lucky, that just point you to an FAQ or something similarly unhelpful.
- ungamedplayer 3y agoI recently watched a movie called the circle with Emma Watson where they want to tie the account with a corporation as a means of Id to register to vote. Imagine leaving identity to a corporate who simply shrugs off all but legal threats. It's terrifying and I reckon we are in our way there
- arzig 3y agoI strongly recommend the book. It’s considerably better and gets into the dystopia better.
- hyperdimension 3y agoYeah, off-topic but I definitely agree. The book is an easy read and good. I didn't know there was a movie; I should watch it.
- ungamedplayer 3y agoThank you for the recommendation. It's now on my list.
- insanitybit 3y agoThe initial poster described that process - you bring government IDs in person to an office. If you want to avoid that, just set up multiple devices.
- raxxorraxor 3y agoOr use a password. Seriously, you have to do better here. I guess we will see recovery options by a master password and then the mechanism would be the question again.
- idle_zealot 3y ago> as a service provider, I'd like to see some device attestation As a user I hope you don't get it. Having an easy way for services to require that everyone using them is doing so via the official app on an iPhone or OEM Android phone sounds like a nightmare.
- javagram 3y ago> A main idea of passkeys is that the private keys are bound to hardware and cannot be copied. This seems incorrect. “ Like passwords, passkeys are encrypted and stored in your iCloud Keychain” I also just recently set up some passkeys via 1Password and they are also not hardware bound.
- brnt 3y agoWhy is a piece of paper not a piece of hardware? We do this for TOTP too as a last resort, nothing wrong with that.
- joshuamorton 3y agoTotp is phishable. Passkeys aren't phishable. At the point where the user can access the private keys phishing is once again a concern. If I can't access my pk, I cannot be phished. As soon as you allow me to copy my key (instead of creating many, which should be acceptable) I can be phished again.
- brnt 3y agoPasskeys are stealable no? If I have you phone...
- joshuamorton 3y agoYou still need my password or fingerprint to usea passkey, and can't transfer it from my device to yours.
- brnt 3y agoDoesn't sound a whole lot different from TOTP to me.
- joshuamorton 3y agoYou can't MITM a passkey, you can MITM a TOTP challenge. That is, passkeys cannot be phished. The only way to get into my passkey protected account is to physically gain access to my passkey device, which requires both physical access to the device, and a second factor like a face/fingperprint or PIN/password. Additionally, the TOTP secret can be copied, while today passkeys don't allow that either.
- zappb 3y agoWhat kinds of services would benefit from this level of security? I could see it being useful in corporate contexts (like locking down which machines are allowed to remotely control other machines), but not as much from a general consumer point of view.
- mr_toad 3y agoAt least with enterprise IT, or a bank etc you can pester them until they let you back in. They’ll have to sort it out eventually. That’s not going to work with Google or most web services. Any web service that locks accounts to devices is going to be shedding customers as they lose or replace phones.
- JohnFen 3y ago> The solution is to trust multiple private keys, each stored within tamperproof hardware. But as a user, this is not a realistic solution. If I have to keep multiple pieces of hardware enrolled, that means that I have to keep all the multiple pieces of hardware at hand when I create an account somewhere, and go through multiple enrollment cycles. That means that I have to keep all the various pieces of hardware in the same physical location and relatively easy to access, which removes a great deal of the safety of redundancy. It's just not realistically workable for me. > I want to know that the keys being used here are not written on a fucking piece of paper. Why do you care?