8 ms·
Amazon Passkeys Launched: Response to Consumer Demand with Poor Implementation
- newscracker 3y ago> Recognizing the increasing demand by consumers to enhance security and in particular user convenience, Amazon rolls out passkeys widely across most devices and browsers. This underlines Amazon’s commitment to bend to consumer demand. Which consumer base has demanded enhanced security and convenience (for which passkeys are the proclaimed answer)? The non-tech crowd has no idea what it is and is probably just hearing about it. The tech crowd on a forum like HN seems to be mostly against it because of issues with account recovery and cross-device use that passwords don’t pose. From what I understand, it seems like passkeys may ultimately rely on SMS OTP or similar mechanisms for account recovery. The other likely result would be losing the account forever, especially if the user is a single device one (there are billions of such people around the world). I’m going to wait it out a little longer to see how the interoperability factors play out in reality and learn from those who are braver than me.
- lxgr 3y ago> to enhance security and in particular user convenience What convenience? Amazon's implementation saves me exactly one thing. "Typing my password" (i.e. pressing my password manager's autofill key combination). The annoying part is having to enter my OTP over and over and over again, with the non-functional "don't ask again on this browser" box below serving as a little mocking statement to show that they have indeed thought about this use case – they just haven't bothered to actually implement it.
- circuit10 3y agoI haven’t read the article so I don’t know if this is the same thing as passkeys but most password managers should support TOTP authentication
- BakaRakuda 3y ago> Which consumer base has demanded enhanced security and convenience (for which passkeys are the proclaimed answer)? The non-tech crowd has no idea what it is and is probably just hearing about it. The tech crowd on a forum like HN seems to be mostly against it because of issues with account recovery and cross-device use that passwords don’t pose. Yeah it's going to be mostly the tech crowd at this point, and it will filter down to non-tech people. And we will all be better off when we are all using passkeys. Looking at my girlfriend's computer her password situation is a nightmare of potentially compromised passwords, reuse of weak passwords, among other issues. Even after spending hours trying to clean it up there are still tons. If we were in a passkey only world then no more weak passwords for her to reuse, no chance of phishing said password from her. Even if the server gets hacked there is no password to get pwned. I really don't care what the contingent of passkey haters on here say. A lot of the discourse here isn't what it used to be. Little better than Reddit for techies. > From what I understand, it seems like passkeys may ultimately rely on SMS OTP or similar mechanisms for account recovery. The other likely result would be losing the account forever, especially if the user is a single device one (there are billions of such people around the world). That's not as I understand it. Why would SMS OTP be used? 100% of accounts today will already have a password, that's how you would login if you lose your only passkey device. If/When passwords are not a thing anymore then why wouldn't the recovery use a "lost password" type flow that happens is facilitated via the account email? > I’m going to wait it out a little longer to see how the interoperability factors play out in reality and learn from those who are braver than me. Fair enough, but you can add a passkey to an account and your password will still work. So it's not like it will cause any harm to try it. You can even remove passkeys from an account if you really don't want to use it. The worst thing about passkey support on Amazon is they didn't embrace it completely so you still have to go through all of the login form bullshit instead of being a one step biometric unlock that passkeys can enable.
- stavros 3y agoYou're right about the level of discourse, and it's become especially obvious to me whenever there's a discussion about passkeys. Everyone keeps repeating the same debunked arguments over and over, with only maybe one argument (attestation) holding some water. It's too bad, I'm really excited about passkeys increasing authentication usability (and security second, for me), but most people here seem to want to hold on to passwords, as if they aren't both terrible UX and terrible security.
- lll-o-lll 3y ago> The tech crowd on a forum like HN seems to be mostly against it because of issues with account recovery and cross-device use that passwords don’t pose. Because of an embarrassing amount of ignorance. Own an android phone? An iPhone? Congratulations, your passkeys are on your password manager. You can recover your passwords when you lose your phone right? Exact same mechanism. (Now, if we want to talk about how solid the protection is for apple/google at keeping these private keys safe in their clouds, and how secure something is when one magic password is enough to unlock literally everything, or how confident we can be that the govs won’t be able to get their paws on them, that’s a more nuanced topic).
- mekoka 3y agoYou obviously don't travel. Lose your phone while abroad. Good luck!
- adolph 3y agoAlso a solved problem with keychain managers. Example: With iCloud Keychain, you can keep your passwords (and other secure information) updated across your devices and shared with the people that you trust. https://support.apple.com/en-us/HT204085 https://support.apple.com/en-us/HT204085
- wasmitnetzen 3y ago> keychain managers Proprietary keychain managers. I will not hand Google or Apple the keys for every account I have, or even just the metadata where I have accounts. I'm well aware that they claim that they don't have access to that, but I do not trust them.
- adolph 3y agoAlso third party keychain managers (which are also often proprietary), so no need to hand your preciouses directly to Goaple.
- Double_a_92 3y ago"Normal" people usually have an incredibly hard time managing accounts and their logins. They constantly have to restore account passwords, or just straight up create new accounts. A passkey which is backupped to their Apple or Google accounts will make things easier.
- lxgr 3y agoSorry to be so bitter about this, but at this point, "Amazon botches UX design for feature X" isn't news – "Amazon delivers useable UX" would be. Passkeys are complicated enough, but even as somebody having spent hours looking into WebAuthN and setting up my own smartcard-based NFC authenticator, it took me a while to understand what's going on with Amazon's implementation. - "If you want to add a passkey, use a different cloud service account (example: Apple ID or Google account). Each cloud service account can only have one passkey for Amazon." is what I see in Firefox, for example – what on earth does that mean? Firefox doesn't synchronize passkeys with either of these accounts. The issue is that they don't support platform authenticators on macOS. That error message does not make sense! - Ok, I get it now, so Firefox does not support passkeys, hence the button is greyed out, fair enough. But, wait... 1Password does provide passkey support through their Firefox extension. It works on every other WebAuthN/passkey-supporting site. And 1Password's passkeys do work on Amazon using Chrome! Do they just sniff the user agent here and grey out the button on Firefox? What's going on? - The only option to manage passkeys in my Amazon account is to... delete ALL of them. I guess adding a list of passkeys and the dates they were added, like almost every other service I know supports, was just too much to ask from Amazon. - "If you didn't set up this passkey, please go to your account settings to delete the passkey.". – Oh, right, let me quickly go through the literal dozens of options in my Amazon account page. I get that Amazon does not want to train users to click links from emails (although that ship has arguably sailed, which is why we are getting WebAuthN in the first place: It's phishing-resistant!). But Is it too much to ask to simply reference the path there, i.e. "Your Account -> Login & security -> Passkey" in that message? On the other hand, this is completely in line with my user experience on any Amazon site or product. I wonder if Amazon is even aware of the mere concept of UI/UX design as something other than a half-day task any backend engineer is just expected to do as part of the feature they're shipping.
- jatins 3y ago> Sorry to be so bitter about this, but at this point, "Amazon botches UX design for feature X" isn't news – "Amazon delivers useable UX" would be. (Tangential) I keep saying this: if any other company without a business model as strong as Amazon was run like Amazon they'd be dead. But for some reason execs see Amazon and think "if they can ship and utterly mediocre product and win, so can we" My brother in Christ first build a distribution network that can deliver a million products to my place within 1 day, then you earn the right to ship an eyesore app.
- danShumway 3y agoPasskey transfer across ecosystems is still an unsolved problem, Linux support is lacking, Bitwarden's implementation hasn't launched yet, and there are host of ecosystem issues and caveats that people keep telling me will be ironed out in the future but haven't been ironed out yet. Meanwhile, Amazon botching its rollout is a symptom of the specification not requiring standardized implementations. It's a symptom of the FIDO Alliance just assuming companies will do a good job and won't break everything. Ideally, this would be the point where the Alliance would step in and say, "okay clearly we need to standardize a lot more because y'all can't handle this much leeway in how you implement the standard." Ideally it would give the Alliance pause about other parts of the standard like attestation where they're also being painfully naive about how corporate implementations will go. But instead, the industry seems intent on barrelling forward with passkeys in their current state anyway. Passkeys aren't ready to recommend to normal consumers yet. We still have yet to see any proof that the portability and lock-out problems are actually going to be addressed. Words are cheap, talk to me when there is an official spec for transferring passkeys between ecosystems and when adherence to that spec and allowing export is a requirement for certification. Talk to me when the services that allow only linking one passkey are barred from official certification until they fix the problem. And people say fixes are coming, but nobody in the industry is waiting for them to come. It's not a priority for them. The major companies are showing that they are perfectly willing to recommend a product to consumers in a half-finished state at a point where there is literally no major implementation that allows transferring passkeys between ecosystems and where there serious caveats around linking passkeys to accounts. So what trust am I supposed to have in that? Don't tell me the FIDO Alliance cares about portability or ease of access; the companies involved do not consider lack of portability and access to be a blocker. I consider it irresponsible to recommend passkeys in their current state and irresponsible for companies to be rolling out wide support based on the current state of the ecosystem. I've lost a ton of faith in the entire standard because of how advocates have glossed over issues and because of how the industry is currently showing that actual universal access and universal support and real Open implementations are not a requirement and that they're willing to try pushing consumers onto passkeys before those critical problems are fixed. The whole thing up to this point has felt dishonest and pushy and weird. If the intent from advocates was to build support by papering over the problems, the effect has been the opposite. I'm still aware of the problems, but now I also don't trust the advocates to be honest when talking about the problems. At some point I need to sit down and write up something more detailed about what the timeline has looked like, because I really feel like the conversation around passkeys and the way companies have moved forward with them is a really good example of how to just completely kill consumer trust in a standard that could have theoretically been good.
- snvzz 3y agoAs long as I can still use passwords. I strongly prefer to keep each account independent, so that there's no single point of failure outside of myself.
- ngrilly 3y agoA passkey for one account is independent from a passkey for another account, by design, unlike passwords that can be shared across multiple accounts.
- tehbeard 3y agoThe issue they state isn't password reuse. All the bits and such to generate those passkeys originate on one device... And it's specifically designed for it's security, to not allow the key material be removable from that one device... A device that may end up in the bottom of a canal in Venice... It's then a case of how do you bootstrap back up to having access? - Did you remember to spend money on an additional passkey device? - Did you ensure you don't need the passkey device you lost to access the other device which the passkey syncs with (for the iOS keychain/google whatever options) - Did you remember at each. and. every. account. you. have. to enroll both your primary and secondary passkeys? vs. - You can remember enough to get into email for resets, or there's a note or a thumb drive kept in a drawer that has enough password info (itself possibly password protected) to get you back on your digital feet. I understand the need for not being able to export from a passkey device... but it massively shifts the paradigm of how users need to operate. And puts all the trust in devices.
- Double_a_92 3y agoI had the same concerns. But I think the idea is to have multiple passkeys on different devices for each account. Also the account recovery process should be the same as if you forgot your password. All I miss now is the possibility to backup / sync the passkeys myself, without having to rely on Apple or Google or whatever.
- Brybry 3y ago
- 8note 3y agoWebsite security was recently lampooned by Ryan George: https://youtu.be/5t15a0im-_4 https://youtu.be/5t15a0im-_4
- freitasm 3y agoJust setup passkeys on my Amazon account. 1. Asking for OTP after using a passkey is redundant and annoying 2. Not listing the keys individually makes management hard - I can't remove a single Yubikey, or Windows Hello or my phone. If anything is replaced it will just keep accumulating in my account. It should list each passkey individually and allow me to give a name to each one.
- vdelitz 3y agoI think they are still in some kind of learning phase / silent rollout and hopefully will fix this soon. I already can see that many users who are not that tech-savvy will also have big issues once it comes to managing their passkeys.
- Shank 3y ago> especially for those using browsers like Chrome on Mac, where a QR code was shown instead of explaining that a passkey is not available or just skipping passkeys (QR codes still being a major struggle for most consumers) Chrome on macOS supports passkeys in icloud keychain as of M118. Hiding passkeys because users “struggle” with QR codes is, frankly, stupid.
- _cenw 3y agoI'm more upset it sets up a resident key, but then doesn't take advantage of not even asking me for my email. Waste of a slot if you use a hardware token.
- vdelitz 3y agoI think this might change in a future update or later stage of the rollout. Making use of the "usernameless" behavior is a potential that Amazon currently left on the road.