7 ms·
I Stopped Using Passwords. It's Great–and a Total Mess
- metaphor 3y agohttps://archive.is/3BjRk https://archive.is/3BjRk https://web.archive.org/web/20240210070900/https://www.wired.com/story/stopped-using-passwords-passkeys/ https://web.archive.org/web/20240210070900/https://www.wired...
- raybb 3y agoDo sites generally allow you to have passkeys and passwords set at the same time for the same account? Do you still use TOTP when using passkeys? I guess I will try a passkey today and see how I feel about it. Bummer that it won't work with bitward and mobile yet. If anyone else is curious, I found this site that shows which websites are supporting passkeys. https://passkeys.directory/ https://passkeys.directory/
- jackson1442 3y ago> Do sites generally allow you to have passkeys and passwords set at the same time for the same account? Typically, yes. You can do this today with Github and Google accounts (and certainly at least a few others). The password option might instead be a link in your email or something similar on other websites, but generally I’ve seen it recommended to have at least one other option to get into your account.
- ngrilly 3y ago> Do sites generally allow you to have passkeys and passwords set at the same time for the same account? In my experience, yes. > Do you still use TOTP when using passkeys? No.
- jbotz 3y agoThat "no" is not so unequivocal. TOTPs have two use cases... 1) to prevent replay attacks, 2) as a second factor. While passkeys do the same as TOTPs for #1, they don't by themselves address #2. You may still want to use a TOTP that's generated by a separate device (physically different from your primary device) for #2. Of course if you're using the same password manager to handle both passkeys and generate TOTPs and have that on all your devices then your TOTP wouldn't be a real second factor. Ideally here you'd use one of those TOTP-only devices such as those old RSA "credit cards".
- cassianoleal 3y agoIsn't the whole point of a second factor to prevent a replay attack / credential stuffing?
- rcaught 3y agoWhat? Passkeys support separate physical devices if you want.
- ngrilly 3y agoThe question was "do *you* still use TOTP when using passkeys". I answered "no" because *I* don't use TOPT with my passkeys, but I'm not saying it's not possible or that you shouldn't do it. Personally, as my keys are stored on a physical device, and are unlocked using my biometrics, I consider this as two factors. But I can see how others would prefer two different physical devices.
- namaria 3y agoThe biometric capture angle is so blatant. Plus phisher can and absolutely will catch up to this technically. And the added bonus of lose your phone = you don't exist online. Sounds nightmarish.
- jackson1442 3y agoBiometric capture?
- namaria 3y agoThe endgame here is big tech wants to own identity. Tying our online existence to biometrics managed by their devices is the path towards that future.
- rrr_oh_man 3y agoThis comment needs to be higher up.
- ngrilly 3y agoTwo factors are needed: something you have (your device) + something you are (your biometric). If you're concerned about losing your phone (I am), then you can backup your passkeys to the cloud and/or sync them with other devices (with end-to-end encryption of course, so that the backup/sync service has zero knowledge of your passkeys).
- namaria 3y agoAgreed in principle but I'd rather use something I know than let some corporation manage my biometric data.
- ngrilly 3y agoYour biometric data are only used locally to unlock the secure enclave on your devices. Your biometric data never leave your device and are never shared with "some corporation".
- teo_zero 3y agoPaying a third party to remember passkeys for you should not be the solution, though.
- ngrilly 3y agoYou usually need to pay a third-party for this only if you want/need to backup your passkeys in the cloud and/or sync them between multiple devices (with end-to-end encryption of course, in order for the third-party to not be able to use your passkeys, even if they're hacked). I think that Apple with iCloud Keychain and Google Chrome are doing this for free though.
- card_zero 3y agoWhat form of authentication does one use to log in to the service that stores one's passkeys?
- ngrilly 3y agoDepends on the service. But that's often a long and random backup key that you're advised to store somewhere safe — can be printed on paper — and is used as last resort if you lose all your devices.
- HeatrayEnjoyer 3y agoHow does this work for people who are homeless or other unstable situations and do not have a safe place to store such a key? I can't lose a password in my brain to a mugging or pickpocket. With moderate effort it can be copied but deleting the original is beyond the legal and moral limits of most people.
- teo_zero 3y agoI have a 40-character master password to backup all my other passwords. I've never felt the need to write it down.
- nonrandomstring 3y ago> login details for the 337 accounts I've made—from pizza delivery and airlines to social media and online shopping over more than a decade online. That's a pathological lack of account management and pruning. Likely less than 100 of those are still active and the author will probably use less than 50 of them ever again. A better strategy is to simply not use services that request you "set up an account", or treat them as disposable and set up a new one each time you need an obstinate online service. Edit: Do please have the good manners to make a cogent argument instead of down-voting what you merely disagree with. Is it not apparent that simply having so many accounts is, in itself, a serious security problem you could be addressing?
- y7 3y agoThe reason you're getting downvotes is because your comment is irrelevant. The point of the article is the transition of passwords to passkeys. Minimizing the number of accounts you have has absolutely nothing to do with that. If the point of the article was about optimizing your online security posture, and passkeys as a method for that, then your comment would be more relevant. The reason no one replies and just downvotes, is because we don't want to clutter up the discussion with even more irrelevant comments. Usually I'd do the same, but for the chance that you are really commenting in good faith and not a troll, I thought I'd present you with a learning opportunity.
- nonrandomstring 3y ago> The point of the article It's fine that you found that to be the singular "Point" of the article. Discuss that if you like. But no, sorry, articles do not come stamped with "This is the point from which you will not diverge". My remarks are both relevant and valid and I do not wish you or anyone else to tell me what you think the "Point" of the article is. These comments are made in good faith (please don't bandy specious accusations of trolling) to address what I and many others consider a widespread misunderstanding around password security.
- card_zero 3y ago
- zogomoox 3y agoPasskeys seem to make it harder for you to backup your own private keys to other devices or to paper. Is there an open source Passkey manager yet that allows importing and exporting?
- pmontra 3y agoAnd that I can sync to my other devices. I currently use one of the several keypass managers on my laptop and on my Android devices. As a matter of discipline (not to lose password) I add passwords only on my laptop and I send the db to my mobile devices with syncthing. I don't want to create a new passkey for each site on each device, so syncing is important. Manual export import doesn't work for the same reasons that manual backup doesn't work.
- DreamFlasher 3y agoBitwarden
- DavideNL 3y agoKeepassXC supports exporting, but i don't think it is released in a stable version / to the public yet: https://github.com/keepassxreboot/keepassxc/pull/8825 https://github.com/keepassxreboot/keepassxc/pull/8825
- card_zero 3y agoFrom the linked site about FIDO: > Passkeys replace passwords with cryptographic key pairs [...] synced between the user’s devices via a cloud service. [...] stores an encrypted copy [...] Passkeys can also by design be available only from a single device from which they cannot be copied. > "single-device passkeys” [...] a physical security key could contain multiple single-device passkeys. > [...] generally referred to as “synced passkeys”, and those that never leave a single device are referred to as “device-bound passkeys”. So, your keys will rely on: * The cloud, or * Some specific phone, or * Some specific USB key. > They can’t be guessed, leaked, or stolen So, they can be lost. Also, stolen.
- _cenw 3y agoSynced passkeys usually bound to biometrics or some other rate-limited authentication like a pin, and at least Apple syncs them on your keychain, so it never is unencrypted in the cloud. And the general idea about device-bound passkeys is to enroll them from all your devices (Google encourages you to do so on first sign in from a device), so one surviving device is enough to continue the chain of trust.
- card_zero 3y agoCan you still access somebody else's phone by showing it a photo of their face, or has that been fixed? Perhaps it has to be a video of their face now.
- _cenw 3y agoFace ID never had this issue, it projects a dot matrix on your face and reads back the distortion. The really old Android face unlock did.
- HeatrayEnjoyer 3y agoMany people only have one or two devices. Even if someone owns many, they're only one abusive partner or house fire away from losing them all. Even if I were to instill robust self-custody practices in 90% of the populace (an impossibly high bar if mere password hygiene hasn't caught on in 30 years), the remainder is still millions of people who will be locked out their entire digital life permanently.
- kseifried 3y agoSo there's a high degree of complexity and subtlety to Passkeys. I wrote a paper about this, some key things: ● Passkeys improve security significantly, and while they make some trade-offs concerning security versus usability, they do not introduce any new attacks; they also make many existing attacks much harder or impossible (e.g., brute forcing attacks or credential stuffing) ● Passkeys will bypass the hurdle of getting people to use password managers, and will likely result in the widespread use of biometrics to secure their Passkeys ● Passkeys can potentially make account sharing harder once attestation is supported, something a lot of service vendors are in favor of. Passkeys are also easier to deploy at scale and more reliable, thanks to supporting device synchronization. Passkeys should also reduce the need for account recoveries and lower support costs when compared to passwords ● Passkey client support in both software and secure hardware tokens is widespread and available now on most platforms, browsers and many third-party password managers ● Passkeys are being supported by major vendors (e.g., as of October 10, 2023, Google announced: Passwordless by default: Make the switch to passkeys, for Gmail users, and Google Workspace administrators can enable it) https://cloudsecurityalliance.org/artifacts/beyond-passwords-the-role-of-passkeys-in-modern-web-security https://cloudsecurityalliance.org/artifacts/beyond-passwords... And if you want to quickly check what the passkeys-related capabilities of your preferred platforms are: https://passkeys.dev/device-support/ https://passkeys.dev/device-support/ And to see what the state is of the services you use: https://passkeys.directory/ https://passkeys.directory/ The TL;DR: there's a LOT of good stuff with passkeys, but there are some concerns a lot of people aren't thinking about, e.g. Passkeys as a Requirement vs. Option Implementing Passkeys, as a provider, does not mean that all authentication must be done via Passkeys. For example, the Cloud Security Alliance generally supports SSO via Apple, Google, Linkedin, and Microsoft, and we support a “classic” username and password-style login. The reason for this is simple: not everyone has or can get an account with one of the SSO providers listed. This is also why we do not require 2FA/MFA: you can choose to use 2FA/MFA with your SSO provider, but the Cloud Security Alliance does not require 2FA/MFA to ensure that people who do not have access to a device that supports 2FA/MFA are also able to access and use our systems. However, for many providers, at scale, it is viewed as a better option to get rid of passwords entirely and move people over to Passkeys wholesale. Many also feel that users cannot be asked or given the option to move to Passkeys as they will simply ignore it (and based on seeing multiple 2FA/MFA rollouts, this is true). Requiring Passkeys in favor of passwords will, of course, largely put an end to phishing and credential stuffing against accounts. Phishing and credential stuffing attacks would still be possible against account recovery processes, but as previously discussed, this is not a new or significantly increased vulnerability. Requiring Passkeys also has the ugly possibility of effectively locking out people who do not have access to a device that can use Passkeys (there are still people who do not own a smartphone or computer but instead rely on public access computers, for example). Balancing the overall security health of a large group of users vs. adversely affecting a disadvantaged group is something that vendors deploying Passkeys will need to consider, especially for “free” services that many people rely upon (like email). edit: formatting.
- rcarmo 3y agoI still haven’t seen a good way to handle multi-device usage, either via syncing passkeys across devices (which is tricky across platforms) or via setting multiple passkeys in the same account.