5 ms·
Every time I see a long inscrutable discussion about Passkeys, I see a weird avoidance of the "something you know" part of security. Here in the US, courts and
by tunesmith 2y ago
Every time I see a long inscrutable discussion about Passkeys, I see a weird avoidance of the "something you know" part of security. Here in the US, courts and law enforcement have every right to get your username, fingerprint, retina scan, face ID, whatever. But they don't have the right to extract something from your brain. Unless I'm missing something basic (which at this point, I don't think is my fault since this whole thing appears incredibly difficult to explain), Passkeys skips past that whole thing in favor of making it a heck of a lot easier to replace "something you know" with "something you have". Which is a security nightmare.
- victor106 2y ago> But they don't have the right to extract something from your brain. Most folks store passwords in password managers and don't use their brains to retrieve them.
- SkyPuncher 2y agoBut my password manager locks….requiring something stored in my brain.
- Fire-Dragon-DoL 2y agoDoesn't your password manager use biometrics to unlock though?
- fabrice_d 2y agoNot necessarily. I use bitwarden with a master password to unlock the vault.
- doubled112 2y agoI stick with passphrases so nobody steals my retina or thumb.
- SkyPuncher 2y agoYes, but that’s locked behind an OS level pass screen.
- noahtallen 2y agoWhich is exactly where your passkeys can be stored too. Put them in a password manager like 1Password, disable biometrics, and law enforcement would have to enter a password to access them
- whymauri 2y agopassword managers are growing, but I'm not sure that 'most' people use them. Maybe 'most' software engineers or techies, but the average person probably has no idea what a password manager is.
- rileymat2 2y agoThey may not know the name of a password manager, but many may know their iPhone remembers and fills in passwords.
- yonatan8070 2y agoSame goes for Chrome and Firefox on all platforms
- static_motion 2y agoWhich is an overall terrible idea since passwords saved by browsers are saved in plaintext and are very easy to get to.
- BuyMyBitcoins 2y ago>”the average person probably has no idea what a password manager is.” In my experience, that’s a notebook or piece of scrap paper next to the PC with all their usernames and passwords scribbled on it. That being said, all of the friends and extended family members that I have helped with computer issues have chosen to save several passwords in their browser’s autofill. Yet, none of them knew that they could view and edit these passwords.
- 2y ago
- tunesmith 2y agoWhich is a bad idea. Right? That counterpoint defends a bad idea. We should be against the practice of permanently-unlocked password managers, and password managers that are only locked by "something you have". People also create ssh keys with null passwords, but it's also a bad idea and we should be opposed to that.
- imwillofficial 2y agoMost folks do not do this. Although they should be.
- LamaOfRuin 2y agoKeys can require a pin (or maybe a password depending on implementation). But in general I haven't felt these are secure enough for the reason you say. While my practical threat model today would make passkeys seem great, the theoretical future threat model in my head does not support it.
- kevincox 2y agoPINs and passwords on HSM keys like this are typically very secure as they will wipe themselves or at least lock themselves after a small number of failed attempts. For example if you only allow 5 failed attempts a 4 digit random PIN has a 0.05% chance of being guessed and a 6 digit PIN is 0.0005%. So the only real risk is key extraction, hardware key extraction is always possible but likely incredibly expensive, so for most threat models it is not an issue. (Software key extraction or side channels is a different problem which may be easier but in theory is not possible.)
- franga2000 2y agoPIN+limit is still a much worse user experience than a password: - a PIN is hard to memorize, so people are more likely to use personally-relevant or common numbers, whereas a password can be easily be both complex and memorable - it's easy to burn through even 10 login attempts through any combination of temporary/permanent disability, stress, being drunk, damaged device... - a wipe-after-failed-attempts system is trivial to abuse, be it by a prankster or a real adversary - it's much easier to see someone's PIN over their shoulder or film them entering it
- Ferret7446 2y agoPINs can include all characters just like a password. They're called PINs for historical reasons. (This does depend on the specific key/protocol.)
- GenerocUsername 2y agoGreat, so we are back to passwords then
- wayeq 2y ago> But they don't have the right to extract something from your brain. sure they do if, unless you want to be held in contempt of court for not providing the information.
- echoangle 2y agoDon’t you have a right to not incriminate yourself? You only have to give them information as long as you’re not incriminating yourself, right?
- saulrh 2y agoHistorically, US courts have declared that giving a password is proof that you control the given asset and that this can be incriminating. In practice, juries will take a refusal to divulge a password as evidence of guilt, the cops will use it as an excuse for even greater brutality, the FBI is perfectly willing to hold you without trial for years on end, and in most cases they don't need it anyway because everything lives on someone else's computer and they're perfectly willing to hand your data over if they haven't already. Furthermore, because the defense is founded on the principle that the password serves as evidence that you owned the encrypted data, if the prosecution is able to prove that you owned the encrypted data in any other way, that protection goes away. > In Boucher, production of the unencrypted > drive was deemed not to be a self-incriminating > act, as the government already had > sufficient evidence to tie the encrypted > data to the defendant I am, of course, not a lawyer. I'm just summarizing easily available information, i.e. wikipedia.
- orthecreedence 2y agoYou cannot be compelled (in US court, anyway) to give up encryption passwords/keys. You can certainly be compelled in a black site torture den, but most people don't have that as a looming threat yet.
- HeatrayEnjoyer 2y ago> You cannot be compelled (in US court, anyway) to give up encryption passwords/keys. Multiple people have been held in contempt for refusing to provide an encryption password by US courts.