11 ms·
Introducing passkey support to Fastmail
- sho 2y agoI like and use fastmail but I'm yet to hear any sort of convincing argument why passkeys are better for me in any way, shape or form than passwords (with a password manager)?
- toomuchtodo 2y agohttps://fusionauth.io/blog/why-passkeys-matter https://fusionauth.io/blog/why-passkeys-matter https://coderoasis.com/passkeys-will-replace-passwords/ https://coderoasis.com/passkeys-will-replace-passwords/ https://developer.apple.com/videos/play/wwdc2022/10092/ https://developer.apple.com/videos/play/wwdc2022/10092/ https://arstechnica.com/information-technology/2023/05/passkeys-may-not-be-for-you-but-they-are-safe-and-easy-heres-why/ https://arstechnica.com/information-technology/2023/05/passk... TLDR Replaces secret strings with crypto primitives mostly automatically managed.
- eep_social 2y ago> mostly automatically managed boosters have yet to address this particular elephant to doubters’ satisfaction
- toomuchtodo 2y agoDoubters gonna doubt, it's shipping to hundreds of millions of people today, and their passkeys are backed up to either iCloud Keychain or Google Password Manager (depending on ecosystem). If you have a password manager, that's great! Most people do not, and this is easier for them.
- tomjen3 2y agoYeah it’s easier than ever right until you lose your iPhone and buy an android.
- deleted 2y ago[deleted]
- bscphil 2y agoDo you have examples of a few popular sites that support them? I honestly don't know that I've seen one, unless the Apple / Google / Github / Gitlab "single sign on" links have all quietly switched to using passkeys under the hood (I thought they were all OAuth 2.0). Would be frustrating if so, because it wouldn't provide for custom / hardware implementations of the standard.
- toomuchtodo 2y agohttps://www.theverge.com/2024/7/30/24209395/dashlane-passkey-report-adoption-passwordless-sign-on https://www.theverge.com/2024/7/30/24209395/dashlane-passkey... https://www.theverge.com/2024/5/2/24147030/google-passkey-passwordless-authentication-400-million-accounts https://www.theverge.com/2024/5/2/24147030/google-passkey-pa... https://passkeys-directory.dashlane.com/ https://passkeys-directory.dashlane.com/ https://passkeys.directory/ https://passkeys.directory/
- bscphil 2y agoSeems like the overwhelming majority of the listed sites require you to already have an account, then go to a difficult-to-find URL on a settings page, enroll a passkey, and then you can login with the passkey. So granted, a handful of sites support it, but I have trouble believing the Google number. Maybe that's including people using their device to sign into Google itself? Putting myself in the position of a typical user, passkeys haven't "replaced" passwords until I don't have a password for Home Depot or what have you. Otherwise there's still a password I have to write down or remember somewhere. I'm not even here as a hater - I do like the idea of cryptographic authentication replacing passwords - but I'm just saying I've seen zero real world uptake of this so far.
- nixosbestos 2y agoEr, Google uses Passkeys and yes is an OAuth2/OIDC IdP for federated sign-in. I think you're missing the point though. I can still login to Google and Tailscale without ever typing a single password, trusting my url bar/eyes, sharing any secret material, etc.
- eep_social 2y agoalways disappointed to hear “well it’s good because we already built it this way” as a deflection. you will, of course, do what you like but the flippant attitude is a showcase of why the boosters have failed to bring the doubters along. reassuring to hear that I can further offload my login security to an opaque fortune 500 of my “choice” if, when challenged, one is unwilling to acknowledge the trade offs that indicates that they don’t understand them which suggests that they should not be trusted, in short. forced passkeys are coming and I do not believe that is a good thing.
- yurrzz 2y agoA lot of advertising on this page, but this is 1passwords explanation of the difference. https://1password.com/product/passkeys https://1password.com/product/passkeys
- peppertree 2y agoFaceID.
- rlayton2 2y agoThe article does a pretty good job of making this argument, including your (and my initial!) question about why not to just use password managers.
- athrun 2y agoThe announcement post from Fastmail does a good job at listing the advantages of Passkeys over passwords: replay resistant, database-leak resistant and fishing proof.
- kijin 2y agoPassword managers are phishing resistant. The browser plugin will not offer to autocomplete passwords on an identical-looking punycode domain. A sufficiently long, randomly generated password is also database-leak resistant. Good luck brute-forcing a 128-bit random string, hashed with scrypt or whatever. So the only significant advantage is replay resistance. Which might or might not be a big deal, but let's not overplay the advantages.
- aaomidi 2y agoPasskeys means no secret material traverses the web. This is a huge benefit. There’s no other way to put it. From the admin side this also means significantly simpler database design
- theshrike79 2y agoAre password managers resistant to social engineering? You can copy & paste a password to a "support chat" from the manager. You can't do that with a passkey. The password is only resistant if the one storing it is following best practices, which are NOT enforced and you really can't check for from the outside.
- kijin 2y agoWell if we're talking about social engineering, I don't think it will be difficult to convince the support guy at most companies to disable passkeys on the target account altogether. :(
- theshrike79 2y agoIf you can engineer "the support guy" then you can do a lot more than disable one passkey. I'm talking about engineering on the other side, the person who has the password and uses it to log in. You can't social engineer Miriam from Accounting to give their passkey, you can do it with a password.
- varenc 2y agoBesides what others have said, I think non-tech savvy users get a huge benefit from passkeys. Imagine the people that aren’t already using password managers (probably most people). With passkeys there’s no way they can reuse or leak a password. Passkeys are quite easy to use.
- weikju 2y agoSo far, non-tech-savvyy I know in real life who have interacted with passkeys have been more confused than helped by how they were implemented. Most likely as a result of blindly clicking yes/ok/accept/etc when asked to migrate to passkeys (e.g. on Google).
- tptacek 2y agoPasskeys (and FIDO keys generally) are mutually-authenticating, which makes them phishing resistant. Phishing resistance is enormously important.
- dadrian 2y agoThey're not mutually authenticating, they're origin-bound (making them non-forwardable on the remote side) and channel-bound (meaning the authenticating action is guaranteed to be for the same device as the user action). However, there's no particular reason a FIDO key couldn't sign a login statement to a phishing site---it's just that statement wouldn't then be usable as a valid credential for the true site, regardless of if the signature from the FIDO key was valid or not.
- skybrian 2y agoPasskeys are basically a protocol upgrade for password managers. A limitation is that you have to use a password manager, but the protocol is more secure. If you have a password manager you like, maybe it’s for the best? Maybe use more than one password manager, just in case.
- al_borland 2y agoI have been using a password manager for 16 years, and as much as I always want to use autofill, there are still situations where I need to either copy/paste the password, or reveal the password and type it in. I don’t think we’re at a point where I can 100% trust that the password manager will be able to handle every situation I run into from now until forever, and that’s what passkeys are asking for. I don’t see it.
- aaomidi 2y agoPasskeys are specifically interacting with a pwd manager. Before this, the manager had to try to figure out what’s a password field.
- al_borland 2y agoAnd what happens when I need to login to a device I don’t own, or don’t have/want my personal password manager on? For example, I can’t (and won’t) load my personal password manager on my work computer, but there is 1 site I use my personal account for and had to login when I got a new work laptop a few months ago. Another example is I still bum TurboTax off my dad, since he gets the version where he can do a bunch of returns. To download my data from the bank I need to login on my dad’s computer, and I’m pretty sure even if it was mine the password manager isn’t going to work with TurboTax. Another example I had was needing to login to a site to download and print something on a computer in a business center at a hotel… not something I ever want to make a habit of, but I was in a bind. I could go on. These things come up. I think the idea that a person will only ever need to login on their own computer is unrealistic. That might be the case 99.9% of the time, but not 100%. That 0.1% does need to be accounted for.
- deleted 2y ago[deleted]
- edweis 2y agoUsing the same device,Fastmail never asks for a password except when doing sensitive actions (like adding an email account). There are a lot of words here, this is an SEO bait, rather than a product update.
- deleted 2y ago[deleted]
- cyrnel 2y agoOne of the most common platform combos on the planet (Chrome + Windows) still doesn't natively support cloud sync for passkeys apparently? https://support.google.com/chrome/answer/13168025 https://support.google.com/chrome/answer/13168025 Is that true?
- nixosbestos 2y agoThey're almost surely stored in the TPM, as they should be.
- YPPH 2y agoWhat are people’s thoughts on the UIX of a sign in page initially with only a single username input? In my view, it is a backwards step. First, I can’t do username <tab> password <enter>. Secondly, with auto fill, it requires two clicks to sign in. I can understand it for Microsoft login where push notification login is an option. Otherwise, I’m not sure it is a great design pattern. I would prefer a regular sign in page, with a button to sign in with passkey (which also does not require username input).
- Bilal_io 2y agoI hate that with passion. Though I don't know the technical reason behind this workflow.
- RexM 2y agoI think it’s so it can look at the login method for the account and act accordingly. If the user is configured to use SSO it can redirect to the identity provider. If it’s password auth it can ask for the password, etc.
- silon42 2y agoIsn't that a security leak? Revealing what auth method the user is using.
- vladvasiliu 2y agoI'm not sure always presenting the password field avoids that. If you type in bob@sso.com for your SSO account, the password field will clearly be a throwaway, and you'll be redirected to your IDP. Being presented with a "wrong password" error would mean the account is local.
- labcomputer 2y agoWeeellll… you’d hope so, but some users may try to autofill a password with the right username, which will inadvertently fill the password too. And now your vendor (Quip or whomever) can potentially see your employee’s passwords. You have to trust them to throw away any password they see for someone from your org.
- jbverschoor 2y agoBut even with passkey you have: - a password, which still can be brute forced if done authentication service doesn’t play nice - resets still need to work somehow The only good thing about it is that you will know which auth device is used for a session and that you don’t need 2fa afaict. Unfortunately most information about sessions and attempts isn’t communicated by 99% of the services
- Scottn1 2y agoHow about they fix their long-standing security issues first. Particularly their DMARC is set to "p=none" which is essentially disabled at a time large providers are mandating properly functioning DMARC. Anyone can spoof email account of other Fastmail users (1). Their #1 job is email, yet Fastmail has poor security scores still in 2024 (2). MTA-STS should be enabled for any competent email host. (1) https://news.ycombinator.com/item?id=18997054 https://news.ycombinator.com/item?id=18997054 (2) https://www.hardenize.com/report/fastmail.com/1723612173 https://www.hardenize.com/report/fastmail.com/1723612173
- jph00 2y agoYour summary of the situation is not accurate. You can quibble about their choice of DMARC setting, but IMO it's the correct choice and best for customers. Your link says "Unable to determine STARTTLS status" -- which doesn't mean anything. Fastmail has an excellent security track record. (Disclosure -- I'm the founder, but I haven't worked there or had a financial relationship with Fastmail for many years.)
- brongondwana 2y agoYou cite a 5 year old post. We have improved things since then. You can't spoof other people through Fastmail any more, we verify permission to send as any address - either through your account owning the domain or alias - or by authenticating the specific address by confirming you can receive an email there. If you have your own domain, you can set whatever DMARC policy you like on it. We'll DKIM sign your email for you if your domain is configured to use the keys we create for you, or do your own outbound email as you want. Also the whole thing about STARTTLS is bogus - that site says "Unable to determine STARTTLS status" - too right. Because we're not listening on those ports. Because that's less secure that only allowing the SSL/TLS ports. We have written about our reasoning here: https://www.fastmail.help/hc/en-us/articles/360058753834-SSL-TLS-and-STARTTLS https://www.fastmail.help/hc/en-us/articles/360058753834-SSL... The key paragraph is this: Today, many email services, including Fastmail, now disable plain text IMAP and POP logins entirely on ports 143 and 110, leaving encrypted connections on ports 993 and 995 as the only option. This makes sure all clients use encrypted SSL/TLS connections to protect sensitive data. (Disclosure: I'm the CEO at Fastmail)
- vouaobrasil 2y agoIt's good to have options but... I hate passkeys. Here is why: 1. Passkeys are device dependent. That means you need to have more devices and be tied to your existing devices. For a lot of people, that means even tighter phone dependence. 2. Even if you don't use a phone to store your passkeys, they promote vendor lock-in, because you need to rely on Apple, Google, or some other cloud-keychain system to store your passkeys. Tech companies love passkeys, not because it makes your life better, but because it entrenches people further into relying on their systems. People will love passkeys because it appears simple and makes passwords a thing of the past. But there's a tradeoff: more dependence on advanced technology are major tech corps. Let me ask you this: suppose you want to go phone-free and big-tech company free. Or you lose your phone and computer overseas. If you only use a passkey, then you'll have to grovel back to Apple or Google to log into your fastmail. Tech corps love that. This is just one step to make people tied to big tech, and so it seems harmless. But it is part of an overall procedure to integrate us so tightly (free Google docs, log in with Google/Apple/X is another of many), so that we can't function on our own any more, or choose any company we like any more.
- Untit1ed 2y agoI still haven't reckoned the security implications, but Bitwarden supports passkeys, you can mostly use them the same way as you do a username/password across devices.
- vouaobrasil 2y agoThat still means dependence on some software product to log-in to basic services. With a password, I don't need to use a software product. What if I don't want to pay for Bitwarden, or buy a smartphone, or tie my log-ins to my computer? What happens when the WebAuthn standard evolves and only the big-tech companies have solutions for storing passkeys because little software vendors or open-source vendors don't support the standard as well? What happens when password-based login is phased out because passkeys are SO much simpler...assuming the user acquiesces and signs up for a big tech company's service? Who will be able to choose then?
- thepill 2y agoI like passkeys - as a second factor
- sebazzz 2y agoYes, that is called WebAuthn.
- jesseendahl 2y agoWebAuthn is just a standard. The standard says nothing about whether it should be used as a primary factor or secondary factor.
- systemvoltage 2y agoTangential: Email spamming is out of control. My fucking hair salon wants me to add 2 factor authentication, and still sends me emails with an OTP. Login and guess what? They’ll send you moar emails to fucking confirm it’s me. Guys, we are destroying the internet in the name of safety and security. I want no GDPR bullshit, I want a simpler and risky experience. I am OK with losing my hair salon account and its history. Don’t care.
- nemoniac 2y agoCould someone point to a description of how the passkey protocol actually works? I mean for example at the level of, here's how you would implement it using a crypto library in Python or some other language.
- everfrustrated 2y agoLong time Fastmail customer. Not sure why all the hate on here. More options is never a bad thing and great to see you're still making product improvements. Seeing as Fastmail peeps are reading this, can we _please_ have a native android app. The function I really need is to be able to rely on quickly showing emailed pdf tickets knowing the app won't try and reload and stall waiting on data connection. I try and load in advance but generally switching back results in a page reload. This is my far my greatest annoyance.
- MaverickOliver 2y ago[dead]
- MELEKE 2y ago[dead]