5 ms·
The article seems to focus on YubiKeys (even despite using a mac device), but at least in the Apple ecosystem the state of the art is far ahead of plugging in a
by slimsag 2y ago
The article seems to focus on YubiKeys (even despite using a mac device), but at least in the Apple ecosystem the state of the art is far ahead of plugging in a thumb drive style device IMO.
When I navigate to various websites that support Passkeys these days - Lowes, Home Depot, and handfuls of others - on iPhone (firefox) I am prompted with 'Do you want to use Face ID to sign in?'
If I do the same on macOS (firefox or safari, I'm sure Chrome does it too.), I am similarly prompted 'Do you want to sign in using a passkey?' and it gives me steps to use my mac's fingerprint reader or delegate to the iPhone Face ID to sign in on my Mac.
Combine that with Apple offering to use a private/hidden email address for signing up to the service in the first place and forward mail to your real email, plus the auto-generated secure passwords stored in the new Apple password manager.. and it's a pretty magical and secure experience as a user.
- cyanydeez 2y agoSo, anyone who can get your face on camera can access faceId?
- maliker 2y agoIt does a 3d scan of the face, so you can't crack it with an image or video.
- beeflet 2y agoit seems kind of bogus to me. You're going from using a cryptographicially secure device to using biometric data. Biometric data can be copied and faked.
- AnotherGoodName 2y agoPhones have a TPM just like a USB security key. The face id on a phone based passkey is just the equivalent of pushing the button on the yubikeys. So they need the physical device. You cannot clone the TPM parts that are in newer phones. The faceID just unlocks that hardware on your phone in the same way pushing the button on a yubikey sends the key up.
- beeflet 2y agoThat's fair, but consider this: 1) The FaceID TPM is connected to the phone all of the time, whereas you only plug the Yubkey TPM into your computer when you need it. 2) The Biometric data that the FaceID TPM collects is available pretty much all the time when you use the phone. It's not like a fingerprint sensor where you would have to go out of your way to press your finger to it. If you can hijack the OS silently, then you can probably hijack FaceID silently. It just seems backwards to me to replace a "simple" hardware token that you have to physically plug in with a massively complex internet-connected device. If someone steals your hardware token, you know.
- AnotherGoodName 2y agoI think a lot of people in this thread are assuming passkeys are passwordless. They are just the latest way to do what we used to need an external Yubikey for. You can still set the settings on individual sites to ask for a password when using a security key (external USB or device based) if that's where your concern is. The whole 'skip password' thing was just there as a convenience for people who aren't worrying about physical and biometric access but do want the two factor auth (protection against phishing, by far the most common threat). You can also set your phones unlock how you want too if you don't want faceID.
- notatoad 2y agoyour face is the pin code, not the passkey. it unlocks the cryptographically secure device, it doesn't replace it. to access your passkey through faceid, they have to steal your phone, unlock your phone, and then spoof faceID.
- traverseda 2y agoNo, faceid unlocks a Cryptographic key stored in a TPM like device. Of someone can run arbitrary code on your iPhone, they can get it to unlock the TPM. If they can't, it would be challenging to fake FaceID right now. It uses a bunch of stuff, IR cameras, a depth camera I think, probably some kind of eularian video magnification for pulse detection. Possible to fake but expensive, probably need to hire some old-timers from industrial light and magic to do it with practical effects. Or you mean literally hold the iPhone to your face, in which case they'd also need to force you to keep your eyes open. The greatest weakness of cryptography has always been that you can beat someone with a five dollar wrench until they unlock the system.
- jmspring 2y agoLast I read, because it bit me with AWS console two factor, FF on macOS didn’t support pass keys. When did this get fixed?
- majormajor 2y agoI'm not at all sold on this experience for disaster-recovery reasons. I can put a backup Yubikey in a safe deposit box or other off-site location pretty easily and for relatively cheaply. I'm not gonna buy and put a backup laptop or iPhone in one. If I lost all my devices in a natural disaster I want way to be able to get back in to accounts. And personally I don't want that to be cloud-dependent (bit of chicken-and-egg dependency story, it seems, plus a centralized weakness). I might be misunderstanding the device-as-passkey story, but the stuff I've read about it hasn't seemed to proactively answer that question.
- skibbityboop 2y agoYeah, if your device is lost or destroyed and you rely on passkeys, you are well and truly f**ed. Your only hope is if you have recovery passwords stored in a password safe or manager. If you already have that safe or manager, than you can already very easily have 25+ character passphrases for every site you use, so what have passkeys gained you except having to be double-vigilant about having a recovery method for every login you create?
- mingus88 2y agoThat’s not true. You can use iCloud keychain and have numerous recovery options, including other passkeys. A lost device is not a critical issue at all. To your questions, the password safe can store passkeys as well. The entire point is to get to a place where we aren’t all dependent on some remote site’s security to keep our secrets safe. Why use a 25+ character password which can be compromised in a number of ways when a passkey doesn’t involve sending secrets at all?
- notatoad 2y agoa good passkey implementation allows multiple passkeys. you can have faceid on your mac, and you can also have a yubikey in a safe somewhere for disaster recovery. also, passkeys get backed up in iCloud, so losing your device isn't really an issue. the disaster scenario is more what happens if apple locks you out of iCloud.
- porphyra 2y agoI'm surprised you had a working experience with passkeys. Every time my iPhone asks me to use a Passkey I just get "something went wrong" or some obtuse error message. It has never worked a single time and I just gave up.