8 ms·
If I install all my private-passkeys onto my phone, then I have a new problem of Lost, Stolen, Broken to deal with. I’m device agnostic, I want to get to my ac
by AstroJetson 2y ago
If I install all my private-passkeys onto my phone, then I have a new problem of Lost, Stolen, Broken to deal with. I’m device agnostic, I want to get to my account from my phone, tablet, laptop, desktop, all I’m doing is spreading the exposure out by needing to install passkeys everywhere.
- jwrallie 2y agoMicrosoft will probably tell you that the Microsoft Authenticator supports syncing, so you should set it up on a backup device. This has several problems though, one of them being that they assume you have at least two mobile devices (let's say a phone and a tablet) and another that they assume the OS you run on both your devices is the same. They do not support migrating you passwords between Android and iOS for example!
- ashleyn 2y agoI do not and never will trust cloud storage of credentials.
- WorldMaker 2y agoMicrosoft's interesting approach here with Authenticator is that they don't expect you to trust one cloud with all your credentials, they are hoping that you can trust two clouds with partial information. They've (allegedly) got some variant of Shamir's Sharing where some of the data is encrypted in OneDrive and some of it is encrypted in iCloud or Google Drive depending on which phone you use. That's (supposed to be) why there is that "phone-type lock-in" on the automatic backups/transfers because the cloud with the most phone-native/device-specific encryption is phone-vendor dependent today.
- UltraSane 2y agoDo you trust VPNs? Because they are the same idea with a slight twist. VPNs encrypt data before it leaves your computer and decrypts it when it arrives at the destination. 1Password and the like encrypt data before it leaves your computer, stores it for however long you want, and then decrypts it when it the data is copied to your computer.
- recursive 2y agoVPNs use (I think) some kind of synchronous key-exchange handshake. That doesn't work with storage part in the middle.
- UltraSane 2y ago1Password's security model is pretty well thought out. The goal is to make it as impossible to decrypt the data you are storing as possible. https://support.1password.com/1password-security/ https://support.1password.com/1password-security/
- FireBeyond 2y agoI love that the "big guys" get to support syncing passkeys between devices... but others don't (wasn't it KeePas who had issues where they were threatened by being blocked from supporting that - https://github.com/keepassxreboot/keepassxc/issues/10407#issuecomment-1994299617 https://github.com/keepassxreboot/keepassxc/issues/10407#iss... )
- eikenberry 2y agoNice how he whipped out the attestation threat when contradicted. Shows their authoritarian leanings.
- arielcostas 2y agoI mean, same with passwords, right? If you enter your password on a compromised device or you forget it, you are screwed. Which is what password managers (or passkey managers, or perhaps we could use a new term like "credential managers") help you with. Syncing, preventing unauthorised access (for example requiring your biometrics, main password or similar), backing up...
- luismedel 2y agoHonest question: Can I have a paper backup of passkeys? How can I pass them to tech-illiterate relatives?
- oefrha 2y agoYou can write down your password anywhere and copy it to any other piece of paper at any time. You don’t need certain brands of paper blessed by a consortium, or have restrictions even when copying to a blessed brand of paper.
- growse 2y agoThe only reason you care about copying your password is because it's usually (always?) the only credentials you have for a service. This isn't true of webauthn/passkeys. The number of use cases where you need to "make a copy of " or "backup" your passkeys is zero. I get that some providers let you do this for some level of convenience, but you can opt out of this and just enrol multiple distinct credentials with each service.
- philjohn 2y agoAnother option is to use a password manager that supports passkeys, such as BitWarden. You can even host it locally, behind a VPN, if you don't trust the threat modelling of their hosted version. Then, it's a case of installing BitWarden on any devices you want to use to login, protected with a strong password and 2FA.
- TheSpiceIsLife 2y agoI don’t understand the benefit of using passkeys in a password manager. If the password manager is unlocked, I get logged in automatically anyways.
- ahofmann 2y ago1. Passkeys are unique, so no more password stuffing attacks. 2. Passkeys can't be to short, in contrast to passwords Passkeys essentially remove almost all risks for websites and moves them to the user (lost passkey, attacks on their password managers). It is not perfect, but it removes a lot of problems that we have right now (like more than a billion leaked passwords in the wild)
- simfree 2y agoSo it adds no value over the long, randomly generated passwords from a password manager besides making a new standard and giving Microsoft a reason to push a new dark pattern on users to force higher uptake rates of this new, bespoke standard with limited support?
- Scion9066 2y agoIt's a standard supported by multiple parties, not just Microsoft, including multiple open source password managers. And it does provide some benefits: phishing protection (no shared secret that can be intercepted or given to the wrong party) and the service does not need to store as much sensitive information (don't need password hashes that could be leaked and cracked, just a public key).
- nonrandomstring 2y ago> a new problem Yes, the problem exists in multiple "places" and all schemes are different balances. There are many different kinds of "security". Each suits different needs, or addresses different threats. Not all are based upon "identity" as a central concept. Not all are based on secrets. For those that are, changing your secret from something you know to something you own merely shifts a locus of trust and mode of use. Passkeys (and ssh keys with passphrase) are a good solution in some cases, where you use multiple end points which may be compromised. But they are no better (and less flexible) than challenge response and one time passwords and other elaborate password schemes that are a superior access control secret in other situations [0]. The problem is that most people don't understand the quite subtle interplay of factors. This is one area of cybersecurity education I'm spending more time on because regulations are going to place more emphasis on making good security choices (and not just accepting vendor defaults). Microsoft unilaterally deciding it thinks it knows what is "best " for you accords with its clumsy patrician over-reach, and cover for a pitiful security record in its products. Perhaps one of the most important meta-security factors is that you be able to select products that allow you to choose your security parameters and how they interact as your situation and access habits change. But that responsibility requires understanding. [0] https://cybershow.uk/blog/posts/secrets https://cybershow.uk/blog/posts/secrets
- vdelitz 2y agoyou can use a password manager to store your private-passkeys, so as long as you have access to it, you don't need to worry about lost devices