20 ms·
Passkeys are a terrible idea. They are security theater and a disaster for users waiting to happen. Imagine you're on vacation and have lost your phone. You wa
by iandanforth 2y ago
Passkeys are a terrible idea. They are security theater and a disaster for users waiting to happen.
Imagine you're on vacation and have lost your phone. You want to go to a cafe and log into a chat app, an email service, whatever to contact your family. In the world that passkey advocates want this is impossible via the passkey flow. If you can't authenticate via a primary device that contains your private key, you're f-ed. Service providers know this so of course they will provide recovery mechanisms. (Not consistent recovery mechanisms of course, each will have their own convoluted and likely to be broken ones). If the recovery mechanism allows for knowledge based recovery (challenge questions) then you're basically telling people that they need N passwords rather than one password. Maybe that challenge question is just a long password (recovery key). Maybe it requires access to another system, which you likely don't have in this circumstance. So you're either back to having passwords, or you're f-ed. Security theater or a disaster.
A service only has value if I can access it. I should be able to sit down at any computer in the world with the knowledge in my head and get access to any online service to which I subscribe.
- deleted 2y ago[deleted]
- d4mi3n 2y agoYou’re not wrong, but I think you’re presenting this as a dichotomy when there’s a lot of value to be had between the two extremes (passkeys all the way or passwords all the way). The big benefit to a passkey for a service provider is that when you see a user using one, you can assert things about that session—that this is the users device, that the session isn’t likely to be spoofed, etc. These are useful things to know if you want to implement any kind of context-aware access! Passkeys certainly aren’t a silver bullet, and I don’t think they’re really marketed or implemented well a lot of the time, but I’d caution against writing off the tech as a whole .
- GoblinSlayer 2y agoHow do you log in anywhere without a computer? You have a wifi receiver implanted in your head?
- culopatin 2y agoWho said they would be on the moon? We’re surrounded by computers we can borrow all the time.
- sleepybrett 2y agoWithout a 'personal computer' that contains your passkeys. Next up, cloud based passkey proxy services. Store your passkeys there they auth for you after you give them some other damn auth method.
- TimC123456 2y agoYes, this is how we already use a password manager like iCloud Keychain or 1Password.
- Spivak 2y agoYou can't actually log in with passkeys using iCloud Keychain or 1Password when borrowing a friend's phone. Bitwarden has the same flaw, you need the software to help you do the negotiation in a way that can't be copy-pasted. Garbage standard, terrible implementations everywhere, my favorite is when logging in with a passkey they still demand SMS 2FA.
- echelon 2y ago> security theater Laypersons probably don't see ATOs at scale. I worked at a fintech and it was a relentless uphill battle to protect our users. We saw massive distributed login attempts daily and constantly bought compromised passwords on the gray market to run against our users' accounts. We tried to encourage better password hygiene, 2FA, Fido, etc. You have to protect users from their own misunderstanding. When it comes to their bank accounts, improper security can be life-changing. The term "security theater" itself is often thrown around to criticize when it's completely undeserved. Lots of people use it to poke fun at the TSA, but the term totally dismisses the fact that hijackings have plummeted [1,2]. The TSA does its job. [1] https://www.statista.com/statistics/1240246/aircraft-hijackings-worldwide/ https://www.statista.com/statistics/1240246/aircraft-hijacki... [2] https://imgur.com/a/xV9ebD9 https://imgur.com/a/xV9ebD9
- vb6sp6 2y agoTSA misses 95% of fake bombs/weapons https://www.nbcnews.com/news/us-news/investigation-breaches-us-airports-allowed-weapons-through-n367851 https://www.nbcnews.com/news/us-news/investigation-breaches-... Hijackings are down because pilots lock the door to the cockpit now
- Longlius 2y ago>The term "security theater" itself is often thrown around to criticize when it's completely undeserved. Lots of people use it to poke fun at the TSA, but the term totally dismisses the fact that hijackings have plummeted [1,2]. The TSA does its job. Your graphic shows 'worldwide' data rather than US data. How would the TSA be involved in reducing hijackings on flights outside of the US? The connection seems spurious at best. We could just as easily argue that hijackings correlate with other violent crime and the reduction in violent crime worldwide has led to their decline. Or that increased prosperity worldwide mitigates hijackings. There's very little basis to believe that TSA has anything to do with it.
- kaibee 2y ago> The term "security theater" itself is often thrown around to criticize when it's completely undeserved. Lots of people use it to poke fun at the TSA, but the term totally dismisses the fact that hijackings have plummeted [1,2]. The TSA does its job. Would you be interested in buying my rock that wards off tigers? Ever since the great Tiger apocalypse where the premier military power in the world went on decades long quest to kill all of the tigers and everyone learned of the dangers of tigers, my rock has been extremely effective at warding off tiger attacks. For just 12 billion dollars a year (adj for inflation annually) (https://www.tsa.gov/news/press/testimony/2024/04/16/fiscal-year-2025-presidents-budget-request-transportation-security https://www.tsa.gov/news/press/testimony/2024/04/16/fiscal-y...), you could have this extremely effective rock. edit: I'm pretty sure I clicked reply on GP's comment. Weird.
- thought_alarm 2y agoIt sounds like you're arguing against passkeys, two-factor authentication, and password managers. Do you use single, easy-to-remember plain-text passwords for all of your accounts and services? If not, you need to understand what the recovery process is when your passkey/2FA/pw-manager is unavailable or lost.
- BadHumans 2y agoI use easy to remember plain text passwords for services that are low risk. It's a spectrum. I'm not concerned about someone hacking into my Hacker News account for example but I am very concerned about someone breaching my bank.
- zamadatix 2y agoGP doesn't seem to mention password managers. The nice thing about password managers vs passkeys is they need not be locked to a particular device or platform. I can sync the same database of credentials between my phone, pc, and laptop without worrying if they are from the same vendor. I can export backups. I can access it through my personal website on any device (assuming I also remember my personal website login too) if desperate. The problem with passkeys isn't the concept, it's the lack of flexibility in implementation.
- jazzyjackson 2y agoSeems to be a common misconception, passkeys need not be tied to a device, they can be saved to a password manager and synchronized.
- josteink 2y agoI in fact do this with Bitwarden on a daily basis. It works ok!
- zamadatix 2y agoThis prompted me to read more about it as I was quite certain this was the reason I had stopped using them. It seems the initial wave of complaints fed into some change about a year after the initial launch. Android 14 (Oct 2023) via the new Credential Manager API and iOS 17 (September 2023) when 3rd parties could actually be a registered passkey provider. https://developer.android.com/about/versions/14/features#credential-manager https://developer.android.com/about/versions/14/features#cre... https://www.dashlane.com/blog/dashlane-passkey-support-ios#:~:text=introduced%20third%2Dparty%20passkey%20support https://www.dashlane.com/blog/dashlane-passkey-support-ios#:... Perhaps passkeys are more viable now with these changes? I'll need to give it another go and see. Thanks for the tip!
- acdha 2y agoI think you’re letting your emotions distract from the larger picture where millions of people are compromised on a regular basis because they use systems designed the way you want. Knowledge-based access is inherently problematic: if you don’t police passwords, most people will be compromised because they use weak and/or shared passwords. If you use strong passwords, you’re also screwed if you lose your phone so you’re in the same reset game with trivia questions which are increasingly weak because they can be answered from information on Facebook/LinkedIn or from breaches from other companies which used the same question. New logins from previously unused devices in a new part of the world shouldn’t work anyway because that’s indistinguishable from a successful attack. Passkeys avoid all of that, but you need backups either in the form of a Yubikey or a recovery code in your wallet. Yes, that’s annoying but there is no world where nobody is annoyed, so it should be a question of whether more people are inconvenienced by their accounts being breached versus traveling and losing all of their devices but still being able to remember their strong passwords.
- dboreham 2y agoOf you have a Yubikey why do you need to use passkeys (which are essentially software emulation of a Yubikey).
- superfrank 2y agoBecause the vast majority of users don't want to bring a yubikey with them everywhere they go.
- nijave 2y agoI'm curious if that's really true. I've had a Yubikey in my keyring for years and it's pretty convenient. It's smaller than my car key and isn't very noticeable. I have the NFC enabled variant so it can be used with a mobile phone
- mebizzle 2y agoI don't have a keyring or a car key anymore so any additional physical object to carry is less convenient.
- figers 2y agoPasskeys are in 1Password. I'm authenticated into 1Password on my phone, ipad, browser extension on multiple computers. As long as I don't lose access to all devices at the same time I'm fine...
- mort96 2y agoPasskeys are arguably slightly more convenient and not risky for those of us who are technically aware enough to use password managers, sure. But that's not what most people will do. Most people will see their phone ask them to add fingerprint/face unlock, so they do that, and now their passkey is stored only on their phone (or in iCloud if they're lucky).
- ncpa-cpl 2y ago> Imagine you're on vacation and have lost your phone. A few years ago when SMS tokens and Authenticator apps where less common, I was able to do work without having my phone on the same room as my computer. Now I need to have it on my desk most of the time for logging in.
- graemep 2y agoThere are authenticator apps that will run on your computer, and apps that will let you read SMSs on your phone from you computer. You phone might need to be on for the latter, and maybe even connected to the same local network, but it does not have to be literally on your desk.
- CharlesW 2y ago> In the world that passkey advocates want this is impossible via the passkey flow. That's incorrect. I use passkeys to login automagically with many services, but nothing precludes me from logging in with my (20 character) passwords. > If you can't authenticate via a primary device that contains your private key, you're f-ed. That's also incorrect, for multiple reasons — accounts support multiple passkeys, those passkeys are securely sync'd across multiple devices, recovery and backup mechanisms exist, etc.
- mort96 2y ago> That's incorrect. I use passkeys to login automagically with many services, but nothing precludes me from logging in with my (20 character) passwords. That is not the world which passkey advocates envision. In the case of those services you mention, passkeys are nothing but convenience; they provide no extra security. In the world passkey advocates envision, passkeys improve security, meaning the removal of password authentication options. I've already been temporarily locked out by one such service, because a Firefox update made the passkeys I store in Bitwarden inaccessible (Firefox would pop up a macOS Touch ID modal rather than the Bitwarden passkey). That is the world which passkey advocates want, because it "improves security".
- Dylan16807 2y ago> That is the world which passkey advocates want Okay, you don't have to take the hyperbole so far it's obviously wrong. They don't want your login to break, and a password vault could also break if you only had a password.
- deleted 2y ago[deleted]
- mort96 2y agoI'm saying that the world which passkey advocates want is a world where if, for any reason, you can't log in with your passkey (due to a lost/broken device, a software bug, whatever), you'll be locked out of your account. I'm saying that to contrast with my parent comment, which claims that the world passkey advocates want is one in which passkeys offer some slight convenience advantages but no security advantages because they'll be an alternative to passwords. Obviously they don't want the software bugs, but we know bugs happen.
- doktorhladnjak 2y agoNobody is checking their email on vacation in an internet cafe in 2024. Losing your phone is a real pain these days.
- Kwpolska 2y agoAn internet café is probably a bad choice, but I can't access a passkey-protected service from a friend's phone either.
- vel0city 2y ago> but I can't access a passkey-protected service from a friend's phone either. You can use passkeys across devices. I've logged into sites for people using passkeys on other devices several times. I just tap or plug in my device to theirs when it asks for the passkey and it logs in.
- acdha 2y agoNor can you access a modern site from their phone unless you have a Yubikey, access to SMS, or a recovery code. If you need to do this, it works the same for a passkey: if it’s a very close friend, you can share the passkey with them. If not, you can use the same login you’re now with the same MFA. Passkeys don’t need 100% adoption to be effective: the big win is blocking phishing attacks and that works as long as you’re not using passwords by default.
- nijave 2y agoI assume any device in an Internet cafe is riddled with keyloggers so now you've lost your phone /and/ email account
- lisper 2y ago> I should be able to sit down at any computer in the world with the knowledge in my head and get access to any online service to which I subscribe. The problem with that is you have no way to be sure that the knowledge in your head won't somehow make its way into someone else's head. There's a reason that phishing is a thing.
- mort96 2y agoIt should be a non-goal to prevent users from making mistakes in ways which harms everyone.
- nijave 2y ago>Imagine you're on vacation and have lost your phone This is a solved problem. a) you can make a phone call b) you can print important travel documents ahead of time c) you can bring a backup device on your travels. I leave a Yubikey with my house keys in the hotel or sleeping accommodations and carry my phone
- jimbob45 2y agoYubico's explanation of the name "YubiKey" is that it derives from the phrase "your ubiquitous key", and that "yubi" is the Japanese word for finger. The Yubikey is greatly held back from wider adoption because of its stupid name.
- beart 2y agoHere are some successful companies with odd-sounding names: Google, GoDaddy, Survey Monkey, Nvidia, Caterpillar, Coca-Cola
- notatallshaw 2y ago> b) you can print important travel documents ahead of time c) you can bring a backup device on your travels. While I remain on the fence about passkeys, I often see this argument from advocates when things go wrong along the lines of: "why didn't you securely store your backups and keep them with you at all times" Firstly, it's annoying when a user is already in that situation, it does not help them solve the problem right now. Secondly, it clearly faces a scalability issue, a significant proportion of passkey users right now tend to be well informed on the authentication model and threats, but when it scales to billions of users many of them will not be well informed and will not think about how to be prepared for when things go wrong, potentially locking them out of everything they would need to fix the situation. While I appreciate the advantage this model gives, I struggle to imagine it will work well on the unsuspecting public.
- rurp 2y ago> I struggle to imagine it will work well on the unsuspecting public. Right, that's because there's a 0% chance we end up in a world where everyone who uses the internet reliably carries a Yubikey or similar backup on their person. It's wild to me how many people here are seriously proposing this as a solution. That might work fine for a typical HN poster, but expecting it to scale to the general public is some insane tech bubble myopia. In reality companies will either provide enough workarounds to negate any security benefits or a whole bunch of people are going to lose access to accounts they own. If passkeys ever get widespread I'm guessing we'll see more of the former option, leading to a lot of unnecessary confusion and very little practical benefit.
- Tomte 2y ago> They are security theater You claimed that but didn‘t support it. They may be a bad idea (and I disgree), but how are they „security theater“, which means they are insecure?
- tptacek 2y agoYou made a case for Passkeys having a flawed UX, but not one for them being security theater. Words mean things; "security theater" is a term of art for things people do for enhanced security that add no security, and Passkeys are not that. Downthread, you claim that Passkeys (if stored in a password manager) are no more secure than a random password stored in that password manager. That seems obviously to be false; Passkeys are phishing-resistant, and stored passwords are not. So that might be where your misconception comes from.
- mecsred 2y agoI don't understand what is meant by phishing-resistant. There always need to be systems to authorize new devices or allow users to re-prove themselves if they loose the primary proof. Is the idea that scammers would have difficulty adapting phishes to access these resources? If "hello this is Jeff Bezos what is your password" works why wouldn't "hello this is Jeff Bezos please click authorise a new device so I can transfer you 1000$"
- brookst 2y agoBecause in the former case the attacker now has your password and can post it for everyone else to abuse. In the latter, which is still a problem, there is no transitivity. You're screwed with this one attack, but if you revoke their access that's it. They cannot re-use the credentials.
- mecsred 2y agoBeing able to revoke individual credentials is definitely a benefit. I'm not convinced about the transitivity, what's stopping one access from authorizing more? I suppose that would be asy to flag in an audit? Either way it's not really resisting the phishing, that's moreso resisting abuse once the credentials are gathered in any way.
- w0m 2y agoTo summarize this comment chain, the initial argument is 'passkeys are not impervious to all attacks therefore they are security theater' vs 'passkeys help significantly in the most common attacks, therefore they are worthwhile.' Statistics are hard. People have a bad habit of seeing 'not 100% fullproof' and thinking that said something is therefore worthless. Same senseless argument people made in the 80s against wearing seatbelts, and 4 years ago thinking it was a legitimate argument against wearing masks in the middle of a pandemic.
- adrr 2y agoAnd if you have 2FA setup and no devices. You're also screwed. Its the exact same scenario.
- mort96 2y agoYeah, TOTP is also a huge problem.
- donmcronald 2y agoMicrosoft Authenticator push notifications are even worse. It's super easy to lose accounts if you lose your device because they are not included in backups and there's no warning that you should have two devices registered when setting it up. Normal users aren't going to keep a backup device, let alone keep track of which accounts are associated with which devices they own. Normal users need something in a portable format that can be backed up. Anything that can be backed up can be stolen and anything that can be stolen shouldn't be used for single factor auth like Passkeys are promising.
- vel0city 2y agoI don't think you can set your Microsoft account to only have push notifications as a second factor without other recovery options?
- donmcronald 2y agoI forgot to enroll a new phone before wiping my old one this year and was looking at a 30 day wait to update my login info. That’s not technically losing the account, but it’s pretty rough. Thankfully I was logged in on a PC and was able to get past it.
- macrolime 2y agoOr if all your passwords are in a password manager on your phone
- eikenberry 2y agoIsn't the difference that with passkeys you'd have 1 password for all passkeys where when using passwords directly you'd have a different one for each site. The benefit of passkeys here being that you shouldn't need that password most of the time so you don't expose it. You get the benefits of unique passwords per-site with only 1 actual password. The same benefits of a password manager but with better unique passwords. The main downside to passkeys currently is that I cannot be my own service provider. Having that I don't see a big downside.
- reaperducer 2y agoof course they will provide recovery mechanisms Or, maybe they won't. Are Google and other free-as-in-facebook services going to suddenly open customer service departments? I got permanently locked out of Facebook because during a phone OS update, the 2FA app somehow lost my Facebook information. I can't log in to Facebook because the 2FA app can't authorize it. I can't add my Facebook account to the 2FA app without first logging in to Facebook. I've sent my photo ID to Facebook a number of times, but it just goes into a black hole and I never get a response. On the plus side, I have a lot more time to do meaningful things, and not scrolling my life away like a drug addict.
- derefr 2y ago> Maybe that challenge question is just a long password (recovery key). Specifically, recovery keys are designed to be so long and complex that no human could possibly memorize them, ensuring that they’re written down / printed instead of memorized — thus making them a “something you have” credential rather than a “something you know” credential.
- lxgr 2y ago> They are security theater Passkeys are highly secure compared to passwords. All problems I know of (and there are quite a few!) revolve around availability, not security. All problems you do write about after this are indeed related to availability, but then you shouldn't call them "security theater".
- christina97 2y agoThe argument is that service providers will not accept the reduced availability and so will deviate from the pure passkey way into some patchwork of security theater.
- kjs3 2y agoMicrosoft has made it very, very clear that they are building toward a future with the expectation that you are always on-line, and if you aren't, they are going to make life painful in large and small ways.
- presentation 2y agoCrazy idea, but maybe passkeys can allow users to log in more easily and with greater security 90% of the time while not significantly worsening the attack surface. It’s almost as if, security against a determined actor isn’t the sole way in which decisions around authentication are made!
- prmoustache 2y ago> If the recovery mechanism allows for knowledge based recovery Basically almost every single auth method is flawed by that because it gives way to social engineering attacks. Also once your email is taken over everything else is.