3 ms·
So passwords are bad because users can't be trusted to chose strong passwords but for passkeys they suddenly are trusted to keep secure, comprehensive, backups?
by OptionX 2y ago
So passwords are bad because users can't be trusted to chose strong passwords but for passkeys they suddenly are trusted to keep secure, comprehensive, backups?
- dsego 2y agoPasswords can be phished, all you need is a convincing fake login form.
- acdha 2y agoPasswords are bad because normal people can’t remember strong passwords AND because they can be phished or leaked. Phishing is the most commonly-mentioned benefit for passkeys because it’s widespread and cannot be eliminated from a password-based system. “Secure, comprehensive backups” sounds scary until you remember that it’s only ever meant not disabling a checkbox for iCloud, Google, or Microsoft users.
- 0cf8612b2e1e 2y agoWhat if my house burns down? How do I convince Google it’s me, please give me my passkeys back? Call customer support? Any solution which does not allow me full autonomy to maintain a backup is not acceptable.
- kbelder 2y agoThis is it. Any security solution has to be under control of the individual. Otherwise it's just another insecurity. Not from the company's perspective, from the individual's.
- XorNot 2y agoThe glee with which people say "and it's on your phone!" is what gets me. Right: it's on the small device I take everywhere and use for everything. The one most likely to get lost, stolen or completely destroyed, and absolutely has to be replaced in about 5 years. That device. You want to permanently lock data to that thing? (My phone is basically disposable in terms of my expectations for it's future survival, and man do I not like the Android recovery options still)
- acdha 2y ago> That device. You want to permanently lock data to that thing? This is why no passkey implementations do this: the mainstream implementations all require synchronization and if you read e.g. Apple’s iCloud documentation note that the offline recovery mode is designed for the case where all of your devices are lost: https://support.apple.com/en-us/102195 https://support.apple.com/en-us/102195
- prmoustache 2y ago"Recovery security Passkey synchronization provides convenience and redundancy in case of loss of a single device. However, it's also important that passkeys be recoverable even in the event that all associated devices are lost. [...] To recover a keychain, a user must authenticate with their iCloud account and password and respond to an SMS sent to their registered phone number. After they authenticate and respond, the user must enter their device passcode.[...]" And we get back to knowledge based auth in the end.
- acdha 2y agoYes, but that’s like saying there’s no difference between a bicycle and a dump truck because they both have wheels and can go off road. Passkeys make an immediate, significant improvement for security and ease of use, and the disaster scenario is no worse, often better.
- jesseendahl 2y agoRecovery flows being based on knowledge based auth that requires multiple pieces of knowledge does not in any way reduce the extremely meaningful security improvements that passkeys bring for both users and Relying Parties on a daily basis.
- vel0city 2y ago> Right: it's on the small device I take everywhere and use for everything. So don't put it on only your phone, put it on your phone, your laptop, your desktop, and maybe a physical hardware token. Lose all but one and you're still fine. I lost my phone. I don't bother with the cloud sync'd passkeys. I didn't lose any of my identities, because I had access through other devices.