7 ms·
One thing passkey proponents forget is password-authenticated key exchanges (PAKEs). PAKEs use passwords, and they are unphishable. That is the direction we sh
by gavinhoward 2y ago
One thing passkey proponents forget is password-authenticated key exchanges (PAKEs).
PAKEs use passwords, and they are unphishable. That is the direction we should go to avoid vendor lock-in.
- jf 2y agoDoes PAKE protect against scenarios like "password written on sticky note", "fake login page hosted at login.nnicrosoft.com", or "scammer impersonating IT staff"?
- gavinhoward 2y agoFrom the first, no. It does handle the second and third, IIRC.
- lima 2y agoIt doesn't handle these either - what stops the user from entering their password on an attacker-controlled phishing page? Passkeys work because the user can't be tricked into entering their private key on a phishing website.
- gavinhoward 2y agoBrowsers could help with this. They just don't.
- growse 2y agoWhere's the vendor lock-in?
- gavinhoward 2y agoCloud sync.
- growse 2y agoThat's not an inherent feature of passkeys.
- gavinhoward 2y agoTrue, but you either have that or a catastrophic loss of identity if you lose it.
- growse 2y agoOnly if you tie your identity to a single cloud provider?
- gavinhoward 2y agoI mean if you don't gave cloud sync, then if you lose your phone, you have lost those passkeys.
- growse 2y agoIf I lose my only front door key, I can't get into my house. This is why I keep a spare.
- gavinhoward 2y agoYour argument is exactly why people conflate passkeys with cloud syncing and vendor lock-in.
- cesarb 2y ago> If I lose my only front door key, I can't get into my house. You can pay a locksmith to pick (and rekey) the door lock. You can even break down the door and replace it later. None of that is an option with passkeys.
- 2y ago