6 ms·
I don't understand what is meant by phishing-resistant. There always need to be systems to authorize new devices or allow users to re-prove themselves if they l
by mecsred 2y ago
I don't understand what is meant by phishing-resistant. There always need to be systems to authorize new devices or allow users to re-prove themselves if they loose the primary proof. Is the idea that scammers would have difficulty adapting phishes to access these resources? If "hello this is Jeff Bezos what is your password" works why wouldn't "hello this is Jeff Bezos please click authorise a new device so I can transfer you 1000$"
- brookst 2y agoBecause in the former case the attacker now has your password and can post it for everyone else to abuse. In the latter, which is still a problem, there is no transitivity. You're screwed with this one attack, but if you revoke their access that's it. They cannot re-use the credentials.
- mecsred 2y agoBeing able to revoke individual credentials is definitely a benefit. I'm not convinced about the transitivity, what's stopping one access from authorizing more? I suppose that would be asy to flag in an audit? Either way it's not really resisting the phishing, that's moreso resisting abuse once the credentials are gathered in any way.
- w0m 2y agoTo summarize this comment chain, the initial argument is 'passkeys are not impervious to all attacks therefore they are security theater' vs 'passkeys help significantly in the most common attacks, therefore they are worthwhile.' Statistics are hard. People have a bad habit of seeing 'not 100% fullproof' and thinking that said something is therefore worthless. Same senseless argument people made in the 80s against wearing seatbelts, and 4 years ago thinking it was a legitimate argument against wearing masks in the middle of a pandemic.
- afiori 2y agoI believe that the crux of it is that password managers with autocomplete already have about the same level of protection and are both more flexible and have less lock-in passkeys imho are being pushed because: 1) a lot of people will not use a (good) password manager 2) it allows more lock-in for the providers (ios/android/1password/etc.)
- tptacek 2y agoTo a first approximation no normal person uses a password manager (people find them extraordinarily hard to use; source: did trainings with a bunch of different cohorts), and the two solutions do not have "about the same level of protection". I watched a fintech company try to get people to stop relaying credentials through SMS with scammers, and that problem was practically insurmountable. I do not believe "autofill" is the fool-proof defense you think it is.
- vel0city 2y ago> have about the same level of protection They don't > have less lock-in I have physical security tokens from multiple vendors which support passkeys. I have Windows machines with passkeys. I have Android devices with passkeys. Tell me again how it is a vendor lock-in? I'm not seeing it.
- tptacek 2y agoGenerally people who assert that Passkeys are "lockin" also object to the notion of using a Google account as your primary online identity. Of course, you don't have to, but that's the concern: a world where they will have to. (You should use a Google account as your primary online identity, unless you have religious reasons not to. Back up your authenticators, set up back up accounts, all that stuff; Google doesn't want you locked out any more than you do, because that requires them to attempt customer service, so they have a bunch of tools here.)
- trinsic2 2y ago
- ziddoap 2y ago>I don't understand what is meant by phishing-resistant By far the most common phish is "click this link or your account will be shut down" which brings you to a fake Microsoft/Google sign-in page, where they say "please enter your credentials" (or some variant of this). This flavor of phishing is eliminated by passkeys. Phishing schemes will try to adapt, and some may still be successful. That is why it is not called "phishing-proof".
- mecsred 2y agoThat's a particular scheme that might be fooled, but what's stopping someone from making a version of the same scheme that redirects to a prompt on the real site which authorizes them as a new user? I'll admit web technologies aren't my area of expertise but I have little doubt it's possible based on my interactions so far. E.g. discord allowing me to log in to a new device by scanning a QR code with my phone and clicking OK. Ultimately the point of phishing is to attack the user instead of the technology. If the user has any control over access to their account, phishing is largely unaffected.
- deleted 2y ago[deleted]
- nailer 2y ago>what's stopping someone from making a version of the same scheme that redirects to a prompt on the real site which authorizes them as a new user I can give a better answer than the sibling: The passkey is domain bound, so the UI won't show up on the phishing site before the passthrough can even happen. Password managers are also domain-bound though.
- Terretta 2y ago> Password managers are also domain-bound though. are also --> can be Often they allow picking an entry for arbitrary domain names, made necessary by firms (such as Microsoft) randomizing their login domains to look like phishing domains.* * Not what they are doing, but to the casual user, logging into xbox.com, office.com, or even microsoft.com through something like microsoftonline.com may as well be phishing.
- tptacek 2y agoSee the comment from 'nailed downthread. I think some people on this thread are trying to axiomatically re-derive what Passkeys and FIDO2 are. Phishing resistance is literally the point of FIDO2.
- lxgr 2y agoThere is no "authorize a new device" for passkeys. You'd need to actually run the "register new passkey" or "authenticate using passkey" flows on the attacker's device. That's why they are so much more secure than passwords and even TOTP or "click approve to authenticate" flows!
- Wowfunhappy 2y ago...this is also the problem with passkeys. It makes it so much harder to move to a new device, and easier to get locked out.
- lxgr 2y agoThere are now synchronizing authenticators that solve this problem pretty well (including open source and platform agnostic ones!), but as a result obviously also exist on a different point on the security-availability/convenience line.
- wkat4242 2y agoPhishing is resisted because the URL of the site is used in the key generation algorithm. So a site with a similar looking but different URL won't yield a workable token, even if the user is tricked into authenticating to the fake site. You'd really have to be a state actor to be able to generate a phishing site on the original url with a valid certificate as well.