13 ms·
I love passkeys. I love them being on my phone, requiring biometric authentication before unlocking. I just hate the vendor lock in that comes with it. Does an
by labadal 1y ago
I love passkeys. I love them being on my phone, requiring biometric authentication before unlocking. I just hate the vendor lock in that comes with it.
Does anyone know the state of the standard wrt this? I know that they planned on doing something about it, just haven't kept up.
- hiatus 1y agoCan you expand on the vendor lock aspect? I have stored passkeys in my password manager, so they feel pretty portable to me. Is it that each service requires a unique passkey? That seems comparable to how each service would require its own TOTP seed.
- supportengineer 1y agoYour password manager came from a vendor. As a thought exercise, switch vendors.
- EnPissant 1y agoBitwarden exports include passkeys.
- dboreham 1y agoHave you actually tried exporting a passkey and importing it into another manager, then successfully authenticate with it?
- coldpie 1y agoKeepassXC lets you export the private key, which you can then back up or import into another KeepassXC instance. I have tested this, it works. I even shipped my exported private key off to a friend in another state and he was able to import it into a KeepassXC instance and log in to my account. Presumably another password manager could support importing the data, as it's just plaintext, though I don't know if any do. Unfortunately the spec authors think this export feature violates the spec and have threatened KeepassXC with being banned by authenticating websites[1]. This explicit support from the spec authors for client banning makes passkeys non-viable to me. The websites I log in to should not be able to restrict what clients I choose to use to manage my own data. [1] Spec author writes, "To be very honest here, you risk having KeePassXC blocked by relying parties. ... (RPs [may] block you, something that I have previously rallied against but rethinking as of late because of these situations)." https://github.com/keepassxreboot/keepassxc/issues/10407 https://github.com/keepassxreboot/keepassxc/issues/10407
- timeflex 1y agoFurthermore, they "heard rumblings that KeepassXC is likely to be featured in a few industry presentations that highlight security challenges with passkey providers." Basically, do what we say or expect us to have our corporate sponsors write bad press about your security.
- EnPissant 1y agoJust having the data exported is peace of mind for me. It's trivial to import or convert to another format (even if not implemented now), so the worst-case scenario is acceptable, especially considering how much better Bitwarden + Passkeys are to every other form of authentication.
- cyberax 1y agoBitWarden is OpenSource. I did try importing the export using my own hosted BitWarden server, it worked.
- koakuma-chan 1y agohttps://blog.1password.com/fido-alliance-import-export-passkeys-draft-specs/ https://blog.1password.com/fido-alliance-import-export-passk...
- recursive 1y ago> we have no interest in creating a walled garden or locking you into 1Password. They have no interest... in collecting subscription fees? I'm a satisfied 1Password customer, but it's hard to take this claim seriously. What does it mean? They literally get paid. Isn't that the definition of an interest?
- koakuma-chan 1y agoMaybe they can get more customers by being based.
- dataflow 1y agoI think you're thinking of incentive not interest. Like how you can have incentives to steal from the supermarket, but still have no interest.
- recursive 1y agoI'm thinking of another definition of "interest". e.g. "have an interest in"
- Steltek 1y agoFrom the article: > But how can websites know whether its users are using secure authenticators? Authenticators can cryptographically prove certain facts about their origins, like who manufactured it, by generating an attestation statement when the user creates a passkey; this statement is backed by a certificate chain signed by the manufacturer. How many scummy companies trot out "Let me protect you from yourself" to justify taking away their users' freedoms?
- yladiz 1y agoUnfortunately I don’t think there’s much to help with vendor lock in directly (like, you may or may not be able to export the private key(s) depending on the tool, and in some cases it’s definitely not possible like with a hardware key), but any website that supports passkeys supports WebAuthn in general so you shouldn’t have difficulty migrating to another tool if desired, although you would need to register again.
- reginald78 1y agoPasskeys support an attestation anti-feature, enshrined in the spec. This feature can be abused (and will be IMO, why put it in the spec otherwise?) to limit which providers can access a service. Lock-in is built into the design. One of the developers already threatened to use it against keepass when they built an export feature he didn't agree with.
- parliament32 1y agoAttestation is probably the best feature of passkeys. From a corporate compliance perspective, I need to ensure that employee keys are stored in a FIPS-compliant TPM and unexportable. Key loss is not an issue because we have, ya know, an IT department. The only way I can ensure this happens is by whitelisting AAGUIDs and enforcing attestation. With these factors I can also get out of the MFA hellhole (because I can prove that whitelisted vendor X already performs MFA on-device without me having to manage it: for example, WHFB requires something you have (keys in your TPM) and either something you are (face scan / fingerprint) or something you know (PIN), without me having to store/verify any of those factors or otherwise manage them). Same goes for passkeys stored in MS Authenticator on iOS/Android.
- yladiz 1y agoBut most passkey providers don’t return attestation data. How do you get the data?
- parliament32 1y ago
- supportengineer 1y agoFor me, the only thing that makes passkeys viable is backing them up in the cloud and automatically syncing them across devices. Otherwise, I do not trust them.
- TechDebtDevin 1y agoWhat do you use?
- dboreham 1y agoNot the parent, but the obvious answer is: a hard token (e.g. Yubikey). After all passkeys are just a software emulation of the smart card / FIDO2 mechanism that's been around for many years.
- crote 1y agoThis doesn't solve the problem, unfortunately. The issue with hard tokens is that there is only one of them. By design, you can't back up a Yubikey's content to a second token. This means that any time you add 2FA to a new account, you must have all of your hard tokens in your possession to enroll them. This means a "one token on your keyring for daily use, one token in a safety deposit box as backup" approach isn't possible. Yubico did propose a potential solution five years ago[0], but that proposal seems to have gone nowhere. Until something like that gets implemented, FIDO2 (and by extension Passkeys) requires some form software implementation backed by cloud synchronization to actually be usable for the average person. [0]: https://www.yubico.com/blog/yubico-proposes-webauthn-protocol-extension-to-simplify-backup-security-keys/ https://www.yubico.com/blog/yubico-proposes-webauthn-protoco...
- hanikesn 1y agoIt works well enough. When you need to signup for a new service on the go, you can add your backup key when you get to it. Having the backup key in a safety deposit box hardly accessible seems like a non-goal given you protect it with a pin with a very limited number of retries.
- taeric 1y agoI always ask how you expect to defeat the vendor lock in? Effectively you have a secret that you are using to authenticate yourself. With pass keys managed by a vendor, you are trusting that vendor to manage your secret. If they are able to give your secret to someone else, then they can no longer confirm who all knows your secret. I'm sure you can come up with a protocol where you can fan out access to the secret in a way that requires fanning back messages to you. But I don't see any clear way to do so that doesn't increase the communication burden on everyone. I'm also sure smarter people than me can surprise me with something, here. But secrets that can be shared historically tend to not be secrets for long.
- blibble 1y ago> I'm sure you can come up with a protocol where you can fan out access to the secret in a way that requires fanning back messages to you. But I don't see any clear way to do so that doesn't increase the communication burden on everyone. the spec actually supports this, it's called caBLE
- taeric 1y agoRight, that flow seems somewhat straight forward and is roughly what I had in mind with my sentence. It doesn't really break you out of vendor involvement, though? You both still have to be fully in on the whole flow. Right? Asked differently, how does this get a vendor out of the picture?
- lxgr 1y agocaBLE is not a specification for transferring secrets, but for mediating (temporary) access to them. But the FIDO alliance is apparently working on that: https://fidoalliance.org/fido-alliance-publishes-new-specifications-to-promote-user-choice-and-enhanced-ux-for-passkeys/ https://fidoalliance.org/fido-alliance-publishes-new-specifi...
- taeric 1y agoI actually thought it was more for mediating confirmation of access to them. You don't share the secret with the new party, but you and the vendor both do a flow with them to confirm that someone claiming to be an identity can support that claim.
- jp191919 1y agoI use KeepassXC on my PC. Not sure of an app for mobile though.
- vngzs 1y agoI can register my Yubikeys on account.google.com (and around the web, e.g., fastmail.com) as passkeys. If you visit the account security page[0] and enable "skip password when possible", then you can log in to Google with only a Yubikey-backed passkey. If you have old Google creds on your Yubikey, you may have to first remove those creds from your account (because there are older and newer protocol choices, and with the old protocols enabled Google will not support passwordless login). Multiple yubikeys are required if you would like to have backups; there is no syncing between keys. For support matrices, see [1]. [0]: https://myaccount.google.com/security https://myaccount.google.com/security [1]: https://passkeys.dev/device-support/ https://passkeys.dev/device-support/
- zikduruqe 1y agoI just use a Trezor One (yes, a bitcoin hardware wallet). I back up my 12 word seed phrase, and then I can restore any and all my TOTP/FIDO/passkeys with another one if needed.
- kccqzy 1y agoI tried setting this up for a non-technical friend who was gifted multiple brand new Yubikeys. The goal is to log in to Google using any one of the Yubikeys with no password. Unfortunately doing so causes Chrome to pop up a dialog requesting a PIN for the Yubikey. How did you solve that problem? Searching online I found an answer on Stack Overflow stating that a PIN is required in this case: https://stackoverflow.com/a/79471904 https://stackoverflow.com/a/79471904 How did you bypass it? I also find it idiotic that it is required. A PIN is just a password in another name, so we are back to using Yubikeys as the second factor in 2FA rather than a password replacement.
- AnotherGoodName 1y agoPasskeys need to have two factor to count as a passkey per the standard. Otherwise in theory someone could steal your key alone and get in (a big risk). You need to buy a newer Yubikey with biometrics to make this work. I assume you have an older Yubikey and Google is getting to the standard by asking for a PIN. I have a https://www.yubico.com/products/yubikey-bio-series/ https://www.yubico.com/products/yubikey-bio-series/ and it works with Google exactly like you want it to, no PIN required. It's completely understandable to require a PIN if you don't have one of these though.
- namro 1y agoOn Android, Keepass2Android developer is working on supporting passkeys in the near future (https://github.com/PhilippC/keepass2android/issues/2099 https://github.com/PhilippC/keepass2android/issues/2099) but I'll be honest, I haven't dedicated enough time learning about passkeys to be sure the app will be able to support all implementations of passkeys and avoid vendor locking completely.
- iknowstuff 1y agohttps://strongboxsafe.com/ https://strongboxsafe.com/
- shellcromancer 1y agoThe FIDO Alliance (who wrote the WebAuthn spec with the W3C) has a draft specification for a format (Credential Exchange Format) and protocol (Credential Exchange Protocol) for migrating passkeys and other credentials [1]. I don't think this is implemented by any providers yet, but it's being worked on. [1] https://fidoalliance.org/specifications-credential-exchange-specifications/ https://fidoalliance.org/specifications-credential-exchange-...
- conradev 1y agoThe big remaining issue in my mind is this one: https://github.com/fido-alliance/credential-exchange-feedback/issues/24 https://github.com/fido-alliance/credential-exchange-feedbac... I am worried about providers blocking exports “because security”. That’s Apple’s favorite argument
- an_d_rew 1y ago1Password integrates with all pass keys on my iPhone, my Mac, and my Linux box. By a far and away WORTH the subscription, for me!
- drdrey 1y agodoesn't that mean your passkeys are now about as secure as a regular password?
- kbolino 1y agoA passkey is a public-private keypair strongly tied to a specific site. Sites never have access to the private key, and the key will never be presented for use on the wrong site. Those two advantages remain even if the passkey is stored in software or synced over the cloud.
- radlad 1y agoPasskeys are highly phishing resistant in a way that passwords are not and are not subject to credential reuse (though password managers somewhat solve the first problem and almost entirely solve the latter problem.) In effect, though, 1Password is both something you have (the device with 1P logged in, login requires a Security Key that you don't memorize) and something you know (the master password) or are (typically biometrics can be used to unlock for a period after entering the master password.)
- jcattle 1y agoHow do Password managers solve phishing issues? Even just somewhat?
- josephcsible 1y agoYour password manager will autofill your credentials on the real site but not on a phishing site.
- 1y ago
- idle_zealot 1y ago> Does anyone know the state of the standard wrt this? Exporting/transporting keys seems to be optional on the part of implementors, but my solution has been to use Bitwarden, so I at least get cross platform keys.
- normalaccess 1y agoI use Bitwarden to store my passkeys. Syncs to all my devices and just works. I have very few issues with it. Also for the truly paranoid, you can run the open-source back end on your own server if you want. https://bitwarden.com/passwordless-passkeys/ https://bitwarden.com/passwordless-passkeys/
- secabeen 1y agoCan you export the passkeys to an importable form that your heirs can use to get into your accounts if you have passed away? Something that's sealed in an envelope inside a fire safe, for example? Every vendor I see offering a solution has no documented export option at all. Yes, you can use the legacy method to login, but an authentication stream that is not used regularly is one that will break, or will ask for a factor that I no longer have access to (I wouldn't know this because I only use passkeys.) I also expect that there will be sites that only accept passkeys eventually, even if the spec says you shoudln't.
- SchemaLoad 1y agoYes. If you use a password manager like 1password you can print out the recovery slip and write your password on it. Then all of your passkeys will be accessible.
- internetter 1y agoI think you missed the point. If I have a passkey in 1password how does it become my passkey? As in, a passkey I can freely read, redistribute, and store in platforms that are not 1password. This is a property of passwords but not of passkeys.
- SchemaLoad 1y agoToday you can do that with open source password managers, and in the future there is a passkey portability specification coming to do passkey migrations between managers. But in general it's a bad idea to have the passkeys just sitting around in text files so the current managers are largely designed around preventing the tech support scammer from instructing grandma to dump the passkeys and email it to them.
- deleted 1y ago[deleted]