23 ms·
The attack pattern is: 1) User goes to BAD website and signs up. 2) BAD website says “We’ve sent you an email, please enter the 6-digit code! The email will c
by DecoPerson 1y ago
The attack pattern is:
1) User goes to BAD website and signs up.
2) BAD website says “We’ve sent you an email, please enter the 6-digit code! The email will come from GOOD, as they are our sign-in partner.”
3) BAD’s bots start a “Sign in with email one-time code” flow on the GOOD website using the user’s email.
4) GOOD sends a one-time login code email to the user’s email address.
5) The user is very likely to trust this email, because it’s from GOOD, and why would GOOD send it if it’s not a proper login?
6) User enters code into BAD’s website.
7) BAD uses code to login to GOOD’s website as the user. BAD now has full access to the user’s GOOD account.
This is why “email me a one-time code” is one of the worst authentication flows for phishing. It’s just so hard to stop users from making this mistake.
“Click a link in the email” is a tiny bit better because it takes the user straight to the GOOD website, and passing that link to BAD is more tedious and therefore more suspicious. However, if some popular email service suddenly decides your login emails or the login link within should be blocked, then suddenly many of your users cannot login.
Passkeys is the way to go. Password manager support for passkeys is getting really good. And I assure you, all passkeys being lost when a user loses their phone is far, far better than what’s been happening with passwords. I’d rather granny needs to visit the bank to get access to her account again, than someone phishes her and steals all her money.
- antaviana 1y agoIf we are talking about real time phishing then sending a code to the email is as secure as a 2FA authentication with password and Google Authenticator code.
- SethMurphy 1y agoCan you explain this more, I don't understand Google authenticator completely? Could a bad actor spoof a 2FA as they can with an email, and capture your input?
- delusional 1y agoThe attacker would just ask you for the TOTP code and forward that to Google.
- jddj 1y agoIn practice it's maybe slightly harder, because they'd have to convince a user to enter their google 2fa code into a site that isn't obviously google? I'd imagine a convincing enough modal would do the trick though, in a lot of cases.
- chii 1y ago> convince a user to enter their google 2fa code into a site that isn't obviously google? if the BAD site itself looks legit, and has convinced a user to do the initial login in the first place, they won't hesitate to lie and say that this 2-factor code is part of their partnership with google etc, and tells you to trust it. A normal user doesn't understand what is a 2factor code, how it works, and such. They will easily trust the phisher's site, if the phisher first breaks the user and set them up to trust the site in the beginning. What google does is to send a notification to the user's phone telling them someone tried to access their account if this happened (or any new login to any new device you previously haven't done so on). It's a warning that require some attention, and depending on your state of mind and alertness, you might not suspect that your account is stolen even with this warning. But it is better than nothing, as the location of the login is shown to you, which should be _your own location_ (and not some weird place like cypress!).
- SethMurphy 1y agoWhat I don't understand is how the site will send the 2FA code request to the bad actors phone, instead of the real users phone? Is this not part of what makes it more secure than a text or email? Wouldn't the bad actor need to be logged into the authenticator as the user your trying to hack?
- chii 1y ago
- Hackbraten 1y agoMy password manager will protect me from entering my password into a website on the wrong domain. It won’t protect me in the passwordless case where the code is sent via email.
- arccy 1y agoThis is also the same problem with TOTP 2fa, passkeys are definitely the way to go for most people.
- DougN7 1y agoIt sounds good, unless granny needs to visit Google or Microsoft to get a new password after losing her phone. Then what??
- drozycki 1y agoShe follows same reset flow as before. Passkeys are identical in this respect to the passwords of yore.
- politelemon 1y agoThen that's worse, it's now two authentication flows to remember. It's only made the situation more complicated.
- cuu508 1y agoIf granny forgets her password, she looks it up on the last page of her notebook where it is written down. Granny cannot write down her passkey. To avoid getting locked out you could add 2-3 passkeys from different providers to each account. And/or use a passkey provider that allows backups, and back up your keys. But I doubt many people will have the discipline to do either of that.
- raphinou 1y agoHonest question: isn't that introducing some weaknesses, allowing the attacker to either reactivate password auth or add it's own passkey eh by tricking the user in accepting that change after receiving a mail with a link to accept that change? That would make the passkey unbreakable, but leave other easier to exploit weaknesses.
- izacus 1y agoNo. You always need that flow.
- jonplackett 1y agoThe problem with passkeys is they’re very unfamiliar and it’s easier therefore for less experienced users to get confused or tricked.
- sriku 1y agoA while ago, I implemented a signin approach that looks similar to this "send a link/code" mode but (I believe) can't be exploited this way - https://sriku.org/blog/2017/04/29/forget-password/ https://sriku.org/blog/2017/04/29/forget-password/ - appreciate any thoughts on that. Btw this predates passkeys which should perhaps be the way to go from now on.
- richardwhiuk 1y agoOne problem is you are requiring users to trust and click on a link in an email which is historically frowned upon. So you are undercutting phishing education.
- dogpuncher 1y agoI don't understand your example. > 2) BAD website says “We’ve sent you an email, please enter the 6-digit code! The email will come from GOOD, as they are our sign-in partner.” Does that mean that GOOD must be a 3rd party identity provider like Facebook, Apple, Google etc?
- Philpax 1y agoBAD is lying about GOOD and presenting GOOD's legitimate service as a mere IdP for BAD, such that the user provides their code for GOOD to BAD so that the latter can then automatically log into GOOD.
- hombre_fatal 1y agoNo, BAD just inserts your email address on GOOD’s login page which sends you the login code, and they lie to prime you into thinking it’s not suspicious that the email came from someone other than BAD. When you insert the login code on BAD, BAD uses it to finish the login process on GOOD that they started “on your behalf”.
- Almondsetat 1y agoThis attack technique is called "real time phishing". If you need a diagram or a more detailed explanation, look it up
- atoav 1y agoBAD assumes: 1. you got login credentials at GOOD 2. you're using the same email address there They then tell you GOOD will send you a code that you have to enter on their website. Then they enter your Email on GOOD and request a reset, which sends a mail with a code to you. You then enter the code on their website. Now that they have the code they can enter it on GOOD and they have your account.
- lmm 1y agoThey don't have to actually be a 3rd party identity provider, just the user has to find it plausible that they might offer 3rd party login. Which, to be honest, pretty much any big or even medium-sized tech company might be doing these days.
- rustystump 1y agoLinks are more worse than otp but both can easily be secure if users check domain which users never do so links and otp are terrible. Long live passkeys.
- klabb3 1y ago> if users check domain which users never do To be fair, can we blame them? There are so many legitimate flows that redirect like it’s a sport. Especially in payments & authn, which is where it’s most important. Just random domains and ping pong between different partner systems.
- t_mann 1y agoThe problems of Passkeys are more nuanced than just losing access when a device is lost (which actually doesn't need to happen depending on your setup). The biggest problem are attestations, which let services block users who use tools that give them more freedom. Passkeys, or more generally challenge-response protocols, could easily have been an amazing replacement for passwords and a win-win for everyone. Unfortunately, the reality of how they've been designed is that they will mainly serve to further cement the primacy of BigTech and take away user freedom.
- tialaramex 1y agoDo you have some examples where people actually require attestation in 3rd party facing systems? Or is this purely "But in theory..." and you've dismissed all the very real problems with the alternatives because you're scared of a theoretical problem ? I always reject attestation requests and I don't recall ever having been refused, so if this was a real problem it seems like I ought to have noticed by now.
- lmm 1y agoThey're not going to start requiring them until they've phased out non-passkey login. But at that point it will be too late.
- XorNot 1y agoI don't know why people don't see this coming: very obviously once Passkeys are everywhere, it'll become "we're requiring attestation from approved device bootloaders/enclaves" and that'll be your vendor lock in where it'll be just difficult enough that unless you stick with the same providers phone, you might lose all your passkeys.
- growse 1y ago> very obviously once Passkeys are everywhere it'll become "we're requiring attestation from approved device bootloaders/enclaves" This is far from very obvious, especially given that Apple have gone out of their way to not provide attestation data for keychain passkeys. Any service requiring attestation for passkeys will effectively lock out every iPhone user - not going to happen.
- boredhedgehog 1y ago> Passkeys is the way to go. I wish there was a stronger differentiation between syncable and device-bound passkeys. It seems like we're now using the same word for two approaches which are very different when it comes to security and user-friendliness. And yes, giving granny unsyncable passkeys is a really bad idea, for so many reasons.
- deleted 1y ago[deleted]
- mths 1y ago> I wish there was a stronger differentiation between syncable and device-bound passkeys. But there is no difference. I'd prefer if services just let me generate a passkey and leave it entirely up to me how I manage it. Whoever setup granny's device should have done so with a cloud based manager. I think Google tries to make some confused distinction, or maybe that has more to do with FIDO U2F vs FIDO2. There you can add either a "passkey" or a "security key", but iirc I added my passkey on my security key so... yeah
- WesolyKubeczek 1y agoI guess this flow is even worse for authenticators like Duo or even Apple’s own iCloud logins with 2fa. You log on to a phishing site mimicking the real one, and your phone asks if it is you trying to log in. Yes of course it’s you logging in, but you don’t realize you’re logging in bad guys by proxy. The prompts that show where the login is coming from are useless, too, because mapping from IP addresses to geographical locations is far from perfect. For example, my legit login attempts showed me all over my country map. If I’m in a corporate VPN already, its exit nodes may also be all over the map, and your legitimate login from, say, Germany may present itself as coming from Cyprus, which is shady as fuck. If I seek to implement 2fa for my own service and have it be not theater and resistant to such phishing attacks, it gets difficult real fast.
- kqr 1y agoPasskeys are still a shared secret, aren't they? Asymmetric cryptography would have been amazing. Barring that I would actually recommend Oauth or something like it, to limit the number of parties who manage shared secrets to a smaller set of actors who have more experience doing so.
- kro 1y agoThey are in fact public/private keys and use signing a challenge for authentication.
- barrkel 1y agoBut in practice they usually rely on attestation by an approved vendor, and the vendor won't let you control your private key, so they'll leverage it for lock-in.
- growse 1y agoNo, they're just resident webauthn credentials which use asymmetric crypto.
- yoz-y 1y agoI don’t like passkeys. Before my process to login was: - open website - if not already logged in, log in to 1Password - autofill password - autofill TOTP Now: - open website - if logged in to 1Password the Use Passkey usually shows up - if not: - log in to 1Password - choose use passkey - this almost always does nothing - choose “use other method” - choose “password” - autofill that - now there is another dialog to choose the 2fa method, choose Authenticator - autofill that Passkeys would be great if they actually made anything simpler on a computer. They work fine on the phone but that’s not where I spend most of my time.
- geden 1y agoPasskeys work very smoothly with Safari and Apple Passwords. Apple Passwords now sufficiently good to replace 1Password for me and I’m slowly transitioning. I don’t mind subscription models per se but there was something about subscription for your own passwords that made me refuse to jump the fence when 1Password switched to that model. Would be a bit faffy if you’re a Chrome user.
- kelnos 1y ago... or like most people, and not a Mac user.
- hgomersall 1y agoOr anyone that thinks a monoculture is bad and that perhaps we shouldn't trust a single vendor with everything important.
- jonplackett 1y agoIt works fine until you dare to have TWO accounts for the same website. Safari will just randomly pick one of them and always tray to log you in with that passkey every time you visit, and the interface for using a different one is really annoying.
- 1y ago
- valenterry 1y ago> Passkeys is the way to go No, at least not on its own. Let's not repeat the mistakes. Password managers are the way to go and ONLY FOR RARE EXCEPTIONS we should use dedicated MFA, such as for email-accounts and financial stuff. And the MFA should ask you to set up at least 3 factors and ask you to use 2 or more. And if it doesn't support more or less all factors like printed codes, OS-independent authenticator apps and hardware keys like yubikey, then it should not be used.
- degamad 1y agoPasskey are more like password managers, and less like MFA tokens - despite the fact that many passkey implementations can function as MFA tokens as well. Bitwarden the password manager includes a full passkey implementation, which doesn't involve any MFA.
- valenterry 1y ago> Passkey are more like password managers, and less like MFA tokens No: - I can always export and import all my passwords from/into my password manager - My passwords always work independently of a password manager or any specific app/OS/hardware That is not true for passkeys and makes them much more like tokens. Of course they don't have to be used in MFA, just like passwords.
- jerf 1y agoI just exported my Bitwarden vault and the resulting .json file has my passkeys in it. I'm not going to try to test import, but if it doesn't work that would obviously be more "bug" than anything else. Clearly "export" is the high concern functionality and once exported, importing them is not a big deal. This is only about your first paragraph, it doesn't affect your second.
- geodel 1y agoIndeed. Credential Exchange Protocol (CXP) is already been worked on and all major vendors are planning to support it. There was talk also in Apple WWDC 2025 about Passkey related APIs including exporting them.
- klipt 1y ago> I’d rather granny needs to visit the bank to get access to her account again Visiting the bank is fine. But who do you visit to recover your Gmail password?
- probably_wrong 1y agoFor the record, if you're in the EU you can make a GDPR request to their Data Protection Officer - since it's your data what's being kept away from you, you have the right to at least a backup. It can take months and it only guarantees a backup, not full access, but it's better than nothing.
- aembleton 1y agoHow would you prove to their data protection officer that you are the owner of that Gmail account?
- probably_wrong 1y agoIn theory: they can ask for ID, sworn affidavit, or whatever other means their local laws determine to be valid. At the end of the day, proving that someone owns something is not a new problem. I've also seen "here's some evidence that I know what the contents of the account are, my legal name matches the account and my legal address matches some emails there". In practice: in my case, anecdotally, they just did it. For some reason owning the backup email account was not enough for the automated workflow to unlock my account, but sending a letter threatening to sue under the GDPR somehow changed their minds.
- kbolino 1y agoEven if they provide you with a dump of their database records on you, you will not be able to recover your password from the salted iterated hash, PBKDF2, bcrypt, Argon2, or whatever else irreversible function they used to store it.
- geocar 1y ago> The attack pattern is: There are lots of attack patterns. That is one. I am not certain I believe it is very likely, because (a) I think "sign-in partner" is obvious bullshit, and (b) I don't understand why I would never enter a code into the wrong website. I believe it can be possible, but... > Passkeys is the way to go. ... I’d rather granny needs to visit the bank to get access to her account again, than someone phishes her and steals all her money. ... I do not agree your story is justification for passkeys, or for letting banks trust passkeys for authentication purposes. I'd rather she not lose access to banking services in the first place: I don't think banks should be allowed to do that, and I do not think it should be possible for someone to "steal all her money" so quickly -- Right now you should have at least several days to fix such a thing with no serious inconvenience beyond a few hours on the phone. I think it is important to keep that, and for banking consumers to demand that from their bank. A "granny" friend of mine got beekeeper'd last year[1] and her bank reversed/cancelled the transfers when she was able to call the next say and I (local techdude) helped backup/restore her laptop. I do not think passkeys would helped and perhaps made things much worse. But I don't just disagree with the idea that passkeys are useful, or even the premise of a decision here between losing all their money and choosing passkeys, I also disagree with your priors: Having to visit a bank branch is a huge inconvenience for me because I have to fly to my nearest. I don't know how many people around here keep the kind of cash they would need on-hand if they suddenly lost access to banking services and needed to fly to recover them. I think passkeys are largely security-theatre and should not be adopted simply if only so it will be harder for banks to convince people that someone should be able to steal all their money/access with the passkey. This is just nonsense. [1]: seriously: fake antivirus software invoice and everything, and her and her kid who is my age just saw the movie in theatres in like the previous week. bananas.
- pavon 1y ago> I am not certain I believe it is very likely, because (a) I think "sign-in partner" is obvious bullshit, and (b) I don't understand why I would never enter a code into the wrong website. I believe it can be possible, but... Now replace email a with text message sent from a short-code.
- rightbyte 1y ago
- traceroute66 1y ago> Passkeys is the way to go. My problem with passkeys is that there is no hardware attestation like there is with Yubikeys and similar. This means for security conscious applications you have no way of knowing if the passkey you are dealing with is from an emulator or the real-deal. Meanwhile with Yubikeys & Co you have that. And it means that, for example people like Microsoft can (and do) offer you the option to protect your cloudy stuff with AAGUID filtering. And similar if you're doing PIV e.g. as a basis for SSH keys, you can attest the PIV key was generated on the Yubikey. You can't do any of that with passkeys.
- timmyc123 1y ago> You can't do any of that with passkeys. Device-bound passkeys which are used in workforce / enterprise scenarios are typically attested. Attestation does not exist for consumer synced passkeys by design. It is an open ecosystem.
- hulitu 1y ago> Passkeys is the way to go. Password manager support for passkeys is getting really good. And how do you access your password manager when your computer is locked ?
- continuational 1y agoEasy to mitigate by only allowing the device that requested the 6-digit code to use the code. Edit: See first reply, this is not a mitigation at all!
- chii 1y agobut the device is under the control of BAD. They fake a signin on their backend to GOOD. Your computer never touches GOOD at all, except from seeing the email from GOOD (which you're told about by BAD, and lied to about being a partner signin thing). The problem being exploited by BAD is that your login account identifier (email in this case) is used in both GOOD (and BAD - accidentally or deliberately orchestrated), and 2-factor does not prevent this type of phishing.
- apt-apt-apt-apt 1y agoWould it be a viable and simple solution to only enter 6-digit codes into the specific website that requested it? Isn't this the same thing as BAD asking, let us know the code i.e. password that GOOD gave you? Why would one be inclined to give BAD (i.e. someone else) this info?
- kylehigginson 1y agoThis came to my mind too. But by using a password manager it will be able to differentiate between the GOOD and BAD site. So I think the point is valid only if the user is not using a password manager.
- pmontra 1y agoOr copy pasting passwords manually. In that case the password manager is equivalent to a list of passwords on a sheet of paper.
- FabHK 1y agoIf you're phished, you're probably not checking the domain too carefully anyway. You get an email, providing you with a phishing link for miсrosoft.com (where the apparent c is actually the cyrillic "s", so BAD). In the background, they initiate a login to microsoft.com (GOOD), who then send you a 6 digit code from the actual microsoft.com. If you were fooled by the original phishing website, you have no reason to doubt the code or not enter it.
- dominicrose 1y agoI'm not sure what kind of websites are vulnerable to these attacks, but websites that have double authentication seem pretty safe to me. And if you forgot your password, then you receive an e-mail to change it with a secure link. This point means the user is not paying attention: 1) User goes to BAD website and signs up. Steps 2-7 wouldn't be possible without 1.
- j1elo 1y ago"User not paying attention" is ultimately the reason for most phising attacks. It happens a lot, and we're trying to solve it as the known problem it is. Everybody, and I say everybody are human beings at the end of the day (so far...) and so by definition, can have a bad day and lower their defenses. It has ironically even happened to reputated security specialists.
- zozbot234 1y ago> I'd rather granny needs to visit the bank to get access to her account again, than someone phishes her and steals all her money. The problem is that I can physically show up at my local bank branch or at my job's IT helpdesk to get my account back, but I can't show up at the Googleplex or at Facebook's or Xitter's HQ and do the same. Device bound passkeys are very error prone for the latter scenario, since users will fail to account for that case.
- hombre_fatal 1y agoTo add, services account for that failure by introducing something worse: a customer service backdoor where you can get into an account with very weak or nonexistent authentication. With Amazon's live chat, someone was able to get into my account by providing an address in the same city as the destination of my latest Amazon order. You see this with 2FA since "sorry lol you've lost your account forever" isn't an option, and it's trivial for users to lose their 2FA key unlike, say, access to their email.
- philistine 1y agoThe solution is what's already happening, but throughly enforced: allow designated users to restore your access to your account.
- hombre_fatal 1y agoHeh, that is kinda interesting and I've never heard of it before. What are some services that have this set up? So, I guess you set up some "emergency users". And maybe if you lose access to your account, you get customer support to mark your account as lost which sends an email to the address that you have on file (in case it's an attack started by someone other than the user). And I suppose if N days pass without any login, one of your emergency users can generate a credential that they can pass to you to recover your account?
- philistine 1y ago
- roelschroeven 1y ago> “Click a link in the email” is a tiny bit better because it takes the user straight to the GOOD website, and passing that link to BAD is more tedious and therefore more suspicious. "Click a link in the email" is really bad because it's very difficult to know the mail and the link in it are legitimate. Trusting links in emails opens to door to phishing attacks.
- johnisgood 1y agoYeah, I was frowning when I read that. It is not any better at all, not even a tiny bit.
- ramraj07 1y agoI know not to click links on random emails but comfortably click links on emails I initiated from a website.
- Cthulhu_ 1y agoYou do, but does the average user? Security's reliance on people's behaviour / knowledge / discipline should be minimal.
- roelschroeven 1y agoHow do you know the email comes from that website? There are known cases of phishing mails being sent when people expect a legitimate mail.
- Yeul 1y agoIf someone hacks my account and starts ordering stuff on bol it's not my problem but the company's so I don't sleep over it. The company doesn't care either because fraud is just the cost of doing business- ease of ordering> security.
- KingOfCoders 1y agoThe website is abc.com the link in the email is abc.com
- avodonosov 1y agoThe scheme is impossible, because the GOOD site says in the email "NEVER SHARE THIS ONE TIME CODE WITH 3RD PARTY APPS OR INDIVIDUALS"
- Perz1val 1y agoPhising = pretending you're the first party
- avodonosov 1y agoTuesday follows Monday
- Perz1val 1y agoI don't know if you're sarcastic or just missing the problem; which is that people will be presented with lika a facebook login page, on a site with url like `facebook.quick-login.com` or `facebock.com` and they'll enter the passcode since as fair as they were concerned, they did everything correct. The disclaimer does shit preventing that, they »obviously« didn't share the code with any other website, they entered it on the facebooks as they were told!
- avodonosov 1y agoI am sarcastic because this discussion is about a different attack. Not about fishing. (The OP says one time codes are worse than passwords. In case of fishing passwords fail the same way as one time codes.) I was also sarcastic/provocative even in the prev comment, saying the GOOD site always includes a warning with the code making the attack impossible. A variation of the attack is very widely used by phone scammers: "Hello, we are updating intercomm on your appartment block. Please tell us your name and phone number. Ok, you will receive a code now, tell it to us". Yet many online services and banks still send one time codes without a warning to never share it! The fishing point may also be used in defence of one time codes: if the GOOD service was using passwords instead of one time codes, the BAD could just initiated fishing attack, redirecting the user to a fake login page - people today are used to "Login with" flow.
- WithinReason 1y agoyou can to the same with text messages, right? That's even more scary.
- Fargren 1y agoI don't see how that's worse than user-password authentication. For password without 2FA the attack pattern is 1) User goes to BAD website and signs up (with their user and password). BAD website captures the user and password 2) BAD website shows a fake authentication error, and redirects to GOOD website. Users is not very likely to notice. 3) BAD uses user and password to login to GOOD’s website as the user. BAD now has full access to the user’s GOOD account. OK, with a password manager the user is more likely to notice they are in BAD website. Is that the advantage?
- samsk 1y agoCan happen, but on the BAD website will the password manager not offer saved password, so user has higher chance of noticing smth. is wrong. Of course if he uses pass manager with complex passwords...
- dan-robertson 1y agoMost password managers are fussy about which websites they fill the password in on. It’s partly a convenience feature to only show relevant accounts but it’s also a security feature to avoid phishing. Passkeys are stronger here because you can’t copy and paste a passkey into a bad website.
- nicce 1y ago> Passkeys is the way to go. Password manager support for passkeys is getting really good. And I assure you, all passkeys being lost when a user loses their phone is far, far better than what’s been happening with passwords. I’d rather granny needs to visit the bank to get access to her account again, than someone phishes her and steals all her money. I am waiting for the era when using passkeys is not depending from some big tech company.
- jp191919 1y agoI use them without being dependent on big tech.
- MyOutfitIsVague 1y agoWe're in that era. BitWarden supports them natively, and you can even self-host.
- timmyc123 1y ago> I am waiting for the era when using passkeys is not depending from some big tech company. You can choose any credential manager you want to store your passkeys.
- wavemode 1y agoThe maker of the credential manager is still a "big tech company", and there is still lock-in. Before I ever use any passkey solution, I would need to be guaranteed the ability to export and backup my passkeys and migrate them wherever I want. My expectations for how long I intend to be alive and using the internet is much longer than my expectations for the continued operation and service of any particular passkey management software. I already had to jump ship from LastPass after they were hacked. Imagine if they hadn't allowed me to migrate my passwords.
- timmyc123 1y agoBitwarden is a great option for you. You can even self host it!
- smallerfish 1y agoBut you could replace #2 with "Enter your password from GOOD, as they are our sign-in partner". I'm not in favor of emailing 6 digit codes either, but your scenario presupposes that users will be willing to trust that two services have intermingled their auth, and in that case their password can be wrangled from them too.
- deleted 1y ago[deleted]
- Hackbraten 1y agoMy password manager won’t allow autofilling in the latter case, because it remembers the domain I used at sign-up time. On the rare occasion that my password manager refuses to autofill, I take a step back and painstakingly try to understand why. This happens about once a year or twice.
- raxxorraxor 1y agoI like capability URLs. I know an URL isn't a secret, but it works in practice and it works well. A bad practice is the shorten the code validity to a few minutes. This cannot really be justified and puts users under stress, which lessens security. The discussion around passkeys, who is and isn't allowed to store them, almost killed them for me personally. I use them for very, very few services and I don't want to extend it.
- smallerfish 1y ago> Passkeys is the way to go. Password manager support for passkeys is getting really good. I set up a passkey for github at some point, and apparently saved it in Chrome. When I try to "use passkey for auth" with github, I get a popup from Chrome asking me to enter my google password manager's pin. I don't know what that pin is. I have no way of resetting that pin - there's nothing about the pin in my google profile, password manager page, security settings, etc.
- Hnrobert42 1y agoThat is unfortunate, but that sounds more like a chrome problem than a passkey problem. You would have the same issue if chrome saved your password.
- kmac_ 1y agoPasskey is a great example of how five kitchen chefs can't make scrambled eggs. Horrible user experience, terrible marketing, no mental model like "your phone is THE key," no tangible or even symbolic presentation of the key.
- acdha 1y agoThat’s a lot of anger without a substantial argument. For Apple users, for example, the user experience is very smooth and the mental model is “I use iCloud to store my passcode just like I use iCloud to store my passwords”. If you use 1Password, you’re changing iCloud for 1Password instead.
- emushack 1y ago"You lost me the moment you mentioned iCloud". At least that's the way the majority of people I know react to this line of thinking. The "cloud" is still mysterious and complicated to a good number of people. Passwords are easy to understand.
- 1y ago
- thiht 1y agoI hate passkeys because even as a savvy user, I don’t know what to do with them. Do they replace my password? Do I need to generate one passkey per account and per device? How do I login on a new device? Are password managers still relevant with passkeys? They’re too opaque for my taste and I don’t like them.
- Yizahi 1y agoIf attacker would fool me at one website he will get that one account (possibly forever) and that's it. If it is a bank connected account, I can intervene and change email/account by writing a physical request to the bank for example, call the bank, do something. And likely it will be only a single bank account. But it may be even some unrelated account. Maybe it will be my Amazon account and all the attacker gets is some ebooks. Or Steam account. Or some email without important links. Etc. Point is, the damage will be likely local to a single or a handful of accounts. If all the accounts are protected by two factor on my phone and I lose it or it bricks, then I'm done. It will be a total mess with no paths to recover, except restarting literally everything from scratch. I have Google Auth app on my phone and every few months I consider using it, but then reconsider and stay with passwords.
- Aaargh20318 1y ago> I’d rather granny needs to visit the bank to get access to her account again, than someone phishes her and steals all her money. But granny can't go to a bank because they closed down most of their offices. Since 99% of what you need a bank for can be done using their app it no longer made financial sense to have a physical presence in most smaller towns and villages. Lots of elderly were complaining about this when it happened because they were too lazy to learn how to use the bank apps. Hell, they already started complaining when you could no longer withdraw money at the desk even before they closed down the offices. Apparently even learning to use something as simple as an ATM was too much effort for them.
- octo888 1y agoYou do realise the average granny is in cognitive decline and dealing with a myriad of health issues? You can judge a society (or a company) by how they treat their elderly
- danparsonson 1y agoWith luck, one day you'll be old and then perhaps you'll understand how unkind your last paragraph is.
- florieger 1y agoHow is it worse than using a password? I think I'm missing something, please explain. 1) User goes to BAD website. 2) BAD website says “Please enter your email and password”. 3) BAD’s bots start a “Log in with email and password” on the GOOD website using the user’s email and password. 4) BAD now has full access to the user’s GOOD account.
- michaelsshaw 1y agoPassword managers can catch this case by not autofilling, hinting the user to take a step back and pay attention.
- Someone 1y agoPeople hopefully won’t reuse the username/password they use on GOOD to log into BAD, so the login that BAD does in step 3 will fail.
- ericjmorey 1y agoSome percent of people will reuse their password. This is all but guaranteed.
- pkilgore 1y agoThere is no password. That's the point. It's just an email, and a six digit code they text you.
- jaggirs 1y agoIn your example, the user is logging in to BAD.com, thinking it is GOOD.com. In the OP's example, the user is logging in to BAD.com intentionally, but his GOOD.com account is still hacked into. This is a lot harder for the user to catch on to.
- account42 1y agoSpecifically, that OP describes sounds like a plausible log-in-with-big-tech-company flow that is really common these days.
- netcan 1y agoGood points but dont underestimate "granny needs to visit the bank to get access to her account again" as a problem. For a lot of people, dealing with (now mostly digital) bureaucracies is a major stress in life. The biggest one, for some. Its not just about invonvenience. Its sometimes about losing access to some, and just not having it for a while. In terms of practical effect, a performance metric for a login system could be "% of users that have access at a given point." There can be a real tradeoff, irl, between legitimate access and security. On the vendor side.. the one time passwords fallback has become a primary login method for some. Especially government websites. Customer support is costly and limited in capacity. We are just worse at this than we used to be. Digital identity is turning out to be a generational problem.
- ilamont 1y agoThat’s right. How many HN denizens are the de facto tech support for family members when they can’t login, can’t update, can’t get rid of some unwanted behavior, or just can’t figure stuff out? I don’t blame them one bit. The tech world has presented them with hundreds of different interfaces, recovery, processes, and policies dreamed up by engineers and executives who assume most of their user base is just like them.
- __MatrixMan__ 1y agoPasskeys will be the way to go if we get them to remove the "attestation object" field from the protocol. Until then there's no way for Jimbob to tell the difference between: > Website: is this Jimbob' phone > Hardware: yes And > Website: I'll give you a dollar if you tell me something juicy about this user > Hardware: Give this token to Microsoft and ask them > Microsoft: Jimbob is most likely to click ads involving fancy cheeses, is sympathetic to LGBTQ causes, and attended a protest last week With passwords and TOTP codes, I am in control of what information is exchanged. Passkeys create a channel that I can't control and which will be used against me. (I chose Microsoft here because in a few months they're using the windows 10->11 transition to force people into hardware that locks the user out of this conversation, though surely others will also be using passkeys for similarly shady things).
- timmyc123 1y ago> Passkeys will be the way to go if we get them to remove the "attestation object" field from the protocol. I don't think you understand the protocol. The attestation object does not mean there is an authenticator attestation. There is no authenticator / credential manager attestation in the consumer synced passkey ecosystem. Period.
- __MatrixMan__ 1y agoIs this not the protocol we're talking about? https://w3c.github.io/webauthn/#sctn-attestation https://w3c.github.io/webauthn/#sctn-attestation It seems pretty clear that "where possible" parties besides the user are provided with information about the user (ostensibly about their device, but who knows what implementers will use this channel for)... so they can make a trust decision. It's going to end up being a root-of-trust play, and those create high value targets which don't hold up against corruption, so you're going to end up with a cabal of auth-providers who use their privileged position to mistreat users (which they already do, but what'll be different is that this time around nobody will trust that you're a real human unless you belong at least one member of this cabal).
- 1y ago
- dada78641 1y agoThis is a 100x better explanation than what's in the blog post. The blog post is practically a tweet.
- eadmund 1y ago> Passkeys is the way to go. No, please, not as long as attestation is in the spec. I firmly believe that passkeys are intended to facilitate vendor lock-in and reduce the autonomy of end users. Frankly, I do not trust any passkey implementation as much as I trust a GPG-encrypted text file.
- TacticalCoder 1y ago> Passkeys is the way to go. I agree but... Passkeys are cloneable though and a clear step back compared to Yubikeys for FIDO2/webauthn. Heck, we even used to have a counter where the user could know if one of its key had been duplicated. I tested this years ago and it worked. That's gone now. For people with strong interests to introduce backdoors worked very hard to lower the security we had: it was too good. The people behind this are going to pretend they lowered security in the name of convenience but to me that's just the excuse: the goal was to lower security and they'll say "we need cloneable passkeys otherwise it's just too inconvenient". xxxINT. Now I'll agree: for regular people passkeys are way better than PIN code or whatever. But if you're a target like a journalist reporting on crooked politicians or a whistleblower exposing frauds, don't go think your passkeys cannot be cloned and used to access your various accounts. Passkeys can be cloned by design. And it's all in totally opaque part of the hardware stack under the control of a few very state-friendly corporations. And those pushing passkeys as the next best thing since sliced bread happen to very often also be the one always turning a blind eye to their states' wrongdoings. So yup, passkeys are good but, no, they didn't lower the security for no reason. So don't rely on passkeys if you're the next Snowden. And certainly don't go to listen to state-apologists explaining that states wouldn't do such things as lowering security standards in order to make sure they've got their shiny backdoors.
- xg15 1y agoThere will not be a bank to visit.
- al_borland 1y agoIsn’t clicking on a link in an email also problematic? It gets users in the habit of trusting links in emails. There is a history of those being used in bad ways as well. I still don’t really understand what recovery looks like for a lost passkey… especially if I lose all of them. Not everything has a physical location where an identity can be validated, like a bank. Even my primary bank isn’t local. I’d have to drive about 6 hours to get to a branch office.
- Arwill 1y agoMobile phone App/Passkey authentication is just a way to pass the responsibility down to users. Losing a phone today is not just losing the passkey, there are "login with QR-code" schemes too, which do not need a password at all. It is a bad trend to pass all security onto the physical phone.
- KingOfCoders 1y agoAnd good luck when your account is closed by the company, e.g. Microsoft or Apple or Google.
- jghn 1y agoIf the target was not actively trying to log into GOOD at that exact moment, why would they treat this as anything other than one of a phishing attempt or spam?
- bombcar 1y agoBecause target WAS trying to login to BAD. Imagine a "free porn, login here" website, when you put in your gmail address it triggers the onetime code from gmail (assuming it did that type of login) - thousands would give it up for the free porn.
- jghn 1y agoOh I see. Misread the whole scenario.
- NoMoreNicksLeft 1y agoIf I have a password manager, what good are passkeys to me? No thanks.
- KingOfCoders 1y agoPlease log into BAD.com - we're a login provider to GOOD.com with a higher security level, from now on use BAD.com to log into GOOD.com Why would I put a secret code from GOOD.com into BAD.com? That's the core of the problem. If you put a code you get from GOOD.com into BAD.com, it's like you put a password from GOOD.com into BAD.com - don't do that.
- Hackbraten 1y ago> If you put a code you get from GOOD.com into BAD.com, it's like you put a password from GOOD.com into BAD.com - don't do that. A password manager will protect me from doing the latter. There’s no way it can protect me from doing the former. Any human can be tricked, no matter how smart they are. A bad actor just has to wait for the right moment. No amount of “don’t do that” can change that fact.
- KingOfCoders 1y agoIf a website says "Do this" and you're the person who follows random websites against security practices, because you believe in authority, a password manager does not help. You will open the password manager, search for GOOD.com and put it into BAD.com and be angry that your password manager can't do that for you. "Any human can be tricked, no matter how smart they are." and "A password manager will protect me from doing the latter." Don't work together. Either everyone can be tricked or not. It says "Everyone can be tricked" but I can't be tricked because I use a password manager.
- Hackbraten 1y ago> you're the person who follows random websites against security practices, because you believe in authority There are many reasons why such lapses of judgements happen, even to people who don’t believe in authority. For example, the fact that any human can be tricked. > Don't work together. Either everyone can be tricked or not. The password manager protects me from filling my password into the wrong site. The password manager will not protect me from BAD.com tricking me into handing them out a one-time code that GOOD.com sent me via email.
- deleted 1y ago[deleted]
- hshdhdhj4444 1y agoThis comment explains why passkeys are nothing more than a way to shift responsibility. If you lose all your data and your entire life because you lost your phone, no company is responsible. But if you get hacked they are. So they’ve come up with a solution that can destroy your entire life, but reduces the risk of corporate liability. But yeah, keep carrying water for the entities that won’t come up with actual user focused solutions because it may cost them 0.01% of their profits.
- zaptheimpaler 1y agoYes that’s what 99% of modern security is. Anything that requires O(N) spending for N users must be thrown away in the name of stock prices.
- _5hxt 1y agoIt’s still possible to use a button in the email if you include a copypasteable variant in the mail itself.
- TechDebtDevin 1y agoI haven't been able to get into my Oracle (free) account for 2 years because I lost 2fa... Unless I start needing to pay them for something, they'll probably never answer my emails. There are consequences for losing your phone when using alternative authentication methods (be careful).
- mvieira38 1y ago>"I’d rather granny needs to visit the bank to get access to her account again, than someone phishes her and steals all her money." More like abuelita gets robbed at gunpoint and made to unlock and clear out her bank account, then has no recourse at home because her device was taken. I live in a third world country and even 2FA simply isn't viable for me due to how frequent phone robberies are. I've had to do the process once and it was a nightmare, whereas with passwords I can just log into Bitwarden wherever and I'm golden
- chimeracoder 1y ago> More like abuelita gets robbed at gunpoint and made to unlock and clear out her bank account, then has no recourse at home because her device was taken. You are describing the current status quo, without passkeys. This is already possible. Well, except maybe for the "without recourse" part, because there are some legal and policy avenues available for dealing with this situation.
- mvieira38 1y agoThe without recourse is the part that matters... With passkeys or 2FA she's at risk of having to wait a day or more to go to the physical location (if there even is one, digital banks are huge in Latin America), with passwords she can just check her notebook the same night and start the recourse through official channels. I know she could just call the hotline, but if 24hr customer service guy can get you in your account same night then the bank is too insecure anyways
- chimeracoder 1y ago> The without recourse is the part that matters... Yes, and I'm saying that part isn't accurate either for the story you're portraying with passkeys or for the status quo. That's not how account recovery flows work.
- mvieira38 1y agoWith passwords, no account was even lost in the scenario for a recovery flow to start. An account recovery flow is only necessary because of the superfluous extra security, which will almost inevitably introduce more attack vectors than before (such as a social engineering attack through customer service) if the banks want to service customers like grandmas.
- RcouF1uZ4gsC 1y ago> 1) User goes to BAD website and signs up. I think this is what Raymond Chen calls the other side of the airtight hatch. The game is already over. The user is already convinced the BAD website is the good website. The BAD website could just ask the user for the email and password already and the user would directly provide it. The email authenticaton flow doesn’t introduce any new vulnerability and in fact, may reduce it if the user actually signs in via a link in the email.
- freeopinion 1y agoPlease help me understand the passkey flow that solves this problem. 1) BAD actor tries to create account at GOOD website posing as oblivious@example.com. 2) GOOD website requests public key from BAD. 3) BAD provides self-generated public key. 4) GOOD later asks BAD to prove that they control the private key. 5) BAD successfully proves they control the private key. Unless you have step 3b where GOOD can independently confirm that the public key does indeed belong to oblivious. But even that is easily worked around.
- arccy 1y agothat's just a strawman bad account creation flow that has nothing to do with passkeys. you verify the email address first. passkeys use a unique keypair per account, there's no single public key that represents you.
- freeopinion 1y agoIndeed, I was illustrating that DecoPerson was proposing that passkeys solve an account creation flow problem. They do not. But as DecoPerson points out, in the realm of account creation, your "verify the email address first" solution has its limits. It is easy to conflate different aspects of trust and think they have the same solution.
- SpaceNoodled 1y agoPasskeys are just passwords that require a password manager.
- michaelmrose 1y agoWhat about the 99 other places granny needs to regain access to after the much more common broke or lost phone many of which doesn't have a meaningful amount of customer service. I see no reason not to use password + one of multiple 2FA methods so the user can regain control.
- sidewndr46 1y agoI work on a product that emails administrators with a list of actions they can take related to certain authorization requests. We got feedback from a customer that all requests were simultaneously approved then denied. It turns out their Microsoft provided email server follows all links and runs all javascript before showing it to the user
- rconti 1y agoPasskeys are a usability nightmare. No two experiences are ever the same. I have passkeys saved in 1Password and in Apple Passwords. I have a YubiKey. I have Duo on my work computer. A common experience is Chrome telling me to scan a QR code. But I know this is not a legitimate method to sign in on any service _I_ use. I also never know WHY I'm being told to "scan this QR code". I scan it, and my phone also has no idea what to do with it! The site has decided, by not finding a passkey where it expects it, that it MUST be on my phone. That's but one example of the horrible implementation, horribly usability, and horrible guidance various sites/applications/browsers/implementations use.
- jancsika 1y ago> “Click a link in the email” is a tiny bit better because it takes the user straight to the GOOD website, and passing that link to BAD is more tedious and therefore more suspicious. Somehow this makes me think of Pascal's Wager... You just got through describing an attack where the victim was not aware that a bad actor can trigger a bona fide password reset code at an arbitrary time. For your little table of threats, you posit that at least clicking the link goes to the bona fide web site. But there's a separate little table of threats for the case where an attacker controls the timing of sending a fake email. I believe realtors have this problem-- an attacker hacks their email and hangs back until the closing date approaches, then sends the fake email when the realtor tells the client to expect one with the wire transfer number/etc.
- derekzhouzhen 1y agoHow is it different from plain old password? 1) User goes to BAD website and enter credentials 2) BAD website use GOOD website to check if credential is valid 3) Pwned It is just MITM attack. The moment you go to BAD and enter credential (password or one time code) you are done.
- SoftTalker 1y agoI suppose the GOOD site should say "do not enter this code on any other sites, we are NOT a login partner for any other sites" but a lot of people would probably not read that. Still, it would help. The very tricky thing about this scam is that it gets people to react to an email that they are expecting. Which means they will not be as guarded as if they got an email out of the blue.
- amelius 1y agoInstead of showing a code, why not give a link that the user can click on?
- sandeepkd 1y agoI am afraid that this flaw is present for almost all phishable methods (SMS, TOTP, email OTP, App Push) to certain extent (except passkeys, mtls) "Click a link in the email" isn't much secure either for most part. You might end up following a link blindly which can lure you into revealing even more information Passkeys aren't that great either cause almost everyone has to provide a account recovery flow which uses these same phishable methods. The language in communication is probably the most important deterrent here, second to using signals in the flow to present more friction to the abuser. A simple check like presenting captcha like challenge to the user in case they are not authenticating from the same machine can go a long way to prevent these kind of attacks at scale
- jcon321 1y agoSo this is only relevant to websites that do not use passwords and only do a temporary one time code... this is not 2FA correct?
- brettgriffin 1y agoedit: kam corrected me below.
- kam 1y agoThe browser that initiated the request is under the control of BAD in step 3.
- brettgriffin 1y agoah, you are correct. thanks for pointing that out.
- anonu 1y agoA similar flow can still happen with passwords. Granted, the user may be confused if they use a password manager and the password doesn't populate.
- phendrenad2 1y ago> “Click a link in the email” is a tiny bit better because it takes the user straight to the GOOD website I don't know, some would say taking an attack from trivial to virtually impossible is a bit more than a "tiny bit".
- araes 1y agoRe: Granny - Pew Research about Online Scams, granny is far less likely to lose her account (15%) than an 18-29 year old (26%). If she's upper income and white even less likely. Similar trends with falling for large numbers of scams. People who've had 3+, granny (19%), 18-26 year olds (24%). [1] The survey notably has the same perception results. Society views the youth as mostly immune from scams (believe only 22%), yet fall victim to them (26%), while worrying about old people (believe 84% fall for them), who actually don't fall victim that often (15%). Most of the time, re: granny, women are targeted a much greater amount because of supposed weakness and vulnerability (report 2/3, victim 2/3), yet males send much larger amounts of money. ($112 vs $205) [2] Too be fair though, old people do tend to lose more with scams. Granny would probably lose $300 on average vs $113 for a 18-24. Conflicting numbers on the money #'s though, so some of that depends on which survey you ask. Old people also tend to write each other a lot of cautionary warning stories such as the AARP article on Stan Lee's swindling in old age (security guard, "senior adviser", "protector", and daughter). [3] Old people get a bunch of grief, yet old people are actually less likely to fall for the scams. Also, if she's a retiree in Miami Beach, more likely to be targeted (Adak, AK; Deepwater, NJ; then Miami Beach, FL are the worst for scams.) [1] https://www.pewresearch.org/internet/2025/07/31/online-scams-and-attacks-in-america-today/ https://www.pewresearch.org/internet/2025/07/31/online-scams... [2] https://bbbmarketplacetrust.org/wp-content/uploads/2025/02/New-Insights-research-report.pdf https://bbbmarketplacetrust.org/wp-content/uploads/2025/02/N... [3] https://www.aarp.org/entertainment/celebrities/stan-lee-elder-abuse/ https://www.aarp.org/entertainment/celebrities/stan-lee-elde...
- ninjachen 1y agoGood explanation! The GOOD's email should contains "Never give this code to others" and the user should know this clearly. I like phone and email OPT, it's easy to login.
- d_theorist 1y agoI think the "click a link in the email" solution is more than a "tiny" bit better isn't it? It almost completely solves the attack pattern you laid out. Passing the whole link to BAD is not only more tedious but totally ridiculous. That is not the kind of thing that even totally naive users would do. And there is a significant benefit of not needing to worry about weak or repeated passwords, password leaks etc. Overall that pattern feels significantly better to me than a normal password system, and MUCH better than the "we'll send you six digits to copy and paste" solution.
- zaptheimpaler 1y agoOr I could keep using passwords in my password manager, where I DON’T lose all my passwords if I lose my phone? Passkeys just seem to solve no real problems and create a black box dependency. Everything I’ve seen about them just makes no damn sense.
- Ey7NFZ3P0nzAe 1y agoFor those like me needing a refresher on passkeys: https://www.passkeys.com/ https://www.passkeys.com/
- bsoles 1y agoAren't your passkeys stored with your password manager? As long as you have web access to your password manager, why would losing your phone be an issue? I am not a passkey users as I find them pretty confusing...
- linhan_dot_dev 1y agoThe scene you described helped me quickly grasp the whole situation! I'd like to add a new example. In your example, the most dangerous part is "the user being convinced to visit the BAD website." Here's my example: - The scammer initiates a login attempt. - The user receives a text message with a 6-digit code and might get confused. - The user receives a phone call from the fraudster. - The fraudster pretends to be a representative from the software platform, convincing the user there's an issue. - At this point, another fake text message is sent, with a link to a convincing-looking platform. - The user enters the 6-digit verification code they just saw on this fake platform. - The scammer logs in successfully.