3 ms·
Passkeys are an open standard? You might as well argue against SSH keys.
by inkysigma 7mo ago
Passkeys are an open standard? You might as well argue against SSH keys.
- hedora 7mo agoThe standard includes a hardware attestation path. That’s the backdoor allowing the eventual takeover of your OS. First people use passkeys, and they become standard. Then they become required for important accounts for security. Then the important accounts require the attestation bit. At that point, you cannot run web browsers on open source operating systems. This is all boring and predictable. It is exactly what they did with Android, and exactly the same organizations are pushing passkeys. Note: If they had good intentions, the operating system would manage any attestation, and not allow websites to query for or require attestation support.
- johncolanduoni 7mo agoThe attestation actually has nothing to do with the browser, only the holder of the passkey's key material. You can satisfy the attestation by having a passkey on your Android device and doing the normal Bluetooth flow with your Firefox browser on your Framework laptop. So this mechanism is totally useless for enacting this plan. The operating system doesn't manage attestation because that's totally useless for the stated goal of the attestation system. Enterprises don't want their SaaS vendors to accept passkeys from some random employee's BitWarden, instead of the hardware keys they issued the employee. If the OS manages attestation and doesn't send anything to the relying party, then it doesn't solve anybody's problem at all.
- doubled112 7mo agoDoes Firefox support the Bluetooth flow on Linux at this time?
- johncolanduoni 7mo agoThat's a matter of implementing an open standard. Google hasn't done anything to prevent open source browsers and OSes from implementing it, and nothing in the spec makes it difficult for Firefox/Linux specifically AFAICT.
- hedora 7mo agoIt seems like it will only be a matter of time before consumer sites start requiring a patched OS with an attestation bit set in the key. Also, as I understand it, sites can whitelist credential hardware. If not, then the attestation is security theater. I (or an attacker on your machine), can just make a sw emulator of a hw attestation device, and use that to protect my choice of OS, (and skim your credentials). If a whitelist exists, then my “hijack your OS” plan works: Require the builtin macos/windows/signed chrome on signed os password managers. That’s 90% of the market (and dropping) right now.
- johncolanduoni 7mo agoAs I said, the attestation structurally does NOT attest to your OS or your browser that are displaying the website performing the authentication. It attests to the device that holds the passkey's key material, which is usually not your desktop computer.
- Borealid 7mo agoThe attestation is in fact readable by the FIDO Platform (the browser/OS). It is not encrypted to be readable only by the RP (web site). It talks about whatever you used to authenticate and the platform can manipulate (or omit) it.
- johncolanduoni 7mo agoYes, but the attestation does not tell the RP anything about the browser. The whole point of the nightmare scenario above was for Google to sneak browser attestation in via passkey attestation. The browser being able to see the attestation doesn’t matter for that.
- debazel 7mo agoI do not want any business with Apple/Google/Microsoft at all, including owning an Android or iPhone for hardware attestation.
- jesseendahl 7mo agoYou don't need to use anything from Apple/Google/Microsoft. Passkeys are just WebAuthn which is an open standard.
- debazel 7mo agoAn open standard that has attestation in it which allows sites to block all open implementations. FIDO Alliance spec writers have even threatened that apps like KeepPassXC could be blocked in the future because they allow you to export your keys.
- peterspath 7mo agoThat standard also allows for importing and exporting passkeys. Apple added that in iOS/macOS/etc 26 to their platforms. https://9to5mac.com/2025/06/13/ios-26-passkeys-password-transfer/ https://9to5mac.com/2025/06/13/ios-26-passkeys-password-tran...
- debazel 7mo agoThe export is end to end encrypted, so you do not have ownership of the data, and the provider (Apple in this case) has full control over who you are allowed to export your keys to. (Notice how there are no options to move your keys to a self-hosted service.)
- lxgr 7mo ago> The standard includes a hardware attestation path. Yes, and iOS and Android's Passkey implementation does not support it, since doing so would be lying about a given credential being hardware-backend when it's actually not (due to being cloud-synced and often recoverable via some process). Attestation is only for hardware authenticators, either dedicated ones like Yubikeys or non-synchronized Android WebAuthN credentials. (iOS only supports them in MDM contexts anymore, I believe.)