3 ms·
On my keychain in a USB hardware token. With a couple of backup tokens in fire safes.
by iamnothere 16d ago
On my keychain in a USB hardware token. With a couple of backup tokens in fire safes.
- rcxdude 16d agoIf you're using a USB hardware token your knowledge of it is at least an order of magnitude better than the median user's. I know where my passkeys are stored, I don't know where my family member's passkeys are stored and neither do they. The same is true for most of my otherwise fairly technical co-workers.
- iamnothere 16d agoThere needs to be industry and government leadership on this to gradually require hardware token usage, for at least critical financial and government applications. Right now everyone is putting their energy behind passkeys, but those are much harder to understand than a physical token. I don’t know any non-technical people who understand how passkeys are normally tied to the device (or the manufacturer-provided cloud account in some cases), how to set them up on a second device, why you might want to do that, etc. And many technical people still don’t get it either!
- ampersandwhich 16d agoAbsolutely not. If that is required, I will do my damndest to only use implementations that deliberately lie about the hardware status. Your line of reasoning is dangerous.
- faust201 16d agoThen that family member does not worry like you do worry. The main point is assuming one can have a proper security for Google account - everything else becomes easy. The fearmongering of losing google account should stop. Yes, some people lose it. There are a larger proportion losing/getting pwned by repeat use. For the majority - just pressing the fingerprint to access an account (like amazon/eBay) via passkey is great. Fairly technical co-workers - I used to suggest them to buy USB security key few years ago. Now that same fairly technical some how has at least 2 devices with them - so they just skipped the USB security key need - and just use Google (in Android) or iPhone in Apple ecosystem. Everything just works. Yes, there will be a poor soul that may lost everything with only one device.
- iamnothere 16d agoPeople keep their entire lives in cloud accounts these days. Their passwords, financial history, copies of important documents, baby photos, etc. Losing access to it is incredibly disruptive and may result in unrecoverable losses. It shouldn’t be this way, but it is.
- faust201 16d agoAt the same time, I know so many people believing DIY raspberrypi based NAS and losing lots of data (thankfully they had cloud backups). Not everyone has access to server grade hardware.
- Aerroon 16d ago>Then that family member does not worry like you do worry. Until they lose access to that account and then it becomes my problem to solve.
- faust201 16d agoThis is a different issue. Not everyone has a data engineer - know it all as a family member. And you need to accept it works for millions.
- rcxdude 16d agoWorking for millions doesn't imply a good hit rate. Google could release a feature that worked 1% of the time and manage that, as well as barely noticing if it wipes out 10% of their users. My actual experience is that almost all the people I know who are using passkeys are using them by mistake and it's only not a big problem because they aren't currently being used up to their promise of preventing the vulnerable authentication methods.
- faust201 15d agoMy actual experience is people with passkey are fine. No more account take over. Mote over they like frictionless login. Yes there are few that used bitwarden and lost everything as their sync using syncthing failed.
- UltraSane 16d agoThe biggest issue with passkeys is that since most USB tokens that support them don't allow syncing the private key to a backup device you have to enroll ALL of them to every site that supports passkeys. This is annoying but it makes storing backups in secure offsite locations impractical.
- iamnothere 16d agoThis is a fair criticism and needs work, I have some short thoughts on it here: https://news.ycombinator.com/item?id=49755217 https://news.ycombinator.com/item?id=49755217
- mrguyorama 16d agoThe entire problem with passkeys is that zero of the issues should have been a surprise, because it should have been part of the design discussion from the start, so the fact that it's not properly implemented before being forced on users says that either it's been done horrifically incompetently and nobody should trust it, or they internally found these concerns and ignored them which means this system is not at all meant to help us, so why is it being forced on us?
- EvanAnderson 16d agoIt's beyond annoying. It's creating needless toil that no "normies" will ever actually do. I'd love a hardware sold in multi-packs and "born" at the factory with identical internal device key encryption keys (DKEK). I'd love, even more, if a token just allowed you to "commission" new ones w/ a user-specified DKEK on first use. I'd use one token as a daily driver and store the other(s) in safe location(s), empty of my personal key material. (Or, if I can just commission a new token w/ my DKEK, store a printed copy of my DKEK in a safe location.) Give the token a mechanism to "type" a backup of its internal state, encrypted with the DKEK, as a USB HID keyboard. That gives me an easy way to backup the token each time I enroll a new website. If I lose my daily-driver token I just pull a spare from storage, import my last backup, and I'm up and running. That would kick ass. No "You just need to buy two tokens and enroll them in every website" bullshit.