4 ms·
How does scanning the barcode with your phone log you into the computer? Does your phone need network access for that?
by 201984 16d ago
How does scanning the barcode with your phone log you into the computer? Does your phone need network access for that?
- jerkstate 16d agowhat good is a phone if it isn't on a network?
- cpburns2009 16d agoHave you ever been in a large building with awful cell reception and no wifi access?
- cesarb 16d ago> what good is a phone if it isn't on a network? 1. It might be on a voice network but not on a data network; for instance, if you don't have a data plan. 2. Modern smartphones are actually a hybrid of a traditional cell phone and a traditional PDA, and you might be using it for the PDA part.
- deleted 16d ago[deleted]
- roryirvine 16d agoIf you're not happy connecting your phone to the network, then how likely is it that you would you be willing to enter your login details on a machine you don't control?
- stonogo 16d agoPoor people exist.
- roryirvine 16d agoThe poorest country I'm familiar with is Zambia, where about 90% of the population have a mobile subscription. The number of people sharing GP's concerns for reasons of poverty rather than because of their personal security posture will be vanishingly small.
- arcfour 16d agoI'll have to remember this one the next time I hear the phone/poverty argument made in bad faith.
- rcxdude 16d agoThey still exist, though. And in my experience people in vulnerable positions have somewhere between zero and one phones at any given time, without necessarily any good continuity between them.
- kps 16d ago> The poorest country I'm familiar with is Zambia, where about 90% of the population have a mobile subscription. Only 85%¹ of the population are over the age of 4. Smart kids they've got. ¹ https://populationpyramids.org/zambia https://populationpyramids.org/zambia
- stonogo 16d agoI don't think "fuck 10% of the population" is as strong an argument as you seem to think it is.
- tavavex 16d agoWhat if you just can't have internet on your phone? Like if the computer is connected via Ethernet and there's no wifi network you can connect to? What if you're abroad and have no roaming? And the ultimate question about a person that the modern world can barely conceptualize - what if you have a dumbphone? Or what if your smartphone is lost or stolen or dead and you need to access some account? That last one has happened to me, and I sure am glad I know the key passwords that I need for survival. These may seem like nitpicks, but there's probably a thousand rare scenarios like these that exist. You inevitably have to consider them when you're moving from punching in letters and numbers that you remember in the normal, low-tech way to a complex networked two-device workflow.
- limagnolia 16d agoIf my phone is lost or damaged, I would buy a new, cheap Android phone and sync my passkeys to it. But I am curious why one would need to login to a website in order to survive? If one did have say a severe medical condition that somehow required a website in order to manage, I guess I would concede that maybe passkeys aren't the best way to secure such a life-sustaining website.
- horsawlarway 16d ago> But I am curious why one would need to login to a website in order to survive? They use bank like Ally or Discover with no physical branches. They use a mortgage provider like Rocket mortgage with no physical branches. They use a medication delivery service with no physical customer facing pharmacies. They have an employer that only facilitates reimbursement for expenses via online tools. etc... I guess "survive" has a sliding scale, but if I lost access to critical accounts... my life is going to FUCKING SUCK in a non-trivial and very impactful way almost immediately, on many fronts. And if your answer to that problem is "well, just call them"... then we're right back to the point the article is making: "An account’s security is still dictated by the weakest recovery method" Passkeys aren't a meaningful improvement in security - assuming you do actually have decent password hygiene like a password manager.
- epihelix 16d ago
- enriquto 16d ago> willing to enter your login details on a machine you don't control? Are you talking about your phone here?
- roryirvine 16d agoSure, your personal security posture might very well preclude that. But, again, if you don't trust your phone then how likely is it that you will be prepared to trust a public computer?
- Yokolos 16d agoSteam does this. If I want to login, it shows a barcode I can scan with the app and it logs me in without needing to enter my login information. Phone needs internet access, doesn't need to be on the same network as the device I'm logging in on. I assume the QR code contains a token for the device, which is used by the app to authorize the login and the server automatically logs in the client on the device with the matching token. Seems a lot safer to me than using my login credentials on a potentially unsafe device.
- limagnolia 16d agoYes, this is how it could work, or it could display a code you type into your phone.
- jon-wood 16d agoThere's a whole set of fallbacks built in to the standard, including Bluetooth, local network connections, and going via a relay server. All of them eventually end up with your device signing something and handing that back to the browser on the other device to complete the authentication flow.
- thwarted 16d agoI cannot speak to how accurate your description is, but this description sounds like there are multiple weak points and multiple attack vectors that open this up to increased risk of compromise, undermining the very security stance it's supposed to provide.
- sgerenser 16d agoSee my response above... I believe the description is incorrect, and bluetooth is required to prove physical proximity.
- LocalPCGuy 16d agoThe spec is quite thorough and well thought out in this regard. Despite what it "sounds like" when described, it is very secure, even with a variety of implementations. What is far weaker is that most sites that offer passkeys also offer a multitude of fallback recovery options.
- sgerenser 16d agoAFAIK, the "scan this QR code" method of signing in with a passkey on a phone on a device w/o the passkey requires Bluetooth. There's some type of handshaking that goes on in order for you to prove you're in physical proximity of the device you are logging in on, to prevent phishing attacks.
- sgerenser 16d agoSince I might have made someone mad... to clarify, as I understand it, Bluetooth is absolutely required for this "Scan the QR code" flow to work. However, it's also possible the actual authentication traffic to travel over a different pathway (wifi, cellular), but the bluetooth part is always required though to prove proximity. So on e.g. a library computer without Bluetooth enabled, you would not be able to log in with a passkey on your phone.