Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jesseendahl
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
31.
▲
by
jesseendahl
10mo ago
(1) is already true today. There is no way for services to enforce whether a passkey is stored in software or hardware. (2) I understand you don't like the user experience. But to make a technical clarification: requiring a user action
32.
▲
by
jesseendahl
10mo ago
In theory any code could be written at any time that does something good or bad. Sure. But in reality, the people who actually work on these standards within the FIDO alliance do not want a world where every website/service makes arbit
33.
▲
by
jesseendahl
10mo ago
The primary credential a user relies on for logging in (whether it's a password or a passkey) is pretty unrelated to the the "lockout issue". The lockout issue is really the age old question of: what happens if I can't d
34.
▲
by
jesseendahl
10mo ago
People should be setting up Recovery Contacts so that they have a way of getting back into their Google account even if they lose all credentials (passwords and/or passkeys) and all their devices. https://blog.google/te
35.
▲
by
jesseendahl
1y ago
I legitimately wish there was an option for: "I show up for my appointments 100% of the time and I'll agree in advance to pay a giant fee if I ever don't show up, if you promise not to bother me with appointment confirmations
36.
▲
by
jesseendahl
1y ago
Not sure why this is being downvoted. This user (palata) is correct — phishing is any attempt by an attacker to trick a user into giving up sensitive information. For anyone who is confused: https://www.cloudflare.com/learni
37.
▲
by
jesseendahl
1y ago
Google's Advanced Protection Program supports both passkeys and security keys.
38.
▲
by
jesseendahl
1y ago
>all the encryption in the world does not matter if either end of the conversation is confiscated or pwned by adversaries. Yes of course, but it's not so simple to bypass the hardware-enforced protections that exist both device side
39.
▲
by
jesseendahl
1y ago
No it doesn't — that's a totally different threat model. Advanced Data Protection is mostly concerned with protecting data from attackers on the server and in transit. If you're interested in protections when an attacker has
40.
▲
by
jesseendahl
1y ago
This is not just encryption in transit or simplistic client-side encryption. It is end-to-end encryption, where each device's key generation is handled by your phone's Secure Enclave. This article is a decent starting point in ter
41.
▲
by
jesseendahl
1y ago
>except for MDM devices where the MDM profile can allow attestation for RP domains on an opt-in basis. And even then, the attestation you get in that scenario is just an attestation that the passkey was created on a managed device. It is
42.
▲
by
jesseendahl
1y ago
>I can't call passkeys "phishing-resistant" unless I can lock them down into unexportable passkey providers only I don't think this is accurate. As far as I know, no credential managers (except for maybe KeePassX) all
43.
▲
by
jesseendahl
1y ago
FYI Home Depot supports passkeys which are a significantly better* sign-in user experience than magic links. *faster + easier (fewer steps)
44.
▲
by
jesseendahl
1y ago
Whether or not you can be compelled to unlock your phone doesn't really have anything to do with passkeys. If you can be compelled to unlock your phone, then whatever you have on your phone (including the stuff in your password manager
45.
▲
by
jesseendahl
2y ago
I haven't traditionally seen these areas of spend rolled into Eng costs in the budgeting process.
46.
▲
by
jesseendahl
2y ago
I just had to go through it for a friend who had forgotten their Google password. It was good. Tbh it would be more surprising if it was bad since they have millions of users. So the amount of people who go through that flow every day is pr
47.
▲
by
jesseendahl
2y ago
Yup and iPhone has the same feature. Seems like parent may not be aware of this.
48.
▲
by
jesseendahl
2y ago
You can’t unlock your iPhone with biometrics at first boot, and holding down the two side buttons will make it so your phone immediately disables biometric unlock, and instead requires your passcode for the next unlock. But none of this has
49.
▲
by
jesseendahl
2y ago
Indeed — I am arguing that 99% of normal everyday folks using passkeys also do not need to understand passkeys.
50.
▲
by
jesseendahl
2y ago
FYI both Google and Apple have an account recovery flow that works even if you lose 100% of your devices.
51.
▲
by
jesseendahl
2y ago
>I _have_ actually lost all my electronic devices in a house fire, so this is from experience. I can't speak to other passkey managers, but both Google and Apple have pretty thorough account recovery flows that work even if you lose
52.
▲
by
jesseendahl
2y ago
>Something as innocent and common as losing a phone could result in complete account lockout. This is the biggest misconception I see repeated about passkeys constantly. Account recovery flows generally do not change at all. Passkeys rep
53.
▲
by
jesseendahl
2y ago
FWIW people don’t actually understand how passwords work either (password hashing etc.), and I am not sure it’s important for most people to understand how passkeys actually work. Also, majority of people reuse the same (extremely weak) pas
54.
▲
by
jesseendahl
2y ago
>I wish I could agree with you but the real world doesn't work this way. The real world does work this way. Businesses make business decisions based on bottom-line impact, and businesses generally push back very strongly against g
55.
▲
by
jesseendahl
2y ago
The amount of one-off work this would take is quite high, so the amount of motivation for a company like Apple to say “No, you can’t legally compel us to to allocate engineering resources to this” is also quite high. My point is that they (
56.
▲
by
jesseendahl
2y ago
Nice seeing you here! :)
57.
▲
by
jesseendahl
2y ago
>Those electronic devices that you mention don't each store the keys in a proprietary format and you can't access them without the vendor's cooperation - i.e. vendor lock in? Passkey portability is being worked on. Here is
58.
▲
by
jesseendahl
2y ago
>Hello, IT, my toddler accidentally dropped my phone in the ocean. I can't log into anything now. It's clear that you are making assumptions without doing any research... Yes you can. See "Recovery security" section o
59.
▲
by
jesseendahl
2y ago
>and people will end up with passkeys that aren't backed up anywhere and get locked out of their accounts. I don't know why this is such a common misconception about passkeys. Account recovery flows are generally entirely unaff
60.
▲
by
jesseendahl
2y ago
>It will likely become more popular to require 2FA for password users in the meantime, as it should. A lot of folks/services/engineers mistakenly think that layering 2FA on top of passwords will help defend against phishing att
More ›