Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
sebk
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
sebk
4y ago
I'm with you here and have been parroting this in just about every Webauthn thread on HN, except maybe with the exception that I think it's password manager vendors who are more interested -- several of them have joined the FIDO a
32.
▲
by
sebk
4y ago
Apple has pretty good security whitepapers about how it does end-to-end encryption for Keychain items like this. If you're more broadly concerned about Apple not honoring those, having (un)intentional vulnerabilities, or them having th
33.
▲
by
sebk
4y ago
Prof. Daniel Abadi talks about the two meanings of consistency in this blogpost: https://dbmsmusings.blogspot.com/2019/07/overview-of-consist... I'd argue that in your second case, there's no consistency
34.
▲
by
sebk
4y ago
The blogpost is light on details but they’re most likely using WebAuthn prf which was designed with this use case in mind: https://w3c.github.io/webauthn/#prf-extension , with the idea that it’s backed by a sync fabric
35.
▲
by
sebk
4y ago
My concern is that without it, people might default to a software implementation that's interoperable. While significantly better than passwords, it's still worse than hardware-backed keys. > Can’t solve for everything in one g
36.
▲
by
sebk
4y ago
> But also the pro is that if you lose access to your sync fabric X (security breach, account closure), you can still use sync fabric Y. It's like backup fido2 tokens. This is forced. I'd rather decide to do that myself dependi
37.
▲
by
sebk
4y ago
>They don't even support Webaunth. Apple iCloud supports WebAuthn as of two months ago: https://www.apple.com/newsroom/2022/12/apple-advances-user-s... Google has supported WebAuthn for quite a while
38.
▲
by
sebk
4y ago
> This is by design. I know, and I don't like being forced to make this tradeoff. This protects the hardware vendors, and inconveniences me. It might leave everyone else unprotected, if the alternative ends up being using virtual au
39.
▲
by
sebk
4y ago
For _using_ WebAuthn, Linux without a TPM has the option of using a hardware key like a Yubikey or Nitrokey, or a virtual authenticator like what 1Password proposes here: https://www.future.1password.com/passkeys/ For
40.
▲
by
sebk
4y ago
The blogpost manages to not explain what they actually intend to do, but I assume it means WebAuthn PRF. The general idea is nice and it works, but it's hindered by the fact that sync fabrics aren't interoperable or pluggable. Let
41.
▲
by
sebk
4y ago
It's not a direct image, which is the specific question, and I don't know if you're including NASA in "most" but NASA disagrees as well, per their article. So do Wikipedia editors: https://en.wikipedia.or
42.
▲
by
sebk
4y ago
For what it's worth, ChatGPT is also wrong: https://i.imgur.com/CsQyEc2.png . The correct answer is https://exoplanets.nasa.gov/resources/300/2m1207b-first-imag... as techsupporter posted in a
43.
▲
by
sebk
4y ago
Unfortunately there are at least two more major caveats: 1. Capability control only works for JavaScript ( https://www.graalvm.org/latest/reference-manual/embed-langua... ) 2. The documentation says in no uncertain
44.
▲
by
sebk
4y ago
This was my understanding too, but I believe the wording in their (Apple's) whitepaper is unclear now. See this comment chain on HN: https://news.ycombinator.com/item?id=33900004 , with the relevant bit being If two-f
45.
▲
by
sebk
4y ago
Other than more convenient UX, with Bitwarden or any other password manager you can just generate an equivalently entropic "secret key" that you store in a file and that you manually concatenate with the password when unlocking yo
46.
▲
by
sebk
4y ago
The Dlang docs make a similar point in the Garbage Collection section, here: https://dlang.org/spec/garbage.html
47.
▲
by
sebk
4y ago
I'm not sure that the crypto used is the weakest link, but even then, I would very much like to see a user-configurable memory-hard KDF, authenticated AES, and FIDO2 hmac-secret support. All of which should be relatively tablestakes fo
48.
▲
by
sebk
4y ago
Your idea is not very different from this proposed spec also defined by Yubico: https://github.com/Yubico/webauthn-recovery-extension In my opinion, along with pluggable Passkey providers, this is the missing piece for
49.
▲
by
sebk
4y ago
YubiKeys can't have copies of themselves, that's a big portion of their selling point. As far as I know and strictily in FIDO, there is no solution here. The closest that Yubico has is this draft: https://github.com
50.
▲
by
sebk
4y ago
This concern is valid depending on your threat model, but improvements are quickly coming to this area. Apple, Microsoft, and Google have announced that they will allow syncing credentials between devices in their ecosystem (fully end-to-en
51.
▲
by
sebk
4y ago
Thank you for the summary. It's very helpful for people like me whose only experience with compilers is a class in college. I'm slightly confused by these two statements together: This is a method of ensuring that future builds d
52.
▲
by
sebk
4y ago
Thank you for the links. In my case, I have two-factor _and_ a recovery key set up. The Account Recovery icon on Apple ID says "Your device passcodes can be used to recover end-to-end encrypted data. If you forget your passcodes, you&#
53.
▲
by
sebk
4y ago
The iCloud recovery key is a 28-character string, not your iPhone PIN: https://support.apple.com/en-us/HT208072 . There is no situation that I can think of where a device PIN is of any use off-device.
54.
▲
by
sebk
4y ago
I'm not sure what service you're using, so this might or might not apply to you: Consider that some password managers use MFA to allow you to connect to their online service that will download a synced, encrypted copy of your pass
55.
▲
by
sebk
4y ago
Thank you for having an honest FAQ, especially about keys not being backed by hardware and its implications. Some competitors implementing a comparable mechanism have been very quiet about it and have severely undermined my trust in them. H
56.
▲
by
sebk
4y ago
They could implement a virtual authenticator, emulating a TPM or security key and running entirely in software. Of course, this nullifies several advantages of FIDO. Alternatively, and likely a much better option longer term, they'll n
57.
▲
by
sebk
4y ago
Attestation information requires that at least 100k security devices share the same attestation key, so device information can't really be used to track a given user. The proposed devicePubKey extension that helps RPs reason about whic
58.
▲
by
sebk
4y ago
FIDO credentials have some baked in assumptions about the cryptographic properties they were generated with, that an RP can use to reason about credential strength, and are designed so that unwrapped private keys are not handled outside of
59.
▲
by
sebk
4y ago
Similarly, I have a Greasemonkey userscript to remove the readonly attribute for the password input form so my password manager works: for (const e of document.getElementsByClassName("pwordinput")) { e.removeAttribute(&#x
60.
▲
by
sebk
4y ago
There's nothing special RPs have to do in order to support Passkeys. It's just WebAuthn that happens to be synced. If the site supports WebAuthn it already supports Passkeys (As long as they're not doing significantly less co
More ›