| |
| ▲ | iamnothere 4 hours ago | parent | next [-] | | On my keychain in a USB hardware token. With a couple of backup tokens in fire safes. | | |
| ▲ | rcxdude 4 hours ago | parent | next [-] | | If you're using a USB hardware token your knowledge of it is at least an order of magnitude better than the median user's. I know where my passkeys are stored, I don't know where my family member's passkeys are stored and neither do they. The same is true for most of my otherwise fairly technical co-workers. | | |
| ▲ | iamnothere 3 hours ago | parent | next [-] | | There needs to be industry and government leadership on this to gradually require hardware token usage, for at least critical financial and government applications. Right now everyone is putting their energy behind passkeys, but those are much harder to understand than a physical token. I don’t know any non-technical people who understand how passkeys are normally tied to the device (or the manufacturer-provided cloud account in some cases), how to set them up on a second device, why you might want to do that, etc. And many technical people still don’t get it either! | |
| ▲ | faust201 3 hours ago | parent | prev [-] | | Then that family member does not worry like you do worry. The main point is assuming one can have a proper security for Google account - everything else becomes easy. The fearmongering of losing google account should stop. Yes, some people lose it. There are a larger proportion losing/getting pwned by repeat use. For the majority - just pressing the fingerprint to access an account (like amazon/eBay) via passkey is great. Fairly technical co-workers - I used to suggest them to buy USB security key few years ago. Now that same fairly technical some how has at least 2 devices with them - so they just skipped the USB security key need - and just use Google (in Android) or iPhone in Apple ecosystem. Everything just works. Yes, there will be a poor soul that may lost everything with only one device. | | |
| ▲ | Aerroon 2 hours ago | parent | next [-] | | >Then that family member does not worry like you do worry. Until they lose access to that account and then it becomes my problem to solve. | | |
| ▲ | faust201 25 minutes ago | parent [-] | | This is a different issue. Not everyone has a data engineer - know it all as a family member. And you need to accept it works for millions. |
| |
| ▲ | iamnothere 3 hours ago | parent | prev [-] | | People keep their entire lives in cloud accounts these days. Their passwords, financial history, copies of important documents, baby photos, etc. Losing access to it is incredibly disruptive and may result in unrecoverable losses. It shouldn’t be this way, but it is. | | |
| ▲ | faust201 23 minutes ago | parent [-] | | At the same time, I know so many people believing DIY raspberrypi based NAS and losing lots of data (thankfully they had cloud backups). Not everyone has access to server grade hardware. |
|
|
| |
| ▲ | UltraSane 3 hours ago | parent | prev [-] | | The biggest issue with passkeys is that since most USB tokens that support them don't allow syncing the private key to a backup device you have to enroll ALL of them to every site that supports passkeys. This is annoying but it makes storing backups in secure offsite locations impractical. | | |
| ▲ | iamnothere 2 hours ago | parent | next [-] | | This is a fair criticism and needs work, I have some short thoughts on it here: https://news.ycombinator.com/item?id=49755217 | |
| ▲ | EvanAnderson 2 hours ago | parent | prev [-] | | It's beyond annoying. It's creating needless toil that no "normies" will ever actually do. I'd love a hardware sold in multi-packs and "born" at the factory with identical internal device key encryption keys (DKEK). I'd love, even more, if a token just allowed you to "commission" new ones w/ a user-specified DKEK on first use. I'd use one token as a daily driver and store the other(s) in safe location(s), empty of my personal key material. (Or, if I can just commission a new token w/ my DKEK, store a printed copy of my DKEK in a safe location.) Give the token a mechanism to "type" a backup of its internal state, encrypted with the DKEK, as a USB HID keyboard. That gives me an easy way to backup the token each time I enroll a new website. If I lose my daily-driver token I just pull a spare from storage, import my last backup, and I'm up and running. That would kick ass. No "You just need to buy two tokens and enroll them in every website" bullshit. | | |
| ▲ | iamnothere an hour ago | parent [-] | | Maybe each token also needs a second key, with the DKEK used for authentication and the second used only for revocation. The main reason not to reuse the DKEK is so a lost key can be easily decommissioned. You would need some out of band way to collect and save your key IDs and publish revocations. I’m not sure if this would work from a security theoretic perspective, need to think about how the request is signed and transmitted so someone can’t fake a key being “alive” when it’s really “dead”. I do agree this would be incredibly useful if it can be made to work. | | |
| ▲ | EvanAnderson an hour ago | parent [-] | | I haven't used a FIDO2 token other than playing around with it on a Yubikey. There, at least, I have to have the PIN to unlock the Yubikey before I can use the FIDO2 credentials (if I'm remembering correctly). Are there hardware token implementations where mere possession of the token is all that's necessary to use the passkeys stored on it? That's incredibly stupid, and should have been disallowed by the standard, if that's the case. | | |
| ▲ | iamnothere an hour ago | parent [-] | | Yes, the PIN is optional even on Yubikeys, although I think individual providers can require it. Ideally a strong PIN should be used but people may just reuse their ATM PIN, birthday, etc. |
|
|
|
|
| |
| ▲ | qmmmur 28 minutes ago | parent | prev | next [-] | | in 1password | |
| ▲ | wolvoleo 5 hours ago | parent | prev [-] | | In a secure vault on your phone | | |
| ▲ | malfist 4 hours ago | parent | next [-] | | How do I use it on my desktop or laptop then? What if I switch browsers on my phone? What if I get a new phone? What if I change from android to iOS or visa versa? What if I need to log into the site on my Wii U's browser? | | |
| ▲ | Johnny555 2 hours ago | parent | next [-] | | >How do I use it on my desktop or laptop then >What if I switch browsers on my phone >What if I get a new phone You can let Apple sync your passkeys between devices using iCloud Keychain. Then you can create a passkey on one device and have it available on all of your devices. Google also syncs passkeys to the cloud and lets you use them on Windows (with Chrome) >What if I change from android to iOS or visa versa I resolve this by storing most of my passkeys in my password manager. I still store the "important" ones (like online banking) in my phone so a password manager breach doesn't make me lose my money. >What if I need to log into the site on my Wii U's browser? Passkeys were designed to let you have more than one, so if you have a device that doesn't let you use your password manager, then just set up another passkey. | | |
| ▲ | makeitdouble 9 minutes ago | parent | next [-] | | Nothing wrong with your answer itself, but having to be Apple or Google is a PITA. These account are ultra critical already and you will want maximum security to access them. This means if you go on a trip somewhere you absolutely need two devices. If you kill your phone and want to buy another one ASAP, you wont be able to do anything with the new device until you can convince the platform it's you. With passkeys you're just SOL. Imagining if you needed a phone to get back from your trip - e.g. etickets, auth needed etc. - it becomes a nightmare scenario. A third party manager makes it easier, but it's a lot less usable that the first party ones. Reasonable people make different life choice, having to constantly think about backup strategies whenever I'm away from home would be so stress inducing to me. | |
| ▲ | malfist 2 hours ago | parent | prev [-] | | Apple can sync to my wii u? | | |
| |
| ▲ | faust201 3 hours ago | parent | prev [-] | | as long as you have one working device all will be OK. Either you scan the QR code shown by the website. or if you did login to Chrome with google account then desktop or laptop will just sign you -friction less. Same with iCloud account. If you browser vendor has implemented passkey then all good. Most things are built for the majority users. Most don't change. Most don't debate browser wars in hn. Life is like that. For Wii etc. You just scan the QR code shown in the TV interface. all just works. Yes, if you want 100% privacy and will do only your own dovecot server then it is not for you. |
| |
| ▲ | mystifyingpoi 5 hours ago | parent | prev | next [-] | | So if I drop my phone to the toilet, I will forever lose access to everything? Since the vault is on my phone. | | |
| ▲ | faust201 3 hours ago | parent [-] | | A majority have more than one phone. Or at least they can get a new SIM card and sign into the iCloud account. Then all passkeys are synced from cloud. Yes, if you are edward snowden then not for you. For rest of us - it is useful | | |
| ▲ | recursive 2 hours ago | parent | next [-] | | This is crazy. I have one phone and zero iCloud. I don't think I'm that unusual. | | |
| ▲ | faust201 21 minutes ago | parent [-] | | You are exaggerating. If the loss or lockdown is so bad then many would have stopped using any of icloud or google equivalent. People are able to depend on it. People are able to repair and use phones even when it falls into abyss. |
| |
| ▲ | chrystalkey 2 hours ago | parent | prev | next [-] | | Idk how much money you must be having, but all of my bubbles only ever go with one device | | |
| ▲ | faust201 19 minutes ago | parent [-] | | this is ridiculous. I don't even have a bubble device. Run lineageos in a decent 2020 device moto G32 for €100. Yes, you can afford to host everything locally. Not everyone can. |
| |
| ▲ | caryme 3 hours ago | parent | prev [-] | | A majority have more than one phone? |
|
| |
| ▲ | rcxdude 5 hours ago | parent | prev | next [-] | | Not always. And which vault? There can be multiple on a given device. This isn't some hypothetical 'mollify the user's worries' question, this is an important practical question of what do they need to worry about losing access to. Trust me when I say that most users I have talked to have absolutely no idea about this, and usually only find out when they've already lost them. | |
| ▲ | cpburns2009 2 hours ago | parent | prev [-] | | Great, what happens if I lose my phone? |
|
|
| |
| ▲ | vntok 4 hours ago | parent [-] | | It depends. Are you part of the 99.99999% users of one of iOS+Apple or Androidlike+Google/Tencent or HarmonyOS+Huawei? If that's the case, you don't need to as the key is automagically saved by your OS' platform and synced with your new device. Otherwise, you're such an extreme outlier that you probably either know what you're doing or can find out by yourself, right? | | |
| ▲ | flerchin an hour ago | parent | next [-] | | How can it be saved and synced without credentials? I'm in that overwhelming majority, but I don't grok how I can recover the account when my phone is lost/stolen/damaged. The answer appears to be, use another device that was already logged in? | |
| ▲ | dspillett 3 hours ago | parent | prev | next [-] | | > … users of one of … Google …? If that's the case, you don't need to as the key is automagically saved by your OS' platform and synced with your new device. This absolutely does not encourage confidence in me. We all know how easy it can be to get locked out of a Google account and have no way of getting back in unless you have enough clout to make a huge noise online so a human there pays attention instead of you being stuck in the 'ol support-bot-run-around loop. It doesn't happen often when you consider how many users there actually are out there, but the potential inconvenience is high enough that “fairly rare in the grand scheme of things” is still enough to be reason enough to be wary. | |
| ▲ | an hour ago | parent | prev | next [-] | | [deleted] | |
| ▲ | faust201 3 hours ago | parent | prev [-] | | The point is people like this usually are arguing as they hate adopting new tech. And they hate FAANG. No way to convince them. |
|
|