| ▲ | hannasanarion 5 hours ago |
| The point about poor support for 3rd party managers is so frustrating. Because this is correct, that is the obvious solution for the normal user, but passkey implementations somehow do not know how to deal with it. Amazon prompts me to create a passkey everytime I log in, even when I logged in with a passkey, because my passkeys live in Bitwarden rather than my OS or browser. And the confusing mechanism hurts there too: I'm always a little bit afraid that i'm somehow more in danger because I keep them in a vault that's shared on all my devices rather than a TPM, because whenever the protocol is explained the "it can't leave your device" part is highlighted as the main source of the security, except.... mine obviously do leave my device, with the vault, so..... |
|
| ▲ | jasonjayr 4 hours ago | parent | next [-] |
| Yet, the Apple + Google implementations will sync passkeys between your devices. "Securely", of course. (I've seen first hand how Apple implements this, and it seems.... sound) Sites can request hardware-bound tokens, which would block any software based password managers. It's an option in the protocol but one not yet widely utilized. |
| |
| ▲ | cryptoegorophy 4 hours ago | parent | next [-] | | So is there a problem with Apple or no? | | |
| ▲ | jasonjayr an hour ago | parent | next [-] | | I'm not qualified to say yes or no; but I will say that Apple's tends to make design decisions that try to empower the user as much as they can while still being easy to use, and have more or less maintained that position.where as Google, on the other hand, started as "open" and "you can do it all on our platform" to "we're taking away your control and choice little by little, in order to 'protect' you". Oh, and you hear more about Google perma-banning your account for no clear reasons, than Apple... | |
| ▲ | SoftTalker 2 hours ago | parent | prev [-] | | I'd absolutely never trust Google to manage passwords/passkeys for me, with their habit of irrevocably auto-banning accounts. Apple seems... better? But that's today. That could change, and then you'd be screwed. |
| |
| ▲ | XorNot 4 hours ago | parent | prev [-] | | Which is a problem. It should not be in the protocol. And I don't trust Apple and Google not to lock it away from me. I want my own open source manager and if that is attempted I want it to lie about it. | | |
| ▲ | tomjen3 27 minutes ago | parent | next [-] | | I am torn on that. It seems fine for a corporate site to be sure employees are using their company issued tokens to access company data. It does not seem fine for any other site to do this. This may be the only place where it would be good with a software patent: corporate would not mind having to pay 10 usd/user/year, Google would never. | |
| ▲ | drtz 2 hours ago | parent | prev | next [-] | | Lying about it may become impossible in the future when you throw hardware key attestation into the mix. https://developer.android.com/privacy-and-security/security-... | | |
| ▲ | tadfisher 7 minutes ago | parent [-] | | FIDO authenticator attestation is dead for consumer-facing RPs. Apple made the right call and simply refuses to support it outside of MDM environments. |
| |
| ▲ | arcfour 2 hours ago | parent | prev [-] | | Can we try to play nice now and recognize that other people have diverging, but valid, interests from your own? For example, securing things? | | |
| ▲ | dsl 37 minutes ago | parent | next [-] | | Passkeys are not about securing things. The entire value proposition, and the reason big sites are pushing them, is they take the user out of the loop of authentication. You are no longer authenticating the user, you're authenticating the users device. For websites you don't have to worry about cookie theft and dealing with the support load of users needing their accounts reset or dealing with fraud. You can also do some level of attestation to hardware which makes automated account creation more difficult. For the user it offers no additional benefits. You still have something secret that gets presented to a website to login. Password managers solved this problem. But now for some reason you can't log in when you buy a new laptop. | |
| ▲ | lelandbatey 2 hours ago | parent | prev [-] | | It is playing nice to criticize things. It's not just "different priorities", passkeys have intentional trade offs which cause them to be "more secure" but in ways that users do not want because it negatively affects them. The intentional trade off made in the name of "more security" makes them wildly inconvenient and risks causing massive lockout. Like removing all the staircases from people's homes and replacing them with climbing walls all in the name of "security". You can't just diffuse that by say "well we want banks to be more secure, we have different priorities." I am already seeing my "normie" friends getting locked out of accounts due to not understanding passkeys. If they don't have their phone, or it's dead, or it breaks, or is stolen, they just can't access their account anymore. They have no idea how they work or what they're trading off, nor do they understand that they should have prepared for this scenario ahead of time somehow. Upon telling them "yeah you have to use your phone now that you have a passkey" they all universally say "wtf, that's stupid, I never want to have that happen again, I will never use a passkey again." Passkeys should never have been built for general audiences, they are a huge mistake, I hope they cease to be relevant and die due to everyday folks realizing they're inconvenient and the "more secure" gains ain't worth it for the usability nightmares. | | |
| ▲ | jerf an hour ago | parent [-] | | "I am already seeing my "normie" friends getting locked out of accounts due to not understanding passkeys." In a weird way this is good news for us. If people are losing passkeys, getting locked out, and incurring non-trivial support costs as a result to the relevant companies, then there's no way those companies will crank down even harder by requiring hardware keys. As an option, I don't mind it existing for situations like a work environment. Work environments are so much easier because there is a clear line to get my credentials reset, from scratch if necessary, even if I lose everything. The problem is that the consumer authentication case is even harder because it lacks that clear line without also creating a backdoor. So I insist on centralizing my passkeys into a password manager. I have no passkeys outside of my password manager and will continue to reject them. If it's important enough to slap authentication on, it's important enough for me to not lose it because I couldn't choose where to stick it, which is in a basket that I protect very, very carefully. Honestly I just don't see how something like Amazon could ever turn on the "require hardware key" feature without blowing their own foot off, or really any consumer-facing service. Everyone loses keys. To a first approximation nobody is going to buy three keys and correctly manage setting up all of them to work with every service. Even if we magically stipulate that all sites support it and they all have some integrated unified approach so that there's no software-side friction at all to register all three at once everywhere, you just get too many people who stuck all three keys on one keychain, people whose houses burned down, people who so successfully stored both backups "securely" that they have no memory of where they are anymore or how to get them back, an endless parade of lost keys. The consumer as a whole is not capable of managing hardware keys. Given how often my household loses its second car keys for extended periods of time I am not exempting myself from this. My work key lives a much simpler life... it just sits in one place, doing work things. My family would hardly last a month if everyone had to carry around physical keys to log in to things. |
|
|
|
|
|
| ▲ | Gareth321 3 hours ago | parent | prev | next [-] |
| > Amazon prompts me to create a passkey everytime I log in, even when I logged in with a passkey, because my passkeys live in Bitwarden rather than my OS or browser. I haaaaaate this. And every time I'm like, "do I not already have one??" Passkey implementation has been half-assed by everyone. |
|
| ▲ | jeroenhd 4 hours ago | parent | prev [-] |
| > Amazon prompts me to create a passkey everytime I log in, even when I logged in with a passkey, because my passkeys live in Bitwarden rather than my OS or browser. What setup are you using? Because I don't have that problem on Linux + Firefox at all |
| |
| ▲ | hannasanarion 3 hours ago | parent [-] | | Linux, Mac, and Windows (i happen to use all three regularly for work, hobbies, gaming), Firefox + Bitwarden. It's totally possible there's something specific about my situation, or the way it was set up in the first place that enables this, idk, but somebody else replied saying they have the same experience so it's not just me. And even if it was just me, it's still clearly something wrong on the provider's implementation, because it should not be possible for software to sidetrack the user into a passkey enrollment flow, when that user logged in with a passkey to open the current session. | | |
| ▲ | TiredOfLife 32 minutes ago | parent [-] | | I will take a wild guess (based on that you are using firefox) is that you probably have enabled the various don't save cookies, clear sessions on close or other hardened privacy settings that are the source of 99% of problems firefox users encounter, like increased cloudflare captchas . | | |
| ▲ | hannasanarion 7 minutes ago | parent [-] | | Could be! I don't recall turning things like those on, I use firefox for features not privacy, and mostly leave stuff like that at their defaults, which I trust Mozilla + uBlock to filter the invasive trackers while leaving actually useful functionality, but it's possible I fiddled with it years ago and forgot. Some probably kinda strong counterevidence to that though is that this doesn't happen on all sites, only Amazon. I've never been prompted to make a new passkey after passkey login on the 12 other sites that I have passkeys in bitwarden for. |
|
|
|