Passkeys have a marketing problem where no one is able to describe simply what it is without having to use technical jargon. There's also the problem where each OS tries too hard in pushing this to the face of end-user
Imagine a password, but it a) types itself for you and b) detects when it's being sent to an impostor site and blocks them from seeing itself, so it can't be phished.
Cool, where are they stored? (I know the answer: 'it depends', and that's the big problem with their usability: most users haven't a clue what the answer is and most tech support can't answer that question straightforwardly because it depends on some decisions the user probably didn't even realise they made).
The biggest issue with passkeys is that since most USB tokens that support them don't allow syncing the private key to a backup device you have to enroll ALL of them to every site that supports passkeys. This is annoying but it makes storing backups in secure offsite locations impractical.
It's beyond annoying. It's creating needless toil that no "normies" will ever actually do.
I'd love a hardware sold in multi-packs and "born" at the factory with identical internal device key encryption keys (DKEK). I'd love, even more, if a token just allowed you to "commission" new ones w/ a user-specified DKEK on first use.
I'd use one token as a daily driver and store the other(s) in safe location(s), empty of my personal key material. (Or, if I can just commission a new token w/ my DKEK, store a printed copy of my DKEK in a safe location.)
Give the token a mechanism to "type" a backup of its internal state, encrypted with the DKEK, as a USB HID keyboard. That gives me an easy way to backup the token each time I enroll a new website.
If I lose my daily-driver token I just pull a spare from storage, import my last backup, and I'm up and running.
That would kick ass. No "You just need to buy two tokens and enroll them in every website" bullshit.
I haven't used a FIDO2 token other than playing around with it on a Yubikey. There, at least, I have to have the PIN to unlock the Yubikey before I can use the FIDO2 credentials (if I'm remembering correctly).
Are there hardware token implementations where mere possession of the token is all that's necessary to use the passkeys stored on it? That's incredibly stupid, and should have been disallowed by the standard, if that's the case.
That is how almost all standard FIDO2 tokens work. You just have to press the capacitive sensor when prompted. You can get fancier biometric tokens that require a fingerprint.
All this hullabaloo taking away user freedom to export keys and backup tokens but physical possession is all that's necessary to use it by default.
kenrick95 · · focus · HN ↗
cfiggers · · focus · HN ↗
Tada, passkeys.
rcxdude · · focus · HN ↗
iamnothere · · focus · HN ↗
UltraSane · · focus · HN ↗
EvanAnderson · · focus · HN ↗
I'd love a hardware sold in multi-packs and "born" at the factory with identical internal device key encryption keys (DKEK). I'd love, even more, if a token just allowed you to "commission" new ones w/ a user-specified DKEK on first use.
I'd use one token as a daily driver and store the other(s) in safe location(s), empty of my personal key material. (Or, if I can just commission a new token w/ my DKEK, store a printed copy of my DKEK in a safe location.)
Give the token a mechanism to "type" a backup of its internal state, encrypted with the DKEK, as a USB HID keyboard. That gives me an easy way to backup the token each time I enroll a new website.
If I lose my daily-driver token I just pull a spare from storage, import my last backup, and I'm up and running.
That would kick ass. No "You just need to buy two tokens and enroll them in every website" bullshit.
iamnothere · · focus · HN ↗
EvanAnderson · · focus · HN ↗
Are there hardware token implementations where mere possession of the token is all that's necessary to use the passkeys stored on it? That's incredibly stupid, and should have been disallowed by the standard, if that's the case.
UltraSane · · focus · HN ↗
EvanAnderson · · focus · HN ↗
All this hullabaloo taking away user freedom to export keys and backup tokens but physical possession is all that's necessary to use it by default.
We are a ship of fools, the IT industry.