Your phone may soon replace many of your passwords
krebsonsecurity.com
krebsonsecurity.com
In these cases, technology is creating not solving problems.
Ask yourself this: As great as smartphones are, do you want a future where everyone is required to purchase one, an a cell plan to exist in society, to engage in commerce, enjoy shelter, health care and security?
I would even go so far as to say cash and physical paper should be supported by any business and government department.
It's an even more dire question: do you want a future where you're required to carry that cellphone on your person at all times?
And for the slippery slope: do you want a future where it's legal to arrest people until their phones can be verified? To prevent impersonation, maybe chip people like dogs so that they can be reliably matched to their phones, and make it a crime (maybe "attempted impersonation") to tamper with the chip or to help someone tamper with the chip?
Magisks have stopped providing patches to games that helped to bypass root detection.
But for people thinking about it, its still worth it, with Afwall+ to not have ads in any app, newpipe to have functionality of youtube premium and barinsta to make sure you are not dragged into endless reels recommendations on instagram, its magic.
In this case, there is a clear government and/or corporate motive in increased data mining and social control, so the only thing restricting them is they need to make people accustomed and not consider it too intrusive in non-totalitarian societies.
Things like "contact tracing" or "preventing terrorism" or "think of the children" are among the ways that the powerful actors at the top are convincing the populus that such a measure would be necessary (and beneficial), and the majority of the population does not seem to care much about this to do anything. Hence, it is reasonable to believe that the claimed event (phone being required at some level) is going to happen at some point.
If you run across any of those in the real world, let me know.
But on topic of the questions in this discussion, allow me to offer an unpopular opinion, just because it sounds like an interesting thing to think about.
> As great as smartphones are, do you want a future where everyone is required to purchase one, an a cell plan to exist in society, to engage in commerce, enjoy shelter, health care and security?
Required to purchase one? How about given one instead? In my country, we have eID cards, which can be used for digitally signing documents and can serve as methods of authenticating against a government site - due to legislation, now everyone gets one, much like people got passports. And yet, nobody questions needing these cards or passports, even though technically if you lose yours, you do have to pay for a new one because "it's government property".
Alternatively, if people would still have to purchase one, force the manufacturers to be open about their production costs and profit margins, mandate certain specs of devices not to exceed certain pricing - much like Chromebooks have already taken over education in many places of the world due to their relatively simplistic nature, i don't see why we couldn't have basic spec Android devices in abundance either.
Better yet, protect phones and being able to use them like one would treat the likes of eID cards and similar:
- all phones need security updates for 5-10 years from the manufacturer
- all phones need certain levels of battery life: if a new Nokia 105 can last for a week, i don't see why you couldn't cut down the standby modes of Android phones to do the same
- all phones need their batteries to be replaceable by the user, should they want to do so, no phone can be sold without them as available replacement parts for purchase
- all phones need proper permission setups: a passcode for installing apps, and full control over network requests, similar to NetGuard https://netguard.me/
- all phone OSes need to be open source and open to modification, no more locked bootloaders or other stuff like that (might need a confirmation with the user's code first)
- all phones need their hardware drivers and all documentation pertaining to those be open source
- all phones must support custom apps being written, installed and run by the owner, much like a *nix machine doesn't constrain you
- all phones must support third party app stores, should the user choose to use them, e.g. FOSSHub/Fossdroid
- to fight malicious usage of the above, have a LED indicate whether a custom ROM is or isn't being loaded and have a checksum or something show up during boot with info about any digital signatures of the ROM
Edit: perhaps the term "phone" here should be replaced with something like "gov-compatible-phone" or whatever one could come up with - i don't doubt that dumb phones would still have their uses. Technically, all of the above should have been achievable on something like the Symbian OS as well.Who knows, maybe eventually the majority of phones would once again become more blocky and more of them would be IP-68 certified, or something like that. In my mind, phones should be dependable computing devices, more like a Raspberry Pi/Arduino with a sturdy case in your pocket, rather than dainty status symbols. Think along the lines of these:
- https://www.catphones.com/en-us/
- https://www.ulefone.com/
- https://us.blackview.store/
> It's an even more dire question: do you want a future where you're required to carry that cellphone on your person at all times?I already do, so nothing would change for me. I cannot imagine leaving a phone at home, much like i cannot imagine spending a day without Internet (this is probably a controversial statement, should lend itself to some discussion about how people live nowadays, especially the younger generation). Doing so would be depriving myself not only of a means to communicate and navigate, but also of the ability to look things up, like tutorials, or information about something that i'm interested in. Some might extend those arguments to things like note taking, audio notes included, as well as entertainment. Alternatives exist, of course, but they're rather unwieldy - who wants to drag a notepad, a map and a compass, as well as a voice recorder, maybe a dumb phone or a walkie talkie with them separately?
Edit: probably interesting to compare this with carrying a wallet around - since it has money/bank cards and quite possibly ID and other pieces of information as well. Which could be replaced by a phone. And it's not like you could use it after stealing/robbing it off of someone, since it would be behind a passcode or additional lock mechanisms.
> And for the slippery slope: do you want a future where it's legal to arrest people until their phones can be verified?
I have no illusions about this not being abused if that were ever the case, which kills argumentation in favor of anything like it from the onset. Similarly to how there were various "tests" put in place before voting in US, many of which targeted ethnic minorities. I bet similar excuses could be made about officers "failing" to validate a phone/identity due to "technical issues" and thus depriving people of their freedoms.
That said, i am in favor of means to identify people that actually work for a change - you should not be allowed to start a company on someone's behalf after presenting pieces of information that could easily be found out, like someone's name and any sort of a national identifier. My country basically had the same problem - a national identification number for each person, which many sites still asked for during signup. Due to this value ever leaving the confines of something that holds and uses it as necessary, it's no longer reasonable to rely upon. Consider the eID cards instead - it stores a private key and can only be used to sign things with PIN codes that the user must know/store themselves. The certificates never leave the physical device. We need more of that approach. PII leaking would suddenly become a less harmful thing, because it's not like you could actually do anything with that information.
> To prevent impersonation, maybe chip people like dogs so that they can be reliably matched to their phones, and make it a crime (maybe "attempted impersonation") to tamper with the chip or to help someone tamper with the chip?
Pretty dystopian, admittedly. Some people already do, to enjoy the benefits of RFID chips. Personally, for the most part, i'd prefer to stick with fingerprints for opening biometric locks with phone apps and such acting as alternatives. Then again, if i were writing a dystopian novel (you know, more dystopian than real life, where every action that we take online is catalogued and can be looked up by the powers that be) it'd be curious to explore the benefits and drawbacks of having everyone have chips in them. If the society were ruled by a benevolent AI? Probably less crime and strong application of the law. If the society were ruled by regular people? Probably blackmailing and discrimination like you cannot even imagine.
(note: none of these views are exactly held strongly, just something fun to ramble about)
It is just hard to tell it to a machine. So i am ok to use a token for that.
The trouble for me are the instances, that want to certify, that i am me. I dont need them, but they are there. The middleman, who wants to have a say, to allow or deny.
I have no problem to tell a token, that it is me. I am pretty happy to self-certify myself.
Actually it is - while you provide for yourself and that may be fine, if you have dependents, having daddy be the single source of authentication for everything is pretty damn stupid. You might have accounts for your kids but they need to actually access those accounts.
If you end up in a coma in the hospital, again, having yourself as the single source of authentication for medical purposes is pretty dumb, too.
If you have any group of people dependent upon a thing, having yourself as the single source of authentication is pretty damn stupid. Look up how nuclear missiles are/were protected, if you want a real world tech example.
This thing where people assume they are the only thing in the world so whatever they want is fine for everybody else, that the real fucking stupid thing.
Well, that's the crux of the problem, isn't it? We need a way for you to confirm that it's you and not someone else who has stolen your credentials. Multiple factors of authentication generally work well enough against this. Same for physical devices, be it those eID cards or something like YubiKey or whatever.
> I am pretty happy to self-certify myself.
Well, that's how GPG/PGP works - as long as you give your public key to other people by yourself, be it in person or otherwise. Then you can manage the private certificates for signing stuff yourself however you wish - be it keeping them in a cloud account somewhere (hopefully not), on a local HDD, a USB stick, or printed on a piece of paper where you'd re-type it as necessary (just a silly example).
The problem is that people want a central authority for certain cases, such as interacting with the government - with the appropriate set of software and middleware built around it, so less technically literate people could just put the card in a reader, input a few codes in some official software and be on their way, rather than trying to figure out what the hell a keychain is.
This shit has got to stop. I ran into similar doing a mortgage... They "only accepted the escrow payment through ${RANDOM_APP}." Yea right, y'all can take a check, and they did.
I'm quite sure _all_ the app does is process the payment.:rolleyes: /s No way they collect/sell any info I send through it. Oh, and I'm sure they'll be super upfront whenever their database that my info sits in for eternity with 'admin:admin' protecting it gets popped.
That said, my previous workplace has offered entrance with cellphone, as well as entrance by regular key fob. Over time, I have seen people switch more and more to cellphone method, and either returning the keyfobs or leaving them at home.
Also, a nitpick: you don't necessarily have to purchase a cell plan for your phone. For example the scheme discussed in the article will work over WiFi just fine. And if you are in front of your computer trying to login, the chances are, you have WiFi as well. So while old cellphone is less convenient that keyfob (needs charging, bigger, heavier), it is still pretty usable.
Whenever I hear about "smart" devices as a replacement for something that is safety/security critical (like a lock), the question of what happens when the internet and/or power fails is rarely even considered. Does the lock fail open or closed? Does the door open if there is a fire in the building that damages the internet/power wiring? If it fails open, does that mean someone can bypass the lock by simply cutting the network/power cables outside the building?
There might be reasonable answers to these questions at a large business building that can afford fallback options, but I'm not sure there are good answers for e.g. residential situations.
If the batteries die and you need to get inside, you need to have a physical key or an alternative ingress.
Paula: "...what's that?"
Blank Reg: "It's a book!"
Paula: "Well, what's that?"
Blank Reg: "It's a non-volatile storage medium.
It's very rare. You should have one."
https://www.youtube.com/watch?v=KIWR-b42lU0I had a broker request a switch from a printed card with challenge responses to a cell phone based system. Rejected with prejudice. Never ever will I do banking or trading with a cell phone.
- Go to the supermarket (you can ask a friend with a phone to help you order online)
- Take a taxi (usually, depends on the driver)
- Eat at a restaurant
- (Basically, enter any place of business)
- Go to the hospital
- Travel to another province
- Visit any scenic area or large public park
- Get a Covid test
- Visit your friend’s apartment (usually)
What if your battery dies? Super-reliance on cell phones means this is a solved this problem: it’s trivial to rent a charger anywhere there’s a convenience store.
To be clear, I also see this as an anti-pattern. The presence or absence of an expensive connected device should not restrict what a person can do in meat space. A person not carrying a mobile phone is still a person.
But I don’t see how you actually do contact tracing at scale without this. In the beginning of the pandemic, entering a supermarket meant writing your contact info (including ID number!) on a paper ledger at the entrance. Fuck that.
The person who smashes their phone, on the other hand, would be totally screwed. Ubiquitous surveillance means that cell phone theft is basically not a thing anymore because the thief is pretty much always caught.
No, I don’t. So it’s a good thing you can already use FIDO authentication without a phone using e.g. a Yubikey!
FIDO security keys connect over USB or NFC to authenticate into a computer. There have not been much successes using them for physical access.
No one remembers that, because it didn't happen. It was misreported, but the correction never went as viral.
“[The data centers are] hard to get into… [T]he hardware and routers are designed to be difficult to modify even when you have physical access to them. So it took extra time…”
https://engineering.fb.com/2021/10/05/networking-traffic/out...
I believe there's laws in some states that require cash to be accepted.
That's before discovering we can't be cured after an car crash because our smartphone can't properly identify ourselves with emergency care smart systems, or we can't enter our hose due to an e-ID vulnerability of our connected door.
I kinda liked smartcards for authentication: https://en.wikipedia.org/wiki/Chip_Authentication_Program
This stuff is simple, works offline and is hard to hack.
I understand it still has some shortcomings, such as permitting MITM attacks.
I hope the new FIDO standard gets a variety of implementations, including dumb keys, etc.
If that does, I revert back to a 1990s savage!
This seems like a slippery slope argument. Almost everyone purchasing these products has a phone and service. Cash is expensive to accept. (And makes zero sense for online-only services, which a cash-mandating law incentivises.)
I don't see it as a slippery slope argument because almost everything will eventually move to being online-based, and if "having a phone" becomes the standard for authN, then someone without a phone is excluded from participating in all of those things.
I’d be fine with this, so long as there’s a safety net of some sort to provide cheap/used phones to anyone who now needs one. Computers make lots of things easier, and forcing every business to accommodate the additional complexity of non-electronic access sounds like a bad idea.
That said, I do agree that something should be done about “use this app to open your apartment door” and “use this app to do your laundry”. I think the emphasis should be on interoperability. So you as a business can’t require the use of a specific piece of software, but you can specify a protocol, preferably one that’s already in use.
As for “my phone lost charge at 3am and I got locked out”. I see this as equivalent to “I lost my keys at 3am and got locked out”; unfortunate, but ultimately either your fault or bad luck. Time to call a locksmith (or digital equivalent, a hacker?).
Kinda hard to with a phone that's out of charge...
[*] Obviously after confirming it's really theirs and/or they have the requisite authority. The usual disclaimers apply.
> If you knew that you needed phone charge to enter your apartment I bet you'd bring a spare battery pack when you went out.
I don't even.. what the hell.. UBIK is a fiction, not a desirable lifestyle. Your sentence is the stuff of tech-nightmares.Re-read please out loud :
"If you knew that you needed phone charge to enter your apartment I bet you'd bring a spare battery pack when you went out."
What if you drop the phone and break the screen?
i have yet to find a powerbank that small. though if such a powerbank existed it would actually help because it would not be able to carry more charge than what is needed to unlock the door. it wouldn't be useful for much else.
Is something really more convenient/better if it doesn’t work when you need it most?
Just carry a Tesla Powerwall for your building. You could fit in the space you save by not needing keys!
And to the people who say “but desktops/laptops are already a necessity of life” - yes, and that’s a problem. We need to be actively thinking of ways to roll things back, rather than allowing technology to become more and more integrated into life.
There are two ways this ends up:
The future where everyone has to carry around a black box computing device controlled by its manufacturer and the privileged creators of the apps you’ve been allowed or compelled to install on it. The present state of iPads/iPhones and to a lesser extent Android phones make this future feel incredibly close.
But the future where everyone carries around an incredible communication and calculation tool that acts as an agent for them and expands every individual’s capabilities feels only just slightly out of reach.
The line dividing the two futures is thin and technical in nature. This leaves us with a tricky situation where most people wouldn’t be able to distinguish which they’re headed towards, or even which they’re living in. All I can do is hope that either legal tides go my way and grant users control over their computers (phones) by force, or that somehow tech literacy rises and people demand control.
I do think society needs to take a proactive role in deciding how it wants to interact with technology though. There’s a certain laissez faire, almost defeatist attitude that you see from a lot of the tech crowd, that goes something like “technology will do what it does, and it will change our lives how it sees fit, and we are powerless to stop it.” But if that was the case, we couldn’t have gun control laws, or environmental protection laws, or restrictions on nuclear technology. Technology may continue to develop, but it’s still up to us how we choose to use it.
I too see this attitude from technical people. To be clear: I do not hold it. Like you say, I favor regulation in the vein of gun control, environmental protection, etc. Left alone the tech market will consolidate and rob users of as much power as possible; it is simply the most profitable way of doing business.
To be more specific: I am a proponent of bills like S.2710 - Open App Markets Act (https://www.congress.gov/bill/117th-congress/senate-bill/271...), which among other things requires operating systems to "... allow and provide readily accessible means for users of that operating system to ... install third-party apps or app stores through means other than its app store". Though I would also want additional provisions, like not allowing OSes to reserve special privileges for first-party or blessed third-party apps, eg iOS restricts third-party apps from running JIT code, preventing browser competition on the platform.
The problem is that people want short term gain and don't see the long term loss.
Regulation won't happen for technology, the government doesn't really have an incentive.
They are already spying on anyone so they don't need anything else. Gun control regulations are great to make people more reliant on the government and environmental protection laws are great for charging extra taxes; what would a "less technology" regulation accomplish? Nothing, it would be counterproductive.
The government wants you to ping you every phone cell you go nearby to.
You don't even need cellphones. Just issue people hard to forge documentation and set up checkpoints. It's the difference between a fence and a shock collar.
Your dream seems to be to set up the infrastructure for universal command and control, then expect it to choose to regulate itself.
I don't think I said anything of the sort. Just because something is electronic doesn't mean it's centralized and restrictive. My dream is one where technology is an empowering tool accessible to anyone and I'm all for regulation to prevent monopolies or cartels from imposing self-serving "standards" that block out competitors and force people into walled gardens. You seem mostly concerned about authoritarianism. I propose that so long as users are in control of their computers then computer ownership will have a net-positive impact on general freedom. If users do not control their computers then they will have a net-negative impact on freedom. So the crucial aspect is not whether or not phones/computers become required for daily life, but whether users have control over them.
Even moreso, there are a growing number of stakeholders and even entire business segments, which require locked-down devices for their activities: The entire business of streaming services only works because they get to place an opaque black box in users' homes and can dictate arbitrary rules and constraints for playback.
The entire app ecosystem is only economically viable because the devices make it impossible (iOS) or really inconvenient (Android) to install apps without paying for them. Also, the devices give the user no way to modify the apps, so developers can implement whatever hostile logic they want and users have to put up with it. The ability to do that is a major appeal locked down platforms have for businesses.
(IMO, the imagination of far too many people in the industry is already running wild with all the kinds of crazy rules, restrictions and "business models" you can implement on locked down devices.)
I think we should reverse this trend and install some actual computer literacy in larger parts of society before we make computers mandatory for everyday life - otherwise, the whole thing will end in a dystopia.
No they're not! You need either a desktop or a laptop or a tablet or a smartphone, but you don't need more than one.
I'm okay living in a world where everyone needs access to some type of computer, in the same way that everyone probably needs access to some type of writing utensil. However, people should be able to choose the form factor that lets them live their best life.
Especially when one particular form factor leads to surveillance of your location.
This is not a form factor result, it's a result of a function.
If you want to have internet access without being near internet AP, you have to accept surveillance. This applies equally to phone, or tablet with SIM card, or laptop with external 3G modem.
If you are OK with only accessing internet in specific location, you can turn off cell subsystem in your phone -- this functionality is present in every phone I have seen.
(Same applies to bluetooth, wifi and other ways to track device remotely)
Not to mention that old people is suffering (at least here in Spain) a lot because services push everyone into apps etc.
I cancelled my fathers bank account for this very reason and moved him to a credit union. It was painful but their customer support was so awful that it was worth it.
The last straw was that they told him he couldn't do a money transfer from his local office but he had to use a mobile app. He called me to help him with that. That got me angry.
(I don't love using the word "addictive" here because phones are not chemically addictive, but any other term makes the point less clear.)
That is true in practice, but not true in theory. There are urban WiFi networks that already operate without spying on the users. Nothing prevents mobile networks from being applied in the same way on a technical level.
In fact when you're using a mobile network, you are near an internet AP in the form of a cell tower. Taking 5G NR, you even have to be nearer to it than you would be to your WiFi AP.
Surveillance is not a result of form factor or function, it's a result of social organization.
Some people don't want any technology at all. What happens to them in your future?
This has gone off on a weird tangent; the article is about how a new standard can greatly simplify account passwords, the very hardest and frustrating thing about modern life on the web.
Changing that into "we shouldn't have any rich if we don't want to" is a strange reaction to making tech more accessible. But perhaps if one wants to eliminate tech from people's lives then making tech as bad and painful as possible might be one way to do that; but it seems like a foolish way to pursue that goal.
I am 100% in favor of giving people the option to log in with their phone instead of a password, if they want to. If that's all the article meant, I stand corrected.
But, I got the impression that the people quoted in the article were working to eventually remove passwords as a method of authentication. That's not cool, because it requires users to have a secondary device.
I don't think my impression was entirely unreasonable, because we're already seeing it in the number of websites forcing users to set up two factor authentication. Note that many of these so-called "two-factor" solutions allow the user to reset their password using only their phone (which is what really makes SIM-swapping such a problem), which means your password is effectively optional, but a phone is required.
That's a shame. They must get very cold in the winter without the ability to build a fire.
I grew up without any of this mobile or home computing technology, and I don't see anything essential today that I cannot do without it. It's all about convenience.
Having something you know (a password) is more secure because something in your memory that you don't share can't be taken from you by any means. Passwords aren't perfect (you can be tricked into sharing it, or tortured into giving it up) but there are solutions for being forced to hand over a password, and neither tokens or biometrics solve the problem of people being tricked.
No one can murder you in an alley, and drag your lifeless corpse to an ATM and clean out your bank account because the murderers have your face, and fingerprints, even your cell phone, but not your pin. Good security should always require a secret that you know.
Not having a password would be fine for logging into low risk sites like this website, where at worst someone might get your account banned or post comments under your username, but any site or transaction where the risk is greater should just always require a password.
Not necessarily. The specific implementation being talked about in the article is to use your phone as your FIDO device, and your phone has to be unlocked. So the "something you have" is your phone, and to unlock it, you can either use "something you are" (biometrics via face ID or fingerprint), or you can have a PIN/password on your phone to make it "something you know".
I wouldn't be surprised (and I would hope) that the FIDO app or feature on phones would also come with the ability to restrict it via PIN/password even if your phone unlocks via biometric.
The dream of a life without passwords sounds great, but I don't think FIDO can get us there and if it can't, we have to think about whether or not the extra convenience we can get from FIDO is worth what it would cost us in terms of all the data and control we'd be handing over to 3rd parties.
> Something you have can be easily stolen, and biometrics cannot be kept secret, can be forged, and can't be reset/changed once compromised.
Something you have can easily be stolen as long as someone is able to access it. Someone on the other side of the world is not going to be able to steal your USB token from the comfort of their own bedroom, just as they're unlikely to get your biometrics.
A password exists in your memory, yes, but it also exists in the databases of untold numbers of corporations, each with different levels of security, and at least some of those corporations duplicate copies of those databases across different data centers throughout the world. These databases can essentially be accessed by anyone, anywhere.
I understand what you're saying, but you're forgetting that passwords, by nature, have to exist somewhere other than your head, guarded by someone other than you.
> passwords, by nature, have to exist somewhere other than your head, guarded by someone other than you.
What? That’s simply not true. Passwords are only stored in your head and anywhere you explicitly write them down for safekeeping (like a password manager). Services do not need a copy to validate your password, and should never store one. They only need a salted hash to confirm if the password you input was correct. Such a hash is irreversible without an attacker randomly guessing your password through brute force, which is beyond impractical for any decent password.
True, and better security systems take advantage of that by combing all three. For me to log into work I have to use a password (what I know), use a hardware token (what I have), and be logging in from a location where they'll expect me to be (what I am). All of those things have their flaws, but the odds of someone managing to pull off all three are much less likely.
As the use of biometrics increases we'll see more examples of that data being collected stolen and and shared around the world. Right now, it's not used often enough for criminals to bother passing around scans of your fingerprints, or photos used to spoof facial recognition, but it's bound to happen.
> I understand what you're saying, but you're forgetting that passwords, by nature, have to exist somewhere other than your head, guarded by someone other than you.
As others have said, they shouldn't. We have to expect failures and breeches, which is why it's so important that we have those other two pillars to fall back on when "what we know" fails us.
It feels weird to encounter resistance to FIDO on HN of all places. The biggest complaint about FIDO is that is has rolled out to slowly, not that it is in any way inferior to our horrendously insecure web dozens of accounts secured by a weak human memorizable password, or worse reused passwords.
Passwordless is better because you aren’t storing a phishable password on a server.
Yes, I know uses FIDO under the hood. But the there are very few ELIA5's for FIDO either. One's that start with "It starts with a super secret private key the FIDO device creates and never leaves the device, so no one ever can learn it. In fact, the security and cost effectiveness of the system rests on the fact that it's near impossible to extract that secret from a piece of cheap silicon. The system works because it's possible for the device to prove it knows that one thing only it could know, without ever revelling what the secret is. ..." From there it goes on to explain the techniques use to ensure despite using the same secret for every server, no two servers (from different domains) will know the same key was used to log into each. And on it goes with mutal auth, and immunity to MITM attacks and on and on. Now I think about it, maybe 5 is a little too young.
Then people say disturbing things about Passkey, like https://www.hanko.io/blog/on-passkeys : "Passkeys = (synced) WebAuthn credentials". Hang on. Is that saying this super secret key never escaped the FIDO token is now synced???
And were is this super secret key stored on the phone? Storing it in a hardware token that receive a backdoor'ed firmware upgrade is one thing. Storing it in a device that accepts firmware upgrades, when governments such as Australia's have passed laws allowing them to compel manufacturers to backdoor firmware upgrades is quite another. But storing that secret on an Android or iOS phone, that are so complex they have proved impossible to make them secure, which we know because many can still be root'ed today - surely that's insanity?
But who knows maybe that's all been thought of and mitigated. Given Google's involvement, that almost seems likely. But you could never learn if it was true from dumbed down to the point of uselessness "hey! we've invented (ye another) replacement for passwords" press releases I've seen so far.
I also usually carry my passport as a backup though that probably won't work if I need to rent car--and on that particular trip it was a last minute overnighter so I didn't throw in my backup documents and cards folder. It took me about half an hour to convince the hotel to let me check in.
In general, I hate traveling with things that you really can't afford to lose and can only mitigate against loss to some degree.
I basically need to port this number to a cheaper carrier and cover the cost…forever
Although I agree with you, it is not realistic.
Do you think kids who are 3 right now will feel the same when they are your age?
Reminds me of the US General who, in WW II, insisted cavalry still had a place in warfare. Can’t remember his name.
anyway the point is not to go back to soldiers riding horses, but to not reduce the authentication options, because it also reduces security.
After all we still use keys to unlock doors and not our phones (because it would be stupid)
"In 1945 Herr wrote that conversion of cavalry to armor was a mistake, an act of "robbing Peter to pay Paul": expansion of armor was necessary, but not at the expense of horse units."
...
"even in 1942 he still struggled for the horse, requesting Marshall for "an immediate increase in horse cavalry."
...
"He enforced a formal policy that any increase in mechanized forces must be preceded by a proportional increase in horse cavalry; as a result the 7th Cavalry Brigade remained the only mechanized unit until 1940. Later, he had to admit the rising power of armor, but was just as unwilling to dismount his troops.
After the outbreak of World War II Herr followed the European campaigns through attaché reports that reinforced his belief in superiority of cavalry tactics. His chief of staff Willis D. Crittenberger pre-screened these reports and jotted "cavalry mission" in the margins to attract Herr's attention.[16] Herr's own interpretation of the intelligence was biased in favor of the horse. He believed that the Wehrmacht relied on horses because of German operational doctrine when, in fact, it was a purely economic decision.[6] He wrote that other Western European armies dismissed the horse because of shrinking horse and forage stocks; the American situation, according to Herr was more akin to Poland or the Soviet Union, which still kept sizable horse formations.[15] He assessed blitzkrieg as a "typical cavalry mission" and suggested expanding the 7th Cavalry Brigade along German panzer division standards, under full Cavalry control.[17] The proposal, delivered at the War College in September 1939, was bundled with the demand that new armored units should be formed from scratch rather than converted from horse troops.
In the first half of 1940 Herr embraced the concept of "horse-mechanized formations" and called for expansion of cavalry brigades into divisions. He alienated George Marshall by insisting that mechanization should be an expansion of existing cavalry troops, rather than their replacement.[19] He publicly rallied for more horse units through Cavalry Journal publications,[15] and brought further tension inside his troops by asking each cavalry officer to choose his side: either for horse cavalry, or for mechanization. According to Bruce Palmer Jr., the request forced officers of all grades to "cut their throats professionally": they had to bet their careers on obsolete war technology, or risk immediate repercussions from their Chief."
https://en.wikipedia.org/wiki/John_Knowles_Herr#Chief_of_Cav...
That purpose wasn't doing pike-and-lance charges into panzer lines. Just like most motorized units, WWI and WWII cavalry didn't fight from horseback - it would use horses to get to where they were going to fight, and dismount to fight.
The Eastern Front had a lot of terrain that was not conductive to wheeled travel.
Cavalry is also far more cost-efficient at hunting down partisans, and terrorizing civilians. It doesn't need petrol, you can just steal horsefeed directly from the people you are occupying.
Cavalry still had a huge role to play in WW2. You didn't ride them into battle (you didn't do that in WW1 either), but they were used for transport. Germany and Russia used 6 million of them.[1]
It was Maj Gen John Herr:
1 point by TedDoesntTalk 7 minutes ago | root | parent | next | edit | delete [–]
It was Maj Gen John Herr:
"In 1945 Herr wrote that conversion of cavalry to armor was a mistake, an act of "robbing Peter to pay Paul": expansion of armor was necessary, but not at the expense of horse units."
https://en.wikipedia.org/wiki/John_Knowles_Herr#Chief_of_Cav...
My neighbour had dropped her phone in some water, it was a Samsung S21, and the screen was messed up. The moment you tried to activate the screen, lines would appear across it. It was unusable.
Thankfully she had a spare phone available to use, but she needed to get a bunch of things setup on there (Google Mail, NHS for the Covid pass as she was travelling abroad).
She ran into an issue authenticating her Google Mail account - the password. She didn't remember it, so we tried the "Forgot Password" user flow.
For reasons unknown, the user flow insisted on sending a notification to her Samsung S21, even though we had swapped the SIM card from that phone into the new phone, and we had no way to swipe the notification on the S21 due to the screen being broke.
Somehow, we managed to trigger sending a text message with a code, and thankfully she got access to her Gmail account and other items.
But it was not a simple process, and there's no way your everyday person would have a clue how to deal with such cases (it confounded me and I'm a developer!), so I hope that someone with UX and QA chops is able to cater for scenarios like someone's phone screen being busted and knows how to provide alternative options that your everyday folk can get to grips with.
You do notice the irony, right?
How ironic would that be?
And those big tech companies are free to lock you out from your account for no reason with no recourse.
I am imagining this working like OTPs that are generated on phones. The actual standard will be open and the implementations do not require a specific platform or any kind of "account", but most people will run it on their phone with Android or IOS because it's handy for them.
I also don't think it's going to require running on a phone, just like OTPs. I can generate OTPs for 2FA purposes on my desktop system running Linux and it works great!
If it does end up working like that, I think it's a great idea.
I too prefer offline-first tools, but the market doesn't, and people are trained to sign up with an email account and password so for the masses "this is just how it is".
I don't want to be a pessimist, but examples of user respecting systems are mainly commonplace in certain corners of the highly technical FLOSS world, it's certainly not the experience of the average person.
TOTP being a notable exception.
Did you see Demolition Man? What do you think about the beginning?
As such I tend to prefer cloneable credentials. Everything that is unique (cellphone, ...) would imply that access credentials could be stolen (as in, actually stolen, not copied), which could imply the threat of violence to succeed.
To clarify, this wasn't meant as an attempt at a "tough guy" acting. If someone tries to coerce my phone out of me irl by threats of violence, they will get the phone. But this being done irl at least has much easier path to being able to trace the criminal, actually prosecute them, and to minimize the damage to my accounts.
Not even mentioning that it is much more risky for them to attempt, given it would have to be done somewhere around a public place with other people and law enforcement around. Meanwhile, some guy from an eastern european country cloning my access credentials to compromise my accounts will almost certainly never be traced, and 100% won't get prosecuted (and that's on top of me not being able to be aware of that happening until after the fact).
As security person I prefer much more old school options, like that I can still use single use passwords with my bank. But I fear that this will go away one day...
At the current price, it's hard to recommend them to people I know. Even to those who still suffer in a world of post-it notes, reused passwords, and unclear knowledge of which device they own has saved what. The sort who live by the "forgot your password?" link. I've recommended password managers to them, but the recomendee is usually put off by the hassle of installing one and creating an account. Oddly enough, this hassle comes off as more surmountable if it's part of making a physical object work properly. There's something about the sunk cost of having already spent money, the natural value associated with a physical object, and the sense that they've already begun the process that makes the hurdle feel smaller.
I do wish it was more widely supported.
I still keep printed one-time recovery codes locked up and hidden to not be completely surrendered to my phone, but i don't really like them since they can be copied without notice, only comfort is that usage of them will trigger notification, yubikeys feel like a better middle ground.
"Passkeys" appears to be another name for FIDO Multi-Device.
FIDO previously took the position that the private keys should never leave your hardware token (or phone). Because that's the most secure position.
That position appears to be out the window. They provide a rather longish obscure FAQ entry explaining, yeah, we said your private key shouldn't leave your token (or phone), but times are a' changing.
From the FIDO multi-device FAQ: https://fidoalliance.org/faqs/#multi-device-fido-credentials
From the FIDO Alliance website: "FIDO Alliance has previously stated that user authentication credentials never leave the device. Has that changed?"
"FIDO Alliance’s mission is to help reduce the world’s over-reliance on passwords. It is true that some relying parties (and their users) get value out of hardware-bound credentials, and the FIDO standards still support this type of deployment.
But for many relying parties, the fact that FIDO’s approach required users to enroll each new device presents some customer usability challenges, and also limits their ability to replace passwords (as passwords frequently serve as a means to verify new authenticator enrollment).
As such, replacing the password with a challenge-response protocol based on asymmetric cryptography is a huge step forward in security, even if those cryptographic keys aren’t bound to hardware – as this helps RPs thwart the constant threats of phishing, credential stuffing and other remote attacks."
Isn't that kind of against the whole "FIDO" thing that I've been personally trying to deploy company wide as much as possible. That you have in your person some actual physical object, what ever it is: YubiKey, SmartCard, a laptop with a TPM chip, a phone.
And your personal private key inside that specific physical object is your "password" that only you can access by PIN or biometric identification.
If you lose access to that physical object, you lose access to the services also. That's the whole point! You can replace it, but then you go through the whole "enrollment" process again. That's another very important point also.
Sounds like a requirement from governments or LEOs. They need access to your private keys and it's much simpler if it's not bound to a physical object anymore. From now on it's just a plain text file on some server, when you backup your phone to the cloud.
You must have zero trust in a device where 3rd parties have full access to change whatever they want at any time and for any reason without your knowledge or consent. That's not happening for the linux server in my closet. It's probably happening for the windows 10 system in the living room, and it's absolutely the case for the phone next to me.
Cell phones are not private and they aren't secure and that makes them the worst kind of device you could insist on people using to replace their passwords.
I'm sure you're thinking something along the lines of "Android has an SELinux sandbox that prompts for permissions." You can run this on normal desktop Linux too though (I forget the command, it's a python script in the SELinux tools (or so) repo.) No one bothers because the distro repos are relatively free of malware and installing non-free software requires a small amount of understanding. This is, of course, considered "bad UX" for non-free software but that is in practice where most of the malware comes from on other OSes. (On Linux most f it comes from sloppy language specific package managers with a free-for-all mentality like node.js or PyPi but no amount of OS design can fix stupid devs without making their work impossible.)
You running npm install can potentially delete everything in your home directory, but a buggy application (even if opensource and made with good intention) can be exploited by evil data just as well. Just because your, say, PDF reader is open source it can be used to exploit your computer with an evil pdf file. So yes, linux desktops are orders of magnitude less safe than either Android or ios.
A phone is one way, and it's pretty good. A Yubikey is another good way. A third way is a printout of secure backup codes, kept with your important papers.
At that point you're pretty safe. (Although, if your phone and Yubikey are both lost while traveling, you might not be able to get in until you get home.)
Some services like Github and Google actually support this, but it's not that common yet.
The other lockout risk is access denied due to a policy violation (which could be a false positive) and adding authentication schemes won't help there; you need backups.
So it's great that this FIDO initiative lets people use their phones, but what's it going to take to make sure everyone has multiple, reasonably secure ways to get in?
Most people tend to automatically unlock their phones without a second thought.
My phone screen broke (turned black), so I wasn't able to log in to my business bank account, not even through the web portal on my laptop. Web login on the laptop requires confirmation via the phone app, but with a black screen I couldn't figure out how to confirm. (It also needs the phone camera to read a QR code, so I guess it would have been a problem if the screen worked but the camera stopped working.)
I phoned the bank and said, surely there must be another way to authenticate in these situations. Or perhaps I could just use bank services over the phone?
Their answer was no, the only option to access any bank services was to purchase another smartphone, move my SIM over, call the bank to activate the new device, and then video myself reading some text. Then I would be able to use the new phone to login to my account on the web on my laptop.
As a result I wasn't able to access the bank account for several days to make payments, until my new phone arrived.
Then similar fault occurred on the new phone a few weeks later (identical model, bought used in a hurry, see above). This time I had just caught Covid so I wasn't going to rush out to local shops for a third phone.
During all this, the original phone was acting as a Google 2FA token for a client Google work account (unrelated to the bank account). Logging in to that Google account required confirmation on the phone, and it had to do something Googley, it didn't accept third party 2FA apps. I never did figure out how to to transfer that token over, but that Google account isn't needed any more so I no longer care.
> Bellovin and others say one potentially tricky scenario in this new passwordless authentication scheme is what happens when someone loses their mobile device, or their phone breaks and they can’t recall their iCloud password.
and Google ignores the authentication question and just assumes a new, charged phone follows every human being wherever they go (and presumably the same goes without saying for backup codes):
> Google says that even if you lose your phone, “your passkeys will securely sync to your new phone from cloud backup, allowing you to pick up right where your old device left off.”
Just implement login via email/sms and that's about it.
Now when it comes to this "phone" authentication, I'm not sure that I like this idea. I have good control over my phone number. I have good control over my domain and email (that's not true for most users, but they have the option). But making all my digital life depending on Apple or Google: that I don't like.
Just let Password Managers do their job easily.
There's an easy way to make passwords usable only by people with password managers: instead of letting the user set a password, generate it for them.
So I really hope Google et. al. will offer some kind of email address cloaking like Apple do with their private relay stuff. Knowing Google, they sure as heck won't, though.
An application/site can optionally request the "email" scope during OpenID Connect sign-in, but if it is not requested (only the "openid" scope instead) then the provider must not return an email address in the ID token, or an OAuth access token which is authorized for an API method which returns the user's email address (OpenID Connect Core 1.0 section 5.4 - "Requesting Claims using Scope Values").
Google implement this (https://developers.google.com/identity/protocols/oauth2/open...), by returning only a unique numeric user ID in the returned id_token. I haven't checked other OpenID Connect providers.
I didn't know the details about different scopes and had always assumed the sites would obtain at least the name and email address, because all I ever saw was the prompt "To continue, Google will share your name, email address, language preference, and profile picture with <site>."
I don't want a vendor-specific or identity-provider specific integration like Google using Chrome and Android for MFA with Google accounts. I mean could my Android or iOS phone connect to a laptop via bluetooth or USB and act as a hardware key just as if I used a yubikey or titan key, and be visible to Firefox or any other software that knows how to talk to U2F or other smartcards to enroll with new websites and identity providers that have nothing to do with Google nor Apple accounts?
The mechanism is already available on chrome and android if you select the option to add an android phone - iPhones and iPads have a developer preview feature flag you can enable to work with this as well, and to have a Mac display a similar option when using the platform level support (aka Safari or certain native apps).
I wish for a completely local mechanism where a phone with a hardware security module could act like a token via completely local communication with the browser, both for enrollment and later login with any relying parties. For general users, I do like the idea of being able to backup/restore the token seeds to allow replacement of hardware without manually re-enrolling redundant keys with all relying parties.
But, I don't see why the cloud-assist should interpose between the user agent and the security device, nor why a cloud-assist should interpose between the user agent and the relying party. How is this cloud-assist different than the other vendors like Duo and Okta, interposed in enterprise client login attempts and organizing MFA options which can include authenticator apps on phones?
I feel like platform vendor lock-in has been gratuitously introduced into this plan. Couldn't a token backup/restore service be offered to users without interposing anything new service between the phone-as-token, the user agent communicating with the token, and the relying party service? Or, couldn't the token standards be amended with some sort of web-of-trust concept to allow a token to announce additional peer/backup token keys during enrollment. so that one enrollment task can simultaneously enroll the present token and offline backup token(s) with the same relying party?
While it's good to be suspicious of something so critical like authentication, particularly coming from a big tech alliance, what about the positives? Consider the number one issue for most people is still phishing, and under this system there's no password to be phished anymore. Also consider that this system is likely using Bluetooth for the PC to phone challenge/response, avoiding current issues with passwordless MFA apps (i.e. Microsoft's right now) where the user could be still be social engineered to confirm a logon by a remote attacker. The Google smart lock app works like this today using BT and FIDO, so we know it works.
Plus the core tech is from what I can tell, just tried and tested asymmetric crypto, with the private key on your phone. The public key is on registered on every web service you want to use it on. Second factor is the phone PIN/Biometric. Sure, Apple will let you store the key in iCloud, but we aren't talking standard iCloud backup here, this is iCloud Keychain where it's protected by your device passwcode which Apple does not know. And if none of this is for you, just use a Yubikey, it's the same tech. And if you do choose to use it, while you are at it, add several Yubikeys as backups to every service, that's standard practice and how it works now.
Relying parties (aka online services using FIDO protocols) have a lot of freedom to define exactly how restrictive they want to be by making choices about which devices they accept. Through choosing which devices they accept they can choose to require any combination of token, PIN, biometric, and password.
This, in my view, is the problem with FIDO.
They shouldn't be able to make that choice.
For anything consumer facing (vs employee/contractor facing), the expectation is that a relying party site accepts everything, or supports a set with a clear industry-defined set of limitations (e.g. must have gone through certification and achieved a certain level such that they meet our security regulations).
The set of limitations which you can set during an authentication request are pretty minimal, on purpose - so you will typically have more prompts and more user errors if you decide to try and limit consumer choice.
Other than that, the expectation is that you do not block end users if they e.g. are using one vendor or the other. You may still ask them to perform additional authentication steps, but the goal is that people do not get conflicting requirements across relying parties that leads them to have to carry a key ring of different vendor USB authenticators in order to be able to do their business.
I still use a flip phone and don't want apps. I want a phone only.
Everything I have read about this approach seems to imply that passwords are still used, only perhaps not as often.
For instance, there's this quote from the article:
"Bellovin and others say one potentially tricky scenario in this new passwordless authentication scheme is what happens when someone loses their mobile device, or their phone breaks and they can’t recall their iCloud password."
As long as there’s a command-line app that I can use instead of my phone (which I will never do), I’m good with this!
I’d be willing to help develop such an app.
- https://github.com/google/OpenSK <- DIY solution
The issue with any FOSS solution is that FIDO requires an attestation private key, which must be shared between a batch of at least 100,000 security keys. Using a DIY or cli app solution (application running on the host) will likely mean you'll be generating that private key yourself, this makes you identifiable across registrations.
Some sites (Cloudflare) may reject the use of attestation keys which are not found on the Fido Alliance Metadata Service. This precludes the use of any DIY solution.
https://fidoalliance.org/metadata/
https://support.cloudflare.com/hc/en-us/articles/44068890480...
Next year: EU government force big tech phone OS manufacturers to enable identity portability
FIDO2 is an open standard, you can use security keys or TPMs or whatever you want.
Quite recently, my bank site was having a fit and I couldn't log in, with only cryptic errors. The first line of help didn't understand a thing and wrote back to IT to find out more. Apparently if you don't hand type / PW manager autotype your password, you are a hacker now; they are actively hostile towards PW managers. Great yet incomprehensible way to push people towards bad passwords. This was at a small bank that uses third party software, also used at another small bank I use. So it will have propagated to who knows where overnight.
Now we want to get rid of passwords altogether, so phishing is a simple as [remotely] watching someone distracted unlocking their phone in the coffee shop, and there is a good chance you can get them to swipe right when they should go left. Idiocracy.
That said, I agree with everyone's fears and frustrations with the actual real world circumstances around phones. I do not trust my phone and I don't really trust the most popular projects to make phones more secure. I suppose you could keep a separate device whose only exposure to networks is to verify access over a limited protocol - but ofc due to the baseband and other requirements you would still be vulnerable. Very frustrating.
This is Web Authentication/FIDO 2. We've had security keys like Yubikeys to do this for years.
This is about committing to have computing devices also have the functionality of these security keys built in, to synchronize those credentials within a platform ecosystem, and to support cross-platform usage such as an android phone letting you into a site on a windows desktop browser.
The hope is that much higher user availability will cause much higher site adoption.
> At its core, a model of identity would be to create a keypair for each account and require that key sign each login request.
That is exactly how it works. Web Authentication declares a javascript API for site access, and the request and signed authentication response formats/processing.
> That said, I agree with everyone's fears and frustrations with the actual real world circumstances around phones. I do not trust my phone and I don't really trust the most popular projects to make phones more secure.
There is about eight years of hardware in the market you can use rather than your phone. In addition to security-opinionated end-users, it is expected that some portion of enterprises and governments will require a separate hardware key for employee/contractor access - and may even require specifically the one that their IT hands to the person.
Yes - doesn't the article suggest that this would use FIDO? "According to the FIDO Alliance, users will be able to sign in to websites through the same action that they take multiple times each day to unlock their devices"
I was pointing out that this model - FIDO or some other version - does make sense. Even if the drawbacks of forcing people to use it on phones are obvious.
> There is about eight years of hardware in the market you can use rather than your phone.
If there are dedicated hardware solutions that's great! It seemed from the article like they were requiring phones - which was the source of my concern.
Account recovery is a pretty well-known space as well. If the person does not have any authentication mechanisms left, you can send an email link or go through identity proofing depending on your security requirements.
Right now my bank requires my phone to get a 2fa code for anything important. I can only have a single device at a time, if I lose my phone, I can of course reset it if I'm in the country and go to a branch. Of course with Covid that was difficult when I last lost my phone, so I had to download a form sign it and fax it to be able to set up my 2fa on my new phone. It took 2 weeks before I could access my bank account.
IMHO based on current policies, it is more likely that they will have one device on your account, like a combined USB and NFC hardware authenticator, that you can request from them and becomes expected for higher security interactions like large money transfers.
Our fallback on passphrase held off-line, for emergency use only.
My method of choice would rather have been what is established now for 2FA with time-based one-time passwords (TOTP). Here the attacker can't initiate the auth flow from the outside.
In the end this likely only leads to training people to automatically approve anything as every little piece of software on their machines needs approval once a day or more often at worst...
I use keepassxc, so I'm not reusing passwords. I'm currently forced to use less secure SMS OTPs for some sites because they won't allow me to use TOTP in keepassxc.
Now I'm expected to tie everything to one device that could be easily lost, stolen, or damaged, and back up my secure key to some random cloud store just in case that happens?? Cloud storage in control of companies that at a whim could lock you out.
I don't think so.
Here are some threats that are prevented by FIDO and not by TOTP:
- An attacker compromises DNS infrastructure and makes a web page that looks 100% identical to the one you're expecting, hosted on the same URL. They wait for you to log in and use the TOTP you send to authenticate to the real site's servers as you. FIDO prevents this threat (phishing via MITM) entirely, TOTP provides little protection. KeepassXC if you don't use your clipboard to paste TOTPs provides limited protection but the matching is DNS-based, not cryptographic like FIDO is.
- A hacker compromises your computer while it's on and keepassxc is unlocked. With keepassxc TOTPs, they now have your TOTP secret and can impersonate you at any point in the future. With FIDO on a separate non-key-extractable token, they haven't gained anything. Sites can verify that the FIDO authenticator you're using disallows key extraction as part of the protocol, and can even blacklist known-compromised second factors without your intervention.
- A hacker is able to guess exactly 1,000,000 passwords in one minute. They have stolen your password but don't have your TOTP secret. They guess the TOTP using their ability within 999,999 attempts, since that's all TOTP with its default six-digit generator provides. With FIDO, the secret is 128 bits, and they'd be guessing for thousands of years.
I'm not saying FIDO/U2F is "better" than TOTP. They're just different. But you, as a security-conscious user, do get concrete advantages (in the form of protection against particular threats) using a FIDO credential over using TOTP.
Additionally, FIDO doesn't requiring storing a secret key per site; TOTP does.
Can you be potentially tracked across the internet with your single public key in the FIDO system. If my understanding is correct you have a private key no one knows and you provide the public key to authenticate yourself. If you only have one private key and one public key surely your open yourself up to tracking/privacy related stuff? I might be wrong due to my ignorance.
Fortunately it looks like security keys such as https://cloud.google.com/titan-security-key can be used instead.
I don't check email on my phone, unless I absolutely have to. I don't have any social media on it except for signal. I don't open the web browser. My phone is mostly used for maps, reading books, and video chatting.
I look forward to a world where people genuinely view social apps and related addictive software the way we do harmful drugs. Something to be avoided, and if you can't avoid them, there should be pressure to seek help.
I agree with your basic point though. Smartphones are the default for doing more and more things. And when traveling, I try to have reasonably backups for maps, itineraries, etc. But I'm hardly religious about it and my phone breaking or getting lost/stolen when traveling would be a major hassle.
But I don't want my phone to serve as my "root" authority. I'd rather have a separate pair of fobs used to seed all my other devices. Then put one of those fobs somewhere safe.
When the USA finally gets smart and implements postal banking, I'd love for the USPS to offer safe boxes. Maybe even other fob related services. Kinda like a notary public, but for credentials.
--
Late 90s, shortly after W3C's P3 failed to catch on, a buddy and me cobbled together a SSO POC for browsers. Our catchy name was "Credendity", a failed portnameau evoking credentials and identity. One of our core motivators was "faceted identity", negotiated per account, to only share partial PII, to thwart data aggregators. So naive; big data deanon always wins.
Our POC was just turrible. Embarrassing. Ditto every SSO implementations I've used since, whether standards-based, vendor, or bespoke. In hindsight, it's too bad our sense of integrity and esthetics prompted us to abandon our effort.
I think it would be more annoying to call a friend to confirm an authentication on their phone than it is to write down a text password.
The app had both location and Bluetooth tracking, when they uploaded your Bluetooth data they do they download everything then do the filtering on the survey.
Then can say your data is stored on your device, we only access it for a specific location, but they do the filtering on the server side..
The app had a QR code using a auth protocol called relating to the future of digital identity, I forget the name. DAT by memory.
The token has your plain text name, DOB for anyone to see, ask for, require on entry.
Last time I checked 60% of people still have it installed collecting Bluetooth data of other people with that app.
The point is your phone is going to replace more than your passwords.
I can think of a few downsides: 1) in the US at least, being compelled to provide biometric identification for all accounts, 2) single hardware device point of failure, on top of that being the most often lost, stolen or damaged hardware device. And all the benefits I can see with it are already served by password managers and TOTP, which the manufacturers can just ship by default if they want to, the tools are there already. And I can back it up in whatever way I choose, securely.
So what's the upside?
Granted, there are some groups which use Google Docs or such to coordinate, so I still have to have a Google account, but this is somewhat optional. And Google Play is pretty nice if you have a cellphone -- but on the older Android tablets I keep them account-less and use F-droid/random APKs from the web instead.
A much concerning thing IMHO is a Facebook requirement -- I am missing a number of events when I tell people I don't use Facebook. Hopefully it will change one day, but I am not holding my breath.
(And re the original article, you only need Google/Apple account if you want to use cloud sync. I am not quite sure how the system will work, but I suspect that with Android, you might either have alternative clouds (like Samsung's cloud), or may be able to use your own service, or sync via wired cable to PC)
Probably things like needing a (google/apple) smartphone for mandated vaccine passports / coming digital ID's, digital currency etc.
Specifically, FIDO binds credentials to a "Relying Party ID". For WebAuthn that's effectively the DNS name of your server, which is why it's protected from phishing.
The W3C publishes the entire WebAuthn spec. so if you care you can read it and see how it works.
If you're using FIDO in some other context (e.g. smartphone apps can do this via Android or iOS APIs) your RPID is based on that context, so e.g. the real Hacker News Android phone app (if such a thing existed) can't be impersonated by a dozen third party knock-off "Hack-a-News" and "News for Hackers" apps.
(from memory this will need much bigger storage in the secure enclaves - thousands of accounts is quite feasible)
Oh wait, example.com sends me a encrypted key, that I decrypt and then use? That sounds ... odd.
I mean, why not just keep the same encrypted data on my local phone ? The attack surface seems much smaller.
https://fidoalliance.org/specs/fido-u2f-v1.2-ps-20170411/fid...
has a clear description in the "Allowing for Inexpensive U2F Devices" section.
For webauthn, they don't use key handle terminology anymore, but the same fuctionality is provided by the "Credential ID":
> SSH auth + Git commit/tag signing using a key stored [on your device]
> turns your [...] device into a WebAuthn/U2F Authenticator
The additional options discussed in this article are are to:
1. use a platform feature to have the TPM or Secure Enclave in the device itself work as an authenticator as an alternative to a hardware dongle. 2. synchronize across devices within an ecosystem (e.g. all Apple devices) using a mechanism on top of the platform account (aka AppleID + iCloud Keychain). 3. allow a phone to be used to authenticate to a desktop, even across ecosystems.
The previous way would be to use a hardware key like a yubikey. If your platform supports #1, most sites _should_ support user management of a set of appropriate authentication mechanisms, and may even prompt on a windows desktop "would you like to use Windows Hello to sign in more quickly in the future?"
A version of Windows has support for #2 might let you instead have that credential be added to every windows desktop or laptop on your account.
Due to the variability of Linux, my suspicion is that each browser will fill some of the gaps there as well.
It is so much less humiliating to put my hand on the sensor than when I have to touch my head to the cash register each time I want to pay for something.
My phone number is no longer up grab.
Grab something else.
The announcement is specifically about FIDO2 adding support for two additional things:
1) The ability to share FIDO credentials between multiple devices. Previously, it was implied and alluded to, but never stated outright, that credentials would be bound to an authenticator, like a MacBook's Secure Enclave, which FIDO calls a platform authentictor, or a Yubikey, which FIDO calls a roaming authenticator. Now there's explicit support for multi-device credentials. Apple recently added this feature in what it calls "Passkeys", a name that other vendors (but not FIDO) seem to be adopting too. This is net positive. Losing a device that was bound to a credential meant that the credential was lost forever. Now, as long as the credential resides in at least one device the user has access to, there's no recovery flow needed. Note that the vendor providing syncing services for these credentials does not have access to them. See https://support.apple.com/guide/security/secure-keychain-syn... for an example implementation
2) Expanded ability and commitment from vendors to use a roaming authenticator over Bluetooth Low Energy (this is already in the standard). And in particular, the ability to use a phone's platform authenticator as a roaming authenticator in a different device. This does not mean, as TFA implies, that you'll need a phone to sign in to services. Rather, it means that for services that allow or require FIDO credentials to sign in, a phone is now an additional option to present those credentials. You can still use a Yubikey, TouchID or any other way you interact with your existing TPM.
I understand that people are concerned about new authentication standards backed by big corporations who have a history of locking users out of their platforms and services, but the current state of secure login is dire. FIDO2 is an incredibly well designed set of protocols to prevent phishing, credential reuse, and several common causes for account compromise. It was clearly designed with that in mind, at the expense of usability. These are notable and incremental improvements to enhance the usability of a standard that is head and shoulders better than existing alternatives like passwords, but still has some ways to go in terms of functionality. Personally, I'm very excited about FIDO and WebAuthn, and some of the improvements I'd like to see in the coming months are:
a) The ability to share passkeys across vendors, including the ability to implement a "sync fabric" as some folks in the WebAuthn working group have called it, so it's interoperable beyond the major vendors. b) For these vendors to strengthen their own log in experience. Apple only allows their own TOTP implementation and SMS fallback to authenticate to iCloud. I'd like to use WebAuthn exclusively here, so I could back up access to my now-precious Keychain that holds all my FIDO credentials with a YubiKey. c) A better story about backing up security keys. Implementing a) would give us that. Devices that can be initialized with a given seed like some common hardware crypto wallets would give us that, albeit not without introducing changes to the threat model -- you have to store the seed and input it somehow -- and https://www.yubico.com/blog/yubico-proposes-webauthn-protoco... would give us that as well. d) A better story for usernameless. The current methodology to have a user initiate a usernameless login and picking the right credential is a UX mess, and I don't believe I have actually seen it implemented in a production site. I'd love to be shown an example!