How to add biometric authentication to your webpage
stackoverflow.blog
stackoverflow.blog
Curious, what happens if people lose their arm or eye? How do you recover the account? Let me guess, email? Lol. So all this and you're still a phish away from pwnage!
Having to have tons of Yubikeys adds so much friction.
I think it can indeed scale, people use USB drives a lot, think of it as another peripheral similar to mouse or keyboard. It is especially more attractive as a single factor auth when you go passwordless. It is a similar security model as physical keys and the cost is only ~1x more.
Biometric auth isn’t “I send a picture of my face over the network and that auths me” but a device a prioiri trusted by the service or the user takes a reading and releases a key.
Nobody says that “your hardware configuration is just a username” when taking about TPM security but when it’s wetware suddenly it’s a huge issue.
https://amp.theguardian.com/technology/2014/dec/30/hacker-fa...
7 years ago too.
On iOS you can enroll additional fingers to touchid if you know the passcode.
>So all this and you're still a phish away from pwnage!
Not possible with 2uf.
https://www.theregister.com/2005/04/04/fingerprint_merc_chop...
> "Hard to steal"
Depends on the situation and attack surface. I would not want to use it to unlock my car or access my bank account. The Chaos Computer Club demonstrated that in 2008 by publishing the fingerprint of a German minister[0]. Fooling fingerprint scanners is entirely possible [1]. It _may_ suit your application, do not blindly believe this article though.
> without adding any friction
That's not my experience with Apple devices. Sometimes it works and only adds about three seconds. Other times you wipe and re-position your fingers a second or even third time.
[0] https://www.heise.de/security/meldung/CCC-publiziert-die-Fin...
[1] https://arstechnica.com/gadgets/2013/09/chaos-computer-club-...
It is indeed hard to steal WebAuthn keys out of modern secure mobile devices. It's not talking about stealing biometric data.
Though to me this is also an inaccuracy in the article which would better be clarified.
https://news.ycombinator.com/item?id=33633773
So I reiterate here:
"This challenge will be returned in the response and you must verify they are the same."
Ummm, "MUST"? (emphasis is mine).
Too bad that we cannot somehow make this requirement word a "SHALL" as this leg of the "ceremony" can easily be overridden by a malicious JavaScript function(s).
Unless these JavaScript scripts AND its references HTML pages are also:
- under the protection of nonce hash values,
- complex CSP properly scoped,
- older WebAuthn protocol made client-side rejectable,
- its server-supplied JavaScript logic gets pre-tested in its client browsers prior to the ceremony,
- CTAP1 properly rejected, AND
- the browser is also deemed provably secured from an nonce override.
Awful lot of conditions such that it reminds me of the children's game of "Jenga" (a tower of stacked rectangular blocks) ... reaching for the sky.
Surely, our large pool of esteemed and well-trained web ninjas can handle this seemingly "nuclear-safety" checklist with relative ease. /s
More must be done to streamline this before web integrity gets properly and safely restored in these days and ages. reply
Shit. Disregard all that I said. I forgot about the malicious client-side nonce-disabling malware. That's a doable thing.
Here's more about the challenges from https://www.w3.org/TR/webauthn-2/#sctn-cryptographic-challen... :
As a cryptographic protocol, Web Authentication is dependent upon randomized challenges to avoid replay attacks. Therefore, the values of both PublicKeyCredentialCreationOptions.challenge and PublicKeyCredentialRequestOptions.challenge MUST be randomly generated by Relying Parties in an environment they trust (e.g., on the server-side), and the returned challenge value in the client’s response MUST match what was generated. This SHOULD be done in a fashion that does not rely upon a client’s behavior, e.g., the Relying Party SHOULD store the challenge temporarily until the operation is complete. Tolerating a mismatch will compromise the security of the protocol."Prompting for a username and password is so 2005. Today, you can just prompt for a fingerprint."
True, you can... but should you?
I would never ever give away biometric data unless forced to (e.g. passport)
It could also be implemented in a way where it's behind a password instead of biometrics. Yubikey and the likes already use this method.
Or they can take the fingers with them.
So I would just sync the keys locally or via some browser-extension and then on each device be responsible to provide the "secret" (e.g. my face or fingerprint) in a readily way to unlock said key, yes?
See apple passkey page: https://support.apple.com/en-in/HT213305
Well, to be fair, a lot of people probably do support the idea that their own country checks the documents of people who enter and exit through their borders, and are maybe glad that the country they are visiting is similarly careful, but in principle, someone might want to emigrate to Antarctica, and never return to their country of birth, and for them it would be an unnecessary burden to have to apply for a passport.
I made the deliberate decision to travel and see different cultures.
But to be frank, I was more or less forced, because I was traveling with my parents ;-)
A mandatory ID card says that every citizen has to prove their validity to the state, and it is the state which can grant or revoke that validity, rather than the state being the servant of the citizens.
There have surely been enough examples by now of successful countries not requiring mandatory ID cards, and examples of ID cards being abused by governments for discriminatory policies, that I don't know why they have such support.
http://www.preventgenocide.org/prevent/removing-facilitating...
https://privacyinternational.org/long-read/4472/exclusion-de...
https://bc.ctvnews.ca/99-of-indian-status-card-holders-have-...
Thug B: "No need to, just cut of their finger!"
Thug A: "But which one?"
Thug B: "Let's take all of them!"
But if my fingers are my password, they could either force me to unlock right now and have the problem that it locks again after some time of inactivity (depending on the impl on the other side), or take away the fingers (instead of a password) with them and be able to unlock as often as they want (and the fingers not rot) :)
I'd rather them take some knowledge and not harm me, or rather: make the harming part less likely.
tldr; my point isn't about keeping the account save, but about the potential risk of injuries to my body.
> Please don't post shallow dismissals, especially of other people's work. A good critical comment teaches us something.
> Due to the abstraction of the WebAuthn API, you can’t be certain the user is authenticating via a biometric. You can take certain steps to encourage it, but you can’t force it.
> However, biometric authentication tied to popular operating systems are a quite prevalent form of WebAuthn-compatible hardware, so it is likely that if you encourage your users to set up WebAuthn logins, they’ll be using biometrics. You can also encourage this via the messaging on your website.
Look man, I wake up around 3 in the morning most days. I browse in the dark pretty frequently. I've never set up face ID, but even if I had, I'm not going to go turn a light on to try and log into your website. And yeah, in 2022, you might find this hard to believe, but I don't even a web cam on any of my desktops. It sure is nice to still be able to use the web.
I also walk very frequently, play Pokemon Go quite a bit, and lift weights daily usually with chalk. As a result, my fingertips are often pretty burned and dry, and it is often not possible to take a fingerprint reading at all. I do have touch ID turned on for all my laptops, but it works maybe 50% of the time.
Just offer options. Whether you think it's less secure or not, my keyboard is almost never going to stop working.
Face ID also works a lot more reliably that Touch ID.
How vigorously are you playing Pokemon that it's rubbing off your fingerprints?
Or is "playing Pokémon" a euphemism for some other activity?