On-device WebAuthn and what makes it hard to do well
mjg59.dreamwidth.org
mjg59.dreamwidth.org
On a practical level I think this attitude has held security back for years.
WebAuthn's killer feature is that it stops most phishing cold. Not OAuth phishing, not more exotic approaches that involve e.g. DNS hijacking, but nearly all of what's out there today. And it doesn't need TPMs or attestation or user presence tests for that. Those features are for malware.
Shielding the keys from malware is all well and good, but it's a fine line between stealing the keys used to authenticate and stealing the authenticated session or access token after the user logs in. You can stop the malware from authenticating, but not from accessing. Is this really worth the loss in usability?
Hopefully passkeys get good enough to finally take WebAuthn mainstream, because it's not likely to happen with hardware. I still have Yubikeys for critical production systems, but a couple years ago I started using a virtual USB driver (or HID gadget on Linux) to do the rest through client code. It's all software, the keys are backed up, and I can easily move between computers.
If they'd just started with software half the business world would've adopted this stuff by now.
1. Windows: https://github.com/frankmorgner/vsmartcard/tree/master/virtu..., which is a fix-up of the older https://www.codeproject.com/Articles/134010/An-UMDF-Driver-f..., and https://github.com/Watfaq/SoftU2F-Win/tree/master/SoftU2FDri.... Note that neither of these actually implement CTAP2.
2. Linux: There's plenty to refer to on HID gadgets, but https://blog.hansenpartnership.com/webauthn-in-linux-with-a-... and the code at https://git.kernel.org/pub/scm/linux/kernel/git/jejb/fido2-c... were my entrypoint and cover the whole idea of WebAuthn in software.
3. Mac: I ended up not implementing a Mac version, but GitHub themselves used to support a CTAP1/U2F software authenticator, now archived at https://github.com/github/SoftU2F. I was going to work from that.
For the service I looked at different software "devices" interfacing with these kinds of drivers (or just the browser directly in Firefox's case).
1. Generic NIST SP 800-73 PIV: https://github.com/CCob/PIVert. Very limited scope, pentest tool with no extraneous features. It uses the BixVReader driver.
2. U2F: Just the corresponding driver repos I think.
3. CTAP2: Firefox Soft Token code, https://github.com/ellerh/softfido, https://github.com/bulwarkid/virtual-fido (the one you found).
I don't trust the software implementations and I don't use 'trusted' software like Windows or Mac. Linux and BSD keep getting forgotten. Firefox for Linux doesn't even support CTAP from FIDO2 (meaning you can use your yubikey only for MFA not passwordless).
https://mjg59.dreamwidth.org/62175.html https://news.ycombinator.com/item?id=33810984
If I sign up for a service I can never sign into it unless I have that device with me. For some ultra secure things that's a good thing, for day to day shopping, etc, it's so inflexible as to be useless.
Again what happens when the device breaks or is lost or stolen?
How do I migrate my credentials from Mac to android to windows to Linux to iOS?
I'll be sticking with my password manager until I'm unable to use it.
For consumers: it's considered good form for these services to allow multiple webauthn devices tied to an account. So you keep a yubikey somewhere to get back in, on the off chance that you simultaneously lose access to your phone and your computer.
For corporate accounts: an admin provisions a new device for you and gives it to you.
Since this technology is in a large part a response to consumers utilising passwords badly I don't see this as a valid assumption.
Let's ignore that some consumers won't have their own devices and therefore won't be able to use any service with this in place. I know people who do online banking at the library because they have no choice.
My current set up with my password manager offers way more flexibility. And the only downside it that the password gets transmitted, encrypted, but it leaves my device.
Hopefully keepass[xc] role out support too.
I wouldn't put my password vault in the cloud and neither will I put any passkeys either.
https://news.ycombinator.com/item?id=33948929
Another option is to use hardware keys running open source user-controlled software, like the Tomu: