I feel like I'm an old grouch who wants things to stay the same... And that's kinda the case :-)
I feel like I'm an old grouch who wants things to stay the same... And that's kinda the case :-)
Once at my first home, where I climbed in through the bathroom window (this was a PITA - it was some 12 feet off the ground and just barely big enough to get through.
Once at my current home, where I just used the porch door that I literally never lock.
----
And I'm actually pretty good about not losing my things. But over a 20 year span, I would have been permanently locked out of digital accounts 4 times if you want to play this game.
For me, that's a complete non-starter. So recovery flows will HAVE to exist. At that point, we're right back to where we are now, where I'm much less worried that someone is going to crack the salt+hash of my password, and I'm much more worried that someone will call customer support and pretend to be me.
But all of these digital techniques also allow multiple keys and / or key recovery.
[citation needed]
And that locks them out of most email providers and online services, especially if their only source of internet access is a public library that "looks like a robot" because a lot of people use it simultaneously.
I'm pretty skeptical that passkeys are going to yield much benefit. Websites will still have to maintain a "recovery" flow for the reason above and this is already the weakest link a lot of the time.
Under this model, new authentication pretty much should always leaves a paper trail, while passkey login, could be more like the "remember me" cookie from the old days.
Sorry for the tangent, but has anyone ever heard anything about cross-device cookie synchronization?
Nothing is stopping you from generating a private key from a password that you have in your head, and using that to authenticate to every site.
Obviously, if that password gets stolen, the thief can get into any of your accounts, but that's a choice you have to make. WebAuthn doesn't mandate a specific way of storing credentials.
Nope. If I don't need my car keys I don't carry my keys. I do tend to carry a small wallet and my phone but also carrying a separate hardware token routinely would actually be a pain for me.
Perhaps most people do. There's also quite a few people that lose those keys - perhaps through neglect or being stupid, perhaps through an accident or getting mugged.
Note that of those unfortunate people that lose their keys, very, very few of them lose their house and everything in it as well - there's many paths to normally quick recovery that would need to be replicated digitally.
What's the issue here, people can't export backups of the passkeys?
Quite the opposite. You can, and are always advised to, have a second key as backup that you can keep in a secure location. So in the same way as you don't lose your home if you lose your home's keys, you don't lose your digital access if you have a backup passkey. There is a slight difference between the two scenarios as in the case of your home, you wouldn't lose it regardless of whether you have a backup key or not. But since you can easily have a backup passkey the difference is very small.
I can, and do, backup and safeguard my KeePass database in ways many and various. I have a fairly robust system to backup "traditional stuff" - including sync to my local NAS, a monthly off-site exchange of external drives with my best friend, and a cloud sync.
I have NO clue how to backup my whatever this is keystore or database or whatever, in a way that I'll feel confident I can seamlessly resume my life. It all seems to be embedded in some cloudy or device-internal ethereal opaque invisible places that make my life super easy when they work and when I do predictable things, and make my life devastating when they don't work or I do unpredictable things. I'm literally and genuinely and actually scared of these changes - not for when they work well, which is apparently magical; but when they don't work well or I fall through system cracks through some unknown change or issue.
I don't know why you would want to though. Since (1) passkeys will rarely be a required nonreissuable credential, and (2) losing access to iCloud Keychain is extremely improbable. For many users, showing ID to a phone store clerk is sufficient for iCloud recovery. For others, it's using their laptop, a recovery key, or a recovery contact.
Can you walk me through how that works? I don't know how Verizon, for instance, could get me that access. Or did you mean at an Apple store or something?
https://support.apple.com/guide/security/secure-icloud-keych...
https://support.apple.com/en-us/HT213305
Basically: For some subset of iCloud Keychain users, SMS is used in combination with the lost device's passcode (or a user-chosen password) to recover the keychain. Since the device is lost, you re-issue the phone number with a carrier. I think 2FA or ADP may require another device or a recovery key, but my memory is hazy on this.
Really? That sounds awful. So now everything is passwordless and tied to a single database that can be stolen?
I thought the whole point of passkey was to tie the login to a TPM, Secure Enclave, HSM, etc. managed key because that means the private key is in hardened, tamper proof storage that simply signs challenges.
passkeys.com:
> When a user sets up a passkey, a key is generated and synchronized to the cloud. When the user connects from another device in the same ecosystem, it will use the same key.
WebAuthn supports verified attestations for hardware-backed authenticators. Passkeys seem to be designed for normal consumers, who worry about losing authenticator devices.
So... it does not seem like a very good analogy?
FWIW be sure to assign proper expectations of security to those lockboxes, i.e. very very low.
I make a hobby of defeating them at friends' houses. Takes a few minutes.
The last time I sold a house, I brought the lockbox to the closing to hand to my real estate agent. He was perplexed.
Fair and good warning, but I'm curious, how long would it take you to pick my front door lock instead? Are you saying those lockboxes are significantly easier to defeat than a standard front door lock? (I am genuinely curious! I imagine it could depend on both the particular brand/model of lockbox and door lock!)
(Plus I have bars on some basement and first-floor windows in places that aren't easily seen from the street so seem especially vulnerable, but not on all my windows, someone could always break a window instead. I do not live in a secure military facility).
The real estate agent lockbox can be defeated by a random ten year old kid in less than ten minutes. Watch out TikTok!
Previously, in Northern Europe, I had a condo where the door+lock manufacturers literally cautioned you that the fire department cannot force a quick entry in case of emergency. Think bolts on hinge side of door, etc.
It does seem like it. The things you mention aren't drawbacks of this technology, and this is par for the course for whenever I see discourse on WebAuthn. People just mention random fears that they have, the vast majority of which aren't true.
If you want, you can keep on using your existing password manager for WebAuthn, or use a password. The standard doesn't care.