A sufficiently long, randomly generated password is also database-leak resistant. Good luck brute-forcing a 128-bit random string, hashed with scrypt or whatever.
So the only significant advantage is replay resistance. Which might or might not be a big deal, but let's not overplay the advantages.
This is a huge benefit. There’s no other way to put it.
From the admin side this also means significantly simpler database design
The password is only resistant if the one storing it is following best practices, which are NOT enforced and you really can't check for from the outside.
I'm talking about engineering on the other side, the person who has the password and uses it to log in. You can't social engineer Miriam from Accounting to give their passkey, you can do it with a password.
True … but the reaction to this by the vast majority of users is to go "stupid password manager autofill not working again", and copy and paste their password out of the pw manager and paste it straight into the phishing site…
You could say - and rightly so - that a person who reuses passwords invited whatever pwnage they get. But these people walk among us, do not use a password manager (often because not tech savvy enough), and passkeys are usable for those people.
- replay resistant: doesn't ssl already ensure this?
- database-leak resistant: if i'm understanding this correctly, this means a leaked database on the Fastmail side wouldn't compromise your Fastmail account? It's hard for me to imagine a situation where a compromise is serious enough that passwords are leaked, but nothing else?
- phishing proof: don't password managers already do this?
Very commonly user databases are the one being accessed for some reason, resulting in user data + salted passwords released.
How so? I can social engineer an employee to give me the password for a site they have in the password manager. I can't make them give me the passkey because they can't do that. It's not something you can paste in a chat.
this is a fundamental and un-addressable problem with passkeys as currently implemented
Presumably, you are already using a password manager at this point. Memorizing dozens of account passwords is not suitable for maintaining strong passwords.
Also, passwords still exist as a fall back if you need it, such as a situation you don’t have your device available. And not all accounts have to use passkeys.
Passkeys are effectively like ssh keys. Do ssh keys “lock you down” to specific devices? Sure they absolutely do unless you generate more keys or have some key management/sync workflow.
Re DB leak: No, you the concern is reused passwords (or similar passwords) from a different site.
Re phishing: Yes, but one of the FUDs against passkeys is that they lock you in to a vendor. There is no more lockin than if store your passwords in a manager.
However, there's no particular reason a FIDO key couldn't sign a login statement to a phishing site---it's just that statement wouldn't then be usable as a valid credential for the true site, regardless of if the signature from the FIDO key was valid or not.
If you have a password manager you like, maybe it’s for the best?
Maybe use more than one password manager, just in case.
I don’t think we’re at a point where I can 100% trust that the password manager will be able to handle every situation I run into from now until forever, and that’s what passkeys are asking for. I don’t see it.
For example, I can’t (and won’t) load my personal password manager on my work computer, but there is 1 site I use my personal account for and had to login when I got a new work laptop a few months ago. Another example is I still bum TurboTax off my dad, since he gets the version where he can do a bunch of returns. To download my data from the bank I need to login on my dad’s computer, and I’m pretty sure even if it was mine the password manager isn’t going to work with TurboTax. Another example I had was needing to login to a site to download and print something on a computer in a business center at a hotel… not something I ever want to make a habit of, but I was in a bind. I could go on.
These things come up. I think the idea that a person will only ever need to login on their own computer is unrealistic. That might be the case 99.9% of the time, but not 100%. That 0.1% does need to be accounted for.
But I expect that businesses will probably like it better than consumers. They probably don’t want their employees logging in using dodgy hotel computers.
The other 2 examples I gave were not random public computers. They were either in my control or the control of trusted family members. I still want solutions to those situations that passkeys can’t answer (as far as I know).
There are similar issues with 2FA. I was traveling a few years back and broke my phone. It’s the only time I’ve ever broken a phone. All the info for my flight and my tickets were on the phone. I was able to get to an Apple Store and get a replacement. When I went to set it up I got a 2FA prompt (it was enabled for me without me opting in sometime earlier). The only reason I was actually able to set it up was because I brought an iPad with me, which was just dumb luck. I often only have my phone. On my most recent trip I created a recovery key, wrote it down, and put it in a money belt I wore everyday. I’m really not sure what other option I’d have to recover if my devices were broken/lost/stolen. Of course having the key on me carries its own risk. Yes it was hidden and on my person, but I also felt the need to add a bit of randomness to it, incase someone did somehow get it, somehow figured out what the paper with a bunch of seemingly random letters was, and tried to use it. But this isn’t a normal thing people do, they’re just going to be screwed if something happens. When security starts locking out the owner because it’s too unclear, too complex, or too device restrictive, it can hurt more than it helps.
I understand the issues with passwords and why people want to get rid of them, but this feels like a happy path solution that doesn’t account for edge cases, which is a problem. There will always be edge cases and they can’t be ignored for something as foundational as authentication.
I have a Yubikey on my keychain and usually have a tablet as well, but it will need to be something more common.
To speculate, credit cards have RFID chips in them now, so maybe there is a possibility to identify yourself well enough to buy a phone and restore backups?
Meanwhile, if you use Google and Apple password managers, they do have systems to get your password manager back on a new device. For Apple, it seems you need to remember your AppleID password and for Google, the pattern you use to unlock your phone.
For that there's CTAP2/WebAuthn: https://fidoalliance.org/fido2-2/fido2-web-authentication-we...
"The other component of FIDO2, Client to Authenticator Protocol (CTAP), is complementary to WebAuthn. It enables an external authenticator, such as a security key or a mobile phone, to work with browsers that support WebAuthn, and also to serve as an authenticator to desktop applications and web services."
https://techcommunity.microsoft.com/t5/security-compliance-a...
"CTAP2 and WebAuthn define an abstraction layer that creates an ecosystem for strongly authenticated credentials. Any interoperable client (such as a native app or browser) running on a given “client device” can use a standardized method to interact with any interoperable authenticator – which could mean a platform authenticator that is built into the client device or a roaming authenticator that is connected to the client device through USB, BLE, or NFC."
And for the multiple person needing access to an account thing, password managers that store the passkeys allow sharing: https://support.apple.com/guide/iphone/share-passkeys-passwo...
Or alternatively, you just add a passkey for each of you in your own password manager to the accounts that you both need access to.
The usual workflow in practice when logging in to an “other” (hotel/work computer) computer is that you will be prompted to complete the authentication using a device with your passkeys (like your phone). The CTAP protocol they mentioned effectively turns your phone into a security key.
Using your phone with passkeys you scan the QR code shown by the website, then CTAP magic happens and you’re authenticated.
The great thing about this is that no reusable credentials are ever revealed to the dodgy computer.
https://coderoasis.com/passkeys-will-replace-passwords/
https://developer.apple.com/videos/play/wwdc2022/10092/
https://arstechnica.com/information-technology/2023/05/passk...
TLDR Replaces secret strings with crypto primitives mostly automatically managed.
boosters have yet to address this particular elephant to doubters’ satisfaction
I honestly don't know that I've seen one, unless the Apple / Google / Github / Gitlab "single sign on" links have all quietly switched to using passkeys under the hood (I thought they were all OAuth 2.0). Would be frustrating if so, because it wouldn't provide for custom / hardware implementations of the standard.
Putting myself in the position of a typical user, passkeys haven't "replaced" passwords until I don't have a password for Home Depot or what have you. Otherwise there's still a password I have to write down or remember somewhere.
I'm not even here as a hater - I do like the idea of cryptographic authentication replacing passwords - but I'm just saying I've seen zero real world uptake of this so far.
if, when challenged, one is unwilling to acknowledge the trade offs that indicates that they don’t understand them which suggests that they should not be trusted, in short.
forced passkeys are coming and I do not believe that is a good thing.