HNHacker News
TopNewBestAskShowJobs

0x4e53

8 karma · joined August 1, 2022

founder / ceo @ repacket | yc wc23 | ex spacex, aws
submissionscomments
0x4e53··on Show HN: Tracecat – Open-source security alert automation / SOAR alternative
Asking if folks use Yubikeys directly after he mentions a YC company literally responsible for deploying Yubikeys.

Nice.

0x4e53··on Passkeys will come at a cost
For context, we run a YC-backed passwordless company, and have rolled passwordless out at major organizations. While I think passkeys will definitely be the answer for consumer passwordless, I'm not sure this is quite reflected in the enterprise yet.

Passkeys are wonderful for consumer use, because they're meant to enable your own ability to break glass, by backing up the credential to other devices. You can do this via iCloud (by default) or via things like Airdrop.

Technically, the devices you share this credential to, cannot provide "attestation" - attestation is the "proof" that the keypair was created by a specific device (like a Yubikey, Apple Machine, etc). Manufacturers (like Yubico) ship a keypair / certificate onboard your key, that can't be extracted. There are no external methods to interface with this keypair - granting admins high confidence this is a real Yubikey.

You can see where this starts to become a problem without attestation, and the ability to share the keys. Enterprises are not willing to inherit the risk of an airdroppable credential exposing access to a privileged employees' account. There is a non-risk of digital theft when it comes to a Yubikey.

Ultimately - passkeys can't even be used to unlock your machines, or servers. FIDO2 (more importantly, OS developers) have a long way to go before we're done with passwords for good.

Today, Yubikeys are filling this gap for most of the enterprise market, some of whom have spent multiple millions of dollars on hardware. Passkeys in their current state are going to be a hard sell.

0x4e53··on Passkeys will come at a cost
At least for the enterprise - this decision should be up to the company. (i.e, flip a switch on your identity provider to enable or disable support for "no attestation")

Some companies are comfortable with the idea of a two-factor method that can be airdropped to friends. Major organizations (AWS, among others) are not huge fans of passkeys for enterprise use. When passkeys released, our initial response at AWS was to give organization admins the ability to disallow passkeys.

Overall, I think there are fixes coming across the board from Apple and the FIDO Alliance to address some of the early shortfalls of passkeys.

0x4e53··on Passkeys will come at a cost
Realistically, I don't think this will completely replace Yubikeys, nor do I think that only "security nerds" use them.

In reality - the majority of leading organizations use Yubikeys to secure authentication across their company. While it's likely not as common for consumers, it is probably the most trusted solution in the enterprise today.

0x4e53··on Launch HN: Matano (YC W23) – Open-Source Security Lake Platform (SIEM) for AWS
To be clear - we were hosting on-premise, and being charged for our own RAM. Servers we had to buy, and then pay for the privilege of using with ELK.
0x4e53··on Launch HN: Matano (YC W23) – Open-Source Security Lake Platform (SIEM) for AWS
At least from my time at SpaceX - this is untrue.

SIEM costs were rapidly ballooning, and we were being charged by RAM. RAM?? Of all things!!

After our SIEM costs for ELK ramped up to where Splunk was - we just bought Splunk instead. I imagine there are many security teams out there that would entertain a cheaper alternative that isn't priced by RAM.