8 ms·
Bringing passkeys to Android and Chrome
- genpfault 4y ago> Passkeys on users’ phones and computers are backed up and synced through the cloud to prevent lockouts in the case of device loss. How do you back them up locally?
- jasonjayr 4y agoAnd what happens if your Google account that these keys are tied to is locked/revoked for a nebulous ToS violation?
- ezfe 4y agoAt least on iOS, passkeys are stored locally in Keychain, even if they're also synced over iCloud (when enabled).
- makeitdouble 4y agoI'd assume it's the same story on iOS, as you won't get access to Keychain if your Apple ID is locked ? Provided Apple has fewer services and less surface for your account to get banned, but that's still a valid concern.
- zie 4y agoIn my experience on iOS, you can't make Passkeys work without also turning on syncing, that's sort of the entire point of Passkeys, otherwise they would just be WebAuthN tokens.
- sowbug 4y agoFrom TFA (the security blog): "The main ingredient of a passkey is a cryptographic private key. In most cases, this private key lives only on the user's own devices, such as laptops or mobile phones."
- toomuchtodo 4y agoFinal step is key escrow authority that will store your private key and produce it to you if you can proof your identity with government ID. It is not enough to store in cloud storage (which Google, Apple, or someone else could deny you access to), or your own device you could lose or destroy (which is why backup hardware tokens are always recommended for U2F MFA); you need the ability (but not a requirement) to bind cryptographic identity to IRL identity. Of course, one doesn’t need to utilize this, but you’re SOL without a recovery mechanism of last resort (unless individual sites and services have their own recovery processes to re-provision a user who no longer has access to their cryptographic credentials).
- EvanAnderson 4y agoIn the United States the US Postal Service would be a great fit for a job like this. They already have good infrastructure for identity verification and physical distribution. I wouldn't want escrow of private keys, however. I'd rather the USPS just act as a certification authority that provides strong guarantees of identity verification.
- toomuchtodo 4y agoYes, definitely. USPS + Login.gov could act as trust anchors, with cryptographic keys reprovisioned upon proofing, versus storing them. I am open to whatever is the optimal balance between security and practicality. https://www.uspsoig.gov/document/role-postal-service-identity-verification https://www.uspsoig.gov/document/role-postal-service-identit... > The Postal Service Reform Act of 2022 has recently expanded the Postal Service’s ability to provide identity verification to all levels of government. A window of opportunity is currently open for USPS to contribute to closing gaps in government identity verification processes.
- insane_dreamer 4y agocan you download/print backup recovery codes?
- googlryas 4y agoI suppose you would just do the "I forgot my passkey" flow.
- colordrops 4y agoUgh, I hope they don't make it difficult to use third party password managers. I'm pretty happy with vault warden.
- selykg 4y agoPretty sure there's been talk on the Bitwarden community forums about them adopting support for using it as a provider. I assume once that's available you might start to see it move into Vaultwarden. But, that's sort of the risk you run with using a 3rd party to a 3rd party...
- colordrops 4y agoAt least with Vaultwarden, it's open source and running locally with data stored on a server in my house, so if they misbehave, I could easily fork or switch projects. If Android doesn't allow or otherwise hobbles 3rd party password managers, there isn't much recourse.
- selykg 4y agoThat's fair, but Bitwarden itself is also open source... though, my understanding is significantly more difficult to get up and running than Vaultwarden.
- greatgib 4y agoAnother product that they will use their dominant position to force down our throat!
- selykg 4y agoThis is all part of the FIDO Alliance, so, a standards based solution that anyone with the wherewithal to implement it can do so. Many password managers have already said they'll be supporting it, as well as major vendors (Google and Apple for instance). I'm struggling to see your complaint being a valid one. This is basically webauthn, so use a Yubikey or similar device if you wish.
- greatgib 4y agoRemember how gmail was just imap/smtp? etc...
- donio 4y agoYes, and it still is. I have been using Gmail since 2004 and I very rarely touch the web or mobile UIs. 99% of my interactions with it are through SMTP and IMAP. I don't think that Gmail has fundamentally changed in this sense, it has just gotten very popular. The various incarnations of their chat services is a better example. Gtalk used to have great XMPP support, even federation for a while. All remnants of that are gone now so I had to stop using it.
- stevewatson301 4y agoYou'll be out of luck when trying to switch from one ecosystem to another (for example, from Apple to Google).
- selykg 4y agoThis is really no different between switching hardware devices. Step 1. Sign in using your existing device Step 2. Add your new device Step 3. Remove your old device (or keep it for a backup) And if you feel that's going to be a big issue for you, use a 3rd party software based tool like Bitwarden, 1Password, or other tools that have indicated they'll be supporting this. That info will sync between those software based tools and allow you to use whichever devices you wish, across multiple platforms with minimal effort.
- madjam002 4y agoSee also https://security.googleblog.com/2022/10/SecurityofPasskeysintheGooglePasswordManager.html https://security.googleblog.com/2022/10/SecurityofPasskeysin... which provides a more technical overview
- LibertyBeta 4y agoInteresting. I'm still struggling to see how this is better than just using a yubi/solo-key
- jrm4 4y agoMore convenient, but less safe for everyone in the long run.
- runako 4y agoPasskey will be supported, with no new user behavior, by ~a billion devices currently in use. It is better because a billion+ devices already have support for this.
- eli 4y agoMore people own an Android phone than a yubikey?
- selykg 4y agoI would use this in addition to those. Instead of having to buy two Yubikeys I can buy one and use a software solution as well. Since I already use a phone capable of doing the same thing, let my phone be my main authenticator, and then I can use a Yubikey as a backup. It's not like one is necessarily better than the other, except that you already carry a phone and they're capable of being a hardware device that works with Webauthn. No need to carry a second device or, pay for one, for that matter. Since at least with Apple's solution it'll sync over iCloud Keychain. If you're happy with Yubikey's, nothing changes. But for the average person, this makes Webauthn an option without having to buy any hardware or carry something you are more likely to lose because you don't understand the intricate details of how the thing works. I wouldn't expect my parents to understand how a Yubikey works well enough to know it should be used as a pair, for backup purposes, but that is a barrier to entry for them that they don't need to worry about now.
- LibertyBeta 4y agoThat makes sense. I do worry we are starting to build key chains that are leveraged obliquely to the user. Once passkey support comes to bitwarden I'll be a little more comfortable I think.
- jrm4 4y agoNah. For all the talk of "one app to rule them all" (which is an awful idea) this is a step closer to that. For all it's faults, crypto has one thing right -- not your keys, not your stuff. I get that doing keys/passwords is hard, but the best thing in the long run is for them to stay in the hands of the user. And if not, the holder of the keys needs to be someone you can easily hold accountable, i.e. either fire, or arrest, or sue if they get it wrong.
- jackson1442 4y agoit is your key, it lives on your device (and is synced across devices using your cloud account if you so choose)
- webmobdev 4y agoAnd BigTech's cloud (who will have no problem sharing it with the authorities). And when all your keys are on the device, it also becomes a lot easier for the government to access all your internet accounts by getting access to the device.
- jackson1442 4y agoThey're end-to-end encrypted. Did you read the article? This is the same threat model as password managers, which are generally approved of on HN.
- jrm4 4y agoYeah, I think HN is mostly wrong about those as well. :)
- tjoff 4y agoYou can backup your password manager. You don't have to depend on the cloud for your password manager.
- webmobdev 4y agoWho cares if it is "end-to-end encrypted" if the device with all your keys / credentials can be easily used to access all your online accounts? (And no online service forces me to use a password manager).
- okhuman 4y agoCheck out AuthCompanion, a passwordless login implementation for ideas. https://github.com/authcompanion/authcompanion2 https://github.com/authcompanion/authcompanion2
- aseipp 4y agoAlso along these lines, there's a really neat little library called "SimpleWebAuthn" that also supports Passkeys, and is basically a small dependency-free set of client Javascript (for initiating the user flow) and a small JavaScript server component to go with it: https://simplewebauthn.dev/ https://simplewebauthn.dev/ The code is pretty simple and a good place to start, as well as AuthCompation, if you wanted to roll your own library in your language of choice or whatever, or something very custom. I found both useful recently.
- wnevets 4y agoPasskeys sound like another way for companies like Google and Apple to lock you into their walled garden. Having each walled garden randomly generating a key for every single domain instead of using the actual domain name as part of the key is a great way to lock regular people into their respective ecosystems.
- redandblack 4y agoyeah. will be switching to this for all google apps, with firefox for general use
- api 4y agoThe entire third party auth push has turned into what may be one of the largest incumbent power grabs I have ever seen. Stuff like Google Amp or even App Store walled gardens pale in comparison. What drives me nuts is how little discussion of this I've seen. People don't even seem aware of the implications of it. It's being pushed hard as a boon to security, which it is in some cases, but at a cost that nobody is even considering or talking about. The implications are pretty profound: large companies having the power to lock you out of everything on a whim (even your own systems and unaffiliated third party services), levy taxes on the use of everything (e.g. Google starts charging you or sites to log in with Google), surveil literally everything (including logging into everything you have as you and sucking down data), and if a big identity provider gets seriously hacked it'll be an epic security apocalypse. Imagine someone stealing the master keys for a provider and pushing ransomware to millions of companies at once. ... and don't forget the obvious: "Oops I got locked out of Google and now I'm locked out of 50 SaaS services, my company's bank, my VPN, and my remote servers." It just totally blows me away that these systems have no privacy protection at all, no portability provision for me to select or change my provider built into the protocol, no built-in support for third factor auth that I can control (e.g. FIDO2), no built in provision for recovery codes, and so on. These kinds of things didn't even seem like they were considered in the design of things like OpenID/OIDC. It's just a big "oh hey lets give god level access with no recourse to third parties and implement it so there's total lock-in... what could go wrong?" Edit: yes some well-implemented systems offer their own built-in support for some of those things (recovery codes, changing your auth provider, reverting to password, etc.) but in my experience it's a minority and there is obviously nothing in the standard to encourage it or provide any guidance on how to do those things securely.
- fotta 4y agoGoogle's auth is getting increasingly frustrating. Recently when I logged in with TOTP 2FA, I had to also open up YouTube on another device and click approve. What's the point of 2FA if they're just going to ignore it?
- htrp 4y agoWelcome to user hostile revenue maximization algorithms
- account-5 4y agoI don't use my phone to log in to anything. All my stuff is done on a computer with a password manager. At no time am I even likely to rely on Google for anything this important; every other week there's a thread about Google killing off accounts for no reason. No way would any sane person allow Google access to this with their track record. And this isn't even considering my suspicion that Google only wants to "help" with this so you're locked into their services and they are better able to track your activity.
- alyandon 4y agoExactly. I will never trust Google to control access to my logins knowing that the Sword of Damocles (the Google "AI" deciding I'm a bad person) is hanging over my head. If Google did an about face and started providing reasonable escalation mechanisms for when they lock you out of your account based on a faulty decision of their algorithm I'd consider it.
- forty 4y agoYou might be able to do "passkey" with your password manager https://www.theverge.com/2022/8/31/23329373/dashlane-passkeys-password-manager https://www.theverge.com/2022/8/31/23329373/dashlane-passkey... (I work for this specific one, but I'm sure others have similar things in the work)
- smileybarry 4y agoAgileBits have passkeys in the works for 1Password: https://blog.1password.com/1password-is-joining-the-fido-alliance/ https://blog.1password.com/1password-is-joining-the-fido-all...
- Spivak 4y agoI mean that’s gonna be my adoption path. Once I can store passkeys in Bitwarden I’ll switch to them everywhere.
- KronisLV 4y ago> I don't use my phone to log in to anything. All my stuff is done on a computer with a password manager. More or less the same, except that I haven't found good TOTP solutions for the desktop, to the tune of KeePass (something that can run on Windows/*nix instead of making me use something like FreeOTP, Google Authenticator or other Android/iOS apps; or in addition to the mobile apps). That said, even with multiple Google accounts for different things (e.g. personal e-mails, file storage, cloud services etc.) it feels like eventually you might want something like Qubes OS, another way to run multiple separate VMs, or just use separate devices for separate use cases. Much like how some orgs have separate laptops for accessing prod environments, that are more tightly controlled, even though that's not convenient enough for most people.
- cglong 4y agoPeople are raising really good points here, but I do find it interesting how negatively this news is being received vs. when Apple said the same thing: https://news.ycombinator.com/item?id=31643917 https://news.ycombinator.com/item?id=31643917
- Someone1234 4y agoThe second most popular top level comment chain is: > Unless I can back it up and import it into a new device from a competitor, then there is no way I am going to use this unless forced. I do not trust one company anymore. Which is the same sentiment as this thread. The first comment was just talking about the open standard of Apple's implementation and weakness of 2FA loss/recovery. https://news.ycombinator.com/item?id=31644190 https://news.ycombinator.com/item?id=31644190
- throw10920 4y agoYup - GP made the mistake of treating HN as a single person with a coherent opinion. It's not, and it's extremely tiring and intellectually uninteresting to repeatedly see people doing that.
- pastage 4y agoNo. While I have tried to counter these group think posts you talk about, I only find them interesting because I think it is human nature to do it. I know I do it all the time.
- woojoo666 4y agoYour GP did not treat HN as a single person, they are simply pointing out population trends. And these trends are important when analyzing the dynamics of a democratic (upvote-based) content platform
- webmobdev 4y agoHN is not really a pure "democratic (upvote-based)" system as moderators can (and do) "interfere" in the process - they can remove comments or bring a low ranking comment to the top of the discussion if they feel that a discussion on that might be more interesting for the HN crowd.
- ok_dad 4y agoTry telling the authorities you "forgot" your password when they know you use passkeys.
- potatoz2 4y agoIt’s not that difficult: you use a PIN/passphrase protected hardware token. Done.
- thrillgore 4y agoComing never to Firefox, Edge, and iOS.
- stavros 4y agoFirefox has supported WebAuthn for years.
- madjam002 4y agoIt’s been supported on iOS since iOS 16
- postalrat 4y agoThere is so much ignorance and misinformation around webauthn. I don't understand why people aren't jumping on it. Passwords suck. Password managers make passwords more manageable but they still suck. Why not move on?
- politelemon 4y ago> A passkey on a phone can also be used to sign in on a nearby device. For example, an Android user can now sign in to a passkey-enabled website using Safari on a Mac. Similarly, passkey support in Chrome means that a Chrome user, for example on Windows, can do the same using a passkey stored on their iOS device. > Since passkeys are built on industry standards, this works across different platforms and browsers - including Windows, macOS and iOS, and ChromeOS, with a uniform user experience. I see no mention of Linux in these examples, which tells me that users having access to their keys is not a primary concern for these implementations?
- oezi 4y agoIt seems the client side is baked into browsers rather than being something which leverages a local implementation for key storage.
- jeroenhd 4y agoCan we have this but self-hostable and open source, please? Something like Bitwarden that you can stuff onto your own device? I know there are hosted services for handling auth on the server backend, but what about the other way around? I use Krypton but that's not maintained (and already broken on some websites like Github). I trust the secure storage module of my phone and I trust my computer's TPM, unlike many other Linux users; surely it should be possible to integrate with the OS somehow to make it secure, right? The last example I saw used USB over IP to inject a virtual FIDO device, which works great, but the implementation is clearly not ready for prime time.
- mimi89999 4y agoDo you know if it's possible to see a list of stored passkeys in Android? I installed the Play Service beta, managed to create a passkey and sign in, but can't see the list of credentials anywhere in the UI.
- xg15 4y agoDumb question: what keeps me from spoofing the fingerprint[1] and obtaining all the passcodes at once? [1] https://phys.org/news/2005-12-biometric-expert-easy-spoof-fingerprint.html https://phys.org/news/2005-12-biometric-expert-easy-spoof-fi...
- chocolatkey 4y agoNote you can't just get the keys even if you have a fingerprint. You would need to maintain continuous access to the device while it is still signed in as the user. It would be pretty easy to the "find my device", if the user didn't already notice you were handling it
- acdha 4y agoFirst, note that the article you linked is pretty old — the people who build biometric systems have added countermeasures in the last couple decades. They're definitely not perfect but it's not an especially easy attack since it's personalized and doesn't scale. The first thing to remember is that your fingerprints / face scan are not the identifier for your passkey. They are used by the local device to unlock its secret store but the actual keys are regular crypto keys and the remote website never sees any of them. The interface also does not provide access to the private keys ever, and it should be rate-limited so it's not “get all of the keys” but the much slower “use the phone I stole to hammer out requests to different websites, mashing that sensor every second or two”. That means that whoever stole your phone & forged your biometrics is in a race with you revoking their access, but when you do it won't matter that they have your biometrics unless they can also steal your new phone (stop pissing off the Mossad). The other thing to consider is what your threat model is. If you're worried about someone stealing your phone and building a realistic model of your fingerprint or scan of your facial structure, you have to ask what the alternatives are. For example, it'd be a LOT easier for an attacker to use a hidden camera or drone to record you entering your password — not using biometrics means you're typing it frequently, for example — and you're also at risk for all of the scenarios which passkeys are immune to (credential reuse, phishing, weak passwords), which happen to be by far the most common way people are compromised. Very few of us have to worry about targeted attacks by skilled adversaries, and if you are worried about that you probably need to move or hire a bodyguard more than anything involving infosec.
- dickhardt 4y agoQ: how many of you will add support to Passkeys to your application? Is it worth the effort of adding yet-another-way-to-login for your users? It will be a long time before you could use it as the ONLY way to login. You will need to figure out how to enable your existing users to convert to Passkeys. Apple has a glide path for converting username password -> but not for other mechanisms. I believe we in letting the user choose whatever way is best for them to login -- and to take that burden off of the developer. If you want to learn more, check out the Show HN post on Hellō I wrote this morning. https://news.ycombinator.com/item?id=33177705#33182379 https://news.ycombinator.com/item?id=33177705#33182379
- fleddr 4y agoI'm noticing very little discussion about the user aspect, and I say that with non-savvy users in mind. I run a mid-sized web app/community where I've been supporting such users for a long time. Right now, I offer a classic login, and a few social providers. You'd think this is straightforward to support, but about 70% of support requests consists of the endless ways in which users can mess this up. "Can't get in" Try recover password. Email didn't come. Because they entered the wrong email. Correct email this time. No wait, think I signed up with a social account, not sure which one, have many. Login worked. Wait now it doesn't again (saved browser password did not update). This is just the tip of the iceberg. This new solution, whatever merit it has, is going to be additive. It won't replace anything, it's yet another way to log in, if at all, as it depends on websites implementing it and about 90% of the web is basically not maintained. So it's only adding complexity/confusion specifically to these users, which I consider to be the vast majority. In turn leading to more support headaches.
- acdha 4y agoThe flip side is that it’s incredibly easy to use, faster, and means you don’t have to worry about forgotten passwords or phishing. It’s like an order of magnitude faster than less secure MFA options, too.
- fleddr 4y agoWell, no, it isn't. Clearly you don't do old people tech support. Passkey? What's that? New word thus meaning unclear. Doesn't seem to ask for an actual pass-anything, so more confusion. No email identifier or thing to remember. How can I know log on at my other device? With a QR code? What on earth is that?
- acdha 4y ago> Well, no, it isn't. Clearly you don't do old people tech support. Actually, I do — in fact the largest system I work on supports predominantly older people with disabilities. I would strongly suggest that you consider whether your assessment of the relative difficulty levels is skewed familiarity with the existing problems with password systems. > No email identifier or thing to remember. How can I know log on at my other device? > With a QR code? What on earth is that? You still use your email address. This replaces passwords, not SSO, and QR codes are only used in some cases for some implementations where you might have restrictions on things like network connectivity. Try the demo here: https://www.passkeys.io https://www.passkeys.io Here's the signup process: 1. Enter your email address 2. Select the option to use a token 3. Approve your device's prompt (on iOS, this is a system dialog which explains that it's stored on all of your devices using iCloud Keychain and the site owner doesn't get any of your PII) Note what's not there: picking a secure password, setting up MFA, remembering that password, and entering it reliably every time. You also can't get phished, which seems like something a lot of people would like. We're familiar with the friction around passwords but consider how many hours a day humanity spends creating passwords, resetting them, dealing with typos, etc. If you support older people or especially those with disabilities, that process is a lot harder. For example, entering a password over a screen reader which meets most site's complexity requirements is terrible. Most non-WebAuthn forms of MFA are pretty painful that way, too, because it requires someone to switch apps, copy/paste or remember a code, switch back, etc. before it times out. This won't be perfect on day one, I'm sure, but it's already easier and faster to use and that's only going to continue because now the system can be improved by the browser vendor rather than needing every site to agree on improvements.
- stavros 4y agoThe thread here seems like a dumpster fire to me. Everyone here is worrying about lock-in to an open standard, so I want to clarify things. WebAuthn is an open standard. It's a way for you to prove to a website that you have a specific private key. There's no lock-in, because the key is portable (unless you don't want it to be). There's no privacy issue, because the key is unique per website. There's no security issue, because it's unphishable and can be unstealable if it's in hardware. If you don't like Google or Apple, use your favorite password manager. All it will have to keep is a private key per website, and you're done. No usernames or passwords. You visit a site and are automatically logged in with a browser prompt. This is amazing, it's the best thing that's ever happened to authentication. It's something the end user cannot have stolen. Can we be a bit more excited about it? EDIT: If you want to try it, I just verified that https://www.pastery.net/ https://www.pastery.net/ works great with Passkeys even though I haven't touched the code in a year. That means that django-webauthin also works great with Passkeys, for you Django users: https://pypi.org/project/django-webauthin/ https://pypi.org/project/django-webauthin/ Also, the latest Firefox on Android seems to work great.
- xg15 4y ago> There's no lock-in, because the key is portable (unless you don't want it to be). > There's no security issue, because it's unphishable and can be unstealable if it's in hardware. You mean, you can (in theory) choose whether you'd rather have a lock-in or a security issue. Both options are mutually exclusive, you can't have them both at the same time.
- stavros 4y agoNo, I don't. You don't have to use Google's thing, use an open source password manager that syncs via Dropbox or whatever. Same thing, different vendor.
- xg15 4y agoSure I can. But then, if an attacker gains access to my device, so can they. They can just set the phone to sync with their own cloud service. Phishing would also be back on the table: The phishers' narrative would just change to something like "Dear $user, we're upgrading our systems. For technical reasons, please change your sync target to $url, otherwise you will lose access to all your logins. Yours truly, Dropbox" My understanding was that many of the advertised security properties of passwordless logins stem from the property that no one, not even the owner of the account has access to the key. This renders phishing impossible because the user cannot physically give away the key even if they wanted to. But that solution is fundamentally incompatible with copying the key to anywhere else.
- sneak 4y agoPretty soon you won't be able to log in to any major website with javascript disabled.
- rektide 4y agoIt's be a damned good time for someone to start building a competing Google Sync impl & server & passkey implementation into Chromium. For a while this was largely built around XMPP but now the stock Google implementation is custom. I'd love a refresher crash course on what's in Chrome that's not in Chromium. It's been a long time since I used Chromium but I think when I did it seemed to have a as-best-I-could-tell working Google Sync implementation. It's hard to imagine a scarier project to fork. I dont think there's a lot of resources out there for DIY'iny a Chromium fork.
- pabs3 4y agoFor those of you who want something like this with Firefox on Linux, the virtual-fido project might provide a decent alternative, it uses Linux's USB-over-IP support to provide a fake FIDO device, and Firefox supports FIDO devices for WebAuthn: https://github.com/bulwarkid/virtual-fido/ https://github.com/bulwarkid/virtual-fido/ https://news.ycombinator.com/item?id=32881956 https://news.ycombinator.com/item?id=32881956
- pabs3 4y agoI wish WebAuthn would have a standardised HTTP header or TLS extension so it would be usable without JavaScript, currently every website has to implement their own login protocol in JavaScript. https://github.com/w3c/webauthn/issues/1255 https://github.com/w3c/webauthn/issues/1255 https://github.com/w3c/webauthn/issues/1616 https://github.com/w3c/webauthn/issues/1616
- pabs3 4y agoHere is the technical side of how passkeys work: https://www.imperialviolet.org/2022/09/22/passkeys.html https://www.imperialviolet.org/2022/09/22/passkeys.html https://news.ycombinator.com/item?id=32946750 https://news.ycombinator.com/item?id=32946750