Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
timmyc123
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
timmyc123
2mo ago
Still taking feedback and questions for an upcoming consumer centric "What's a passkey?" site. https://forms.gle/wmaydkzmUp2eKfJG7 Original post: https://news.ycombinator.com/item?id=47852849
2.
▲
by
timmyc123
2mo ago
You can use any credential manager you choose for Microsoft Account passkey.
3.
▲
by
timmyc123
2mo ago
https://mobileidworld.com/apple-introduces-cross-platform-pa... https://support.google.com/chrome/answer/13068232?hl=en&co=G... https://1password.com/blog/import-autofill-
4.
▲
by
timmyc123
5mo ago
We’re building an interactive resource to demystify passkeys for both the general public and more technical users. We’re aggregating questions to ensure our FAQ and interactive guides cover "how do I use this?" type questions from
5.
▲
by
timmyc123
7mo ago
> The essay has a condescending attitude towards the normie computer user who can't possibly be expected to know, but it's precisely the normie computer user who would never get the stupid idea of "cleaning up" their
6.
▲
by
timmyc123
7mo ago
You can use any credential manager you choose. It is an open ecosystem. If you don't want to use a cloud service, don't. You can self-host many credential managers. There are also many solutions that just use a local database.
7.
▲
by
timmyc123
7mo ago
Hey I'm the guy you're talking about. Always easy to crap on people when you selectively quote what they said. The core pieces you left out are: > I don't quite understand why requiring file protection/encryption can&
8.
▲
by
timmyc123
7mo ago
> Too bad the spec is stupid and requires password managers to be identifiable so servers can deny the "insecure ones". There is no requirement that credential managers identify themselves. Please stop spreading misinformation.
9.
▲
by
timmyc123
7mo ago
Not sure what you mean. In most cases, passkeys sync across your devices.
10.
▲
Please, please, please stop using passkeys for encrypting user data
(blog.timcappalli.me)
14 points
by
timmyc123
7mo ago
|
11 comments
11.
▲
by
timmyc123
9mo ago
> stored on a YubiKey/Secure Enclave/TPM and that was what made them resident. Stored in an authenticator/credential manager in general, not specific to a security key, secure enclave, or TPM.
12.
▲
by
timmyc123
9mo ago
Not really. The attestation model defined for workforce (enterprise) credential managers/authenticators doesn't really work in practice for consumer credential managers.
13.
▲
by
timmyc123
9mo ago
A passkey is a discoverable credential (aka resident key) in spec terminology. But the type of credential has no relationship to attestation (which is not used in the consumer passkey ecosystem).
14.
▲
by
timmyc123
9mo ago
The dialog provided by the browser or OS usually tells you where the passkey is saved.
15.
▲
by
timmyc123
9mo ago
Copy and paste in clear text? Yes, I don't think that's a good idea. Download to disk in clear text? Yes, I don't think that's a good idea. Years and years of security incidents with consumer data show that this is a rea
16.
▲
by
timmyc123
9mo ago
If a website were to attempt to do this, you (or your credential manager) could simply change the AAGUID to match another credential manager.
17.
▲
by
timmyc123
9mo ago
Attestation is not used in the consumer passkey ecosystem.
18.
▲
by
timmyc123
9mo ago
Hi, Tim Cappalli here. Not sure how stating that my (an individual) opinions on a topic are evolving is interpreted as "threatened the KeypassXC developers". If you've been following along, you'll have seen that I am act
19.
▲
by
timmyc123
9mo ago
This is one of the core use cases for why FIDO Cross-Device Authentication was created. To be able to use a passkey to sign in on a shared device, a device you don't control, or a device where you just need temporary access to somethin
20.
▲
by
timmyc123
9mo ago
> it’s discouraged Why do you say that? There are billions of synced passkeys being used by users with some of the largest sites and services in the world.
21.
▲
by
timmyc123
9mo ago
Not exactly. For example, the default credential manager on Android is Google Password Manager, which works on Windows, macOS, iOS, and Ubuntu. There are also dozens of other third party choices.
22.
▲
by
timmyc123
9mo ago
I used the technical name for the capability, but you've likely run into it before. If there is no passkey on the local device, a QR code will appear which you can scan with your phone or tablet, and use the passkey for the account fro
23.
▲
by
timmyc123
9mo ago
Unclear how this quoted comment relates to what I was replying to (which was about exporting / backing up your credentials). But I'll respond. > Will I always be able to use any credential manager of my choice? Any naturally al
24.
▲
by
timmyc123
9mo ago
You're quoting the first post of a long discussion, where the importance of protecting your data on disk was highlighted, and a proposal was made that at minimum, the default should be encrypting the backup with a user selected secre
25.
▲
by
timmyc123
9mo ago
I can certainly see the confusion. Thanks for highlighting it!
26.
▲
by
timmyc123
9mo ago
Passwords is the name of the app on your Mac.
27.
▲
by
timmyc123
9mo ago
> The passkey vendors state that the goal was to make phishing not just difficult but impossible. This means plaintext access to your credentials is forbidden forever, regardless of your level of expertise, and regardless of the complexi
28.
▲
by
timmyc123
9mo ago
Google Password Manager, Bitwarden, 1Password among many others.
29.
▲
by
timmyc123
9mo ago
Your credential manager provides this sync and backup capability. There are dozens of credential managers available that work on all platforms. You don't have to use the default one on any given platform. Bitwarden is my personal choic
30.
▲
by
timmyc123
9mo ago
Hi! I'm the commenter on that post that keeps being brought up! I don't think requiring an encrypted backup (with a key or secret that YOU control) by default is "preventing users from being able to export their own private
More ›