Passkeys

cd24,
@cd24@sfba.social avatar

I spent the morning switching as many accounts as I could to , and it was the most pleasant, simple, and straightforward process. I am disappointed that many sites are only using it as a 2FA option instead of the main sign in tool (including ).

It's extremely intuitive, and I can't wait for all of my passwords to be gone.

cd24,
@cd24@sfba.social avatar

Really, exquisite work on the Passkeys project by @rmondello and co. 👏👏

matt,
@matt@isfeeling.social avatar

truly are the new lock in for password managers. I'm trying to be a good citizen and use passkeys wherever I can, but now I can't properly try other password managers without needing to create dozens of new keys. I'm trying Proton Pass now, and it's a major pain.

Extrapolate this out to a world where passkeys are the norm and effectively all of my accounts authenticate this way, and moving your data becomes impossible. :dumpster:

matt,
@matt@isfeeling.social avatar

I know the FIDO Alliance and passkey enthusiasts will say that the passkey standard isn't built to lock users in, and migrating them should be possible.

That's well and good, but we're several years into this and zero of the major players support this. Whether you use Apple, Google, 1Password, or anything else, your passkeys are locked to those accounts today. maybe you can move in a few years, but you can't now. Yay.

matt,
@matt@isfeeling.social avatar

Something something, don't get a product today based on hopes and dreams of future software updates…

As an aside, Apple is the only place I've been that makes it impossible to use anything besides their password manager for setting up a passkey. It's maddening.

beli3ver, German
@beli3ver@social.tchncs.de avatar

@protonprivacy warum sagt bei mir das nicht möglich sind? Ich habe ein OnePlus 9 Pro with Android 14

why does tell me that are not possible? I have a OnePlus 9 Pro with Android 14

protonprivacy,
@protonprivacy@mastodon.social avatar
srueegger, German
@srueegger@swiss.social avatar

🔑 Passkeys: Die passwortlose Zukunft ist da!

Bist du es leid, dir unzählige zu merken? Die neueste Technologie der verspricht eine einfache Lösung.

Aber wie nah sind wir wirklich an dieser Zukunft? In meinem neuesten Blogbeitrag werfe ich einen kritischen Blick auf die aktuellen Herausforderungen von Passkeys.

Erfahre mehr über die Zukunft der digitalen Authentifizierung. 🚀💻

https://rueegger.me/2024/05/05/die-herausforderungen-der-passkeys-eine-zukunft-ohne-passwoerter/

jela, German
@jela@social.tchncs.de avatar

Das hat ihre Richtlinien zur digitalen Identität für die Verwendung von ergänzt. US-Behörden können synchronisierbare und gerätegebundene Passkeys verwenden, um eine Phishing-resistente zu ermöglichen.
https://www.nist.gov/blogs/cybersecurity-insights/giving-nist-digital-identity-guidelines-boost-supplement-incorporating

jnareb,
@jnareb@fosstodon.org avatar

I'm very disappointed that passkeys (allegedly) got enshittified before I could start to try to use them: https://fy.blackhats.net.au/blog/2024-04-26-passkeys-a-shattered-dream/

#passkeys #Enshittification #passwords

schizanon,
@schizanon@mastodon.social avatar

PassKeys seem like a bad idea. Google backs them up to the cloud, so if your Google account is compromised then all your private keys are compromised. I don't see how that's an improvement over password+2FA at all.

Now security keys I get; keep the private key on an airgapped device. That's good. Hell I even keep my 2FA-OTP salts on a YubiKey.

#passkeys #fido2 #webauthn #yubikey #2fa #otp #authentication #cryptography #security #passwords #passkey #password #securityKey #google

vintprox,
@vintprox@techhub.social avatar

@magitism @schizanon In other words... "magic link" but with extra steps.

firefly,
@firefly@neon.nightbulb.net avatar

Structural security trumps computational security ... or ...
Diffuse structural security trumps amalgamated computational security ...
All your big, strong passkeys in one basket is less secure than your passwords in many individual baskets ...
Trying to explain this to tech bros can resemble pushing a wagon uphill ...
Because they want to sell something, logic is not paramount.

See here:

https://www.metzdowd.com/pipermail/cryptography/2023-September/038186.html

"A password in my brain is generally safer than an app or SMS stream that can be compromised. Although a passphrase may in some cases not be computationally more secure than a token mechanism or two-factor sytem, the simple passphrase is often structurally more secure because that passphrase only links to and exposes one service target."

and here:

https://www.metzdowd.com/pipermail/cryptography/2023-September/038188.html

"I like to compare it to having one basket of eggs in one spot, and many baskets of eggs in many places. If your one basket of eggs has the master key to all the other stronger keys, is it easier to get the one basket, or the many baskets with weaker keys? So in this scenario cipher strength is not the most important factor for security. With a single basket one fox or pick-pocket or one search warrant can own all of your eggs for all your services."

#Passkeys #Passkey #Passwords #Password #2FactorAuth #Authentication #Security #Cryptography

scottjenson,
@scottjenson@social.coop avatar

Am I the only one confused by ? They feel clunky, it's not at all clear what is going on, and honestly doesn't feel any different than a password manager (but somehow worse)

I really don't even understand what is going on under the hood. Are there any good explainers out there?

Ciantic,
@Ciantic@twit.social avatar

@scottjenson The main problem for me is that browser vendors have intentionally made passkeys difficult to use without hardware keys. There are clunky ways to emulate Bluetooth hardware keys purely in software but that just adds to the confusion.

I would've preferred tight integration with something we know, like GPG/PGP, though that stack has its own set of issues (mainly that there are not good secondary implementations, but they might be resolved.)

grantpotter,

If you really want put them in a password manager you control. But don't use a platform controlled passkey store, and be very careful with security keys. https://fy.blackhats.net.au/blog/2024-04-26-passkeys-a-shattered-dream/

JetForMe,
@JetForMe@geekstodon.com avatar

I recently implemented Passkey support in one of my apps, and ran into some limitations of the spec. I had no idea it was this bad.

I had assumed I’d be able to get my passkeys out of my Apple devices, but hadn’t put any real thought into that.

“Since then Passkeys are now seen as a way to capture users and audiences into a platform. What better way to encourage long term entrapment of users then by locking all their credentials into your platform, and even better, credentials that can't be extracted or exported in any capacity.”


https://infosec.exchange/@firstyear/112335226264184474

katzenberger,
@katzenberger@social.tchncs.de avatar

@firstyear , the author of webauthn-rs, on #passkeys (I don't agree with everything in the article):

»starting to agree - a password manager gives a better experience than passkeys.[…]

Get something like bitwarden or if you like self hosting get vaultwarden. Let it generate your #passwords and manage them. If you really want passkeys, put them in a password #manager you control. But don't use a platform controlled passkey store, and be very careful with security keys.«

https://fy.blackhats.net.au/blog/2024-04-26-passkeys-a-shattered-dream/

kas,
hateaid, German
@hateaid@troet.cafe avatar

yqUxBV#_\jfVyD!mZ8RH7]Te8jqKA![? – auch dieses Passwort kann geknackt werden. Deshalb bieten immer mehr Dienste [#Passkeys als Login-Alternative an. Lest hier, wie sie genau funktionieren und was sie so sicher macht: https://hateaid.org/sicheres-passwort/?mtm_campaign=tsp-it-sicherheit-passkeys&mtm_kwd=mastodon

Dieses Projekt wird unterstützt vom Bundesministerium der Justiz.

#Datensicherheit #ITSicherheit

nsa,
@nsa@hachyderm.io avatar

New post on choosing the right timeout value in !

tl;dr

  • design your challenge-response protocol to allow for a very long value
  • whatever you do, don't leave it to the default value

https://satragno.com/blog/webauthn-timeout/

ianRobinson,
@ianRobinson@mastodon.social avatar

What account should I use as my first experimental login to convert to using passkeys?

PayPal?

I know you don't know what systems I use, so this is a bit of a meaningless question. But do you know of any popular systems that a lot of people use that now support passkeys?

Preferably ones that can be stored and used by 1Password 8. Maybe I should do 1Password first if they support passkeys.

Unlogic,
@Unlogic@hachyderm.io avatar

@ianRobinson I have initially switched to passkeys for eBay and GitHub. Storing them with KeePassXC.

ianRobinson,
@ianRobinson@mastodon.social avatar

@Unlogic Ta!

protonprivacy,
@protonprivacy@mastodon.social avatar

Hate ? Use !

This new and easy way to secure your accounts removes the need for passwords by authenticating you with your device. Passkeys also provide a higher protection against attacks.

Here’s how to get started with on , and browser extension. https://proton.me/blog/what-is-a-passkey

protonprivacy,
@protonprivacy@mastodon.social avatar
case2tv,
@case2tv@social.tchncs.de avatar

@protonprivacy make them available for Firefox and I will try.
Until know passkeys are not working 🤷‍♂️

fission,
bsi, German
@bsi@social.bund.de avatar

Nie mehr komplizierte Passwörter! Mit könnt ihr endlich auf sie verzichten – die Einrichtung ist einfach und die basiert auf einem kryptografischen Verfahren. Mehr dazu: 👉 https://www.bsi.bund.de/dok/1107468

ljrk,
@ljrk@todon.eu avatar

@larma @TuxOnBike Nein, wie eben woanders beschrieben, kriegt man damit maximal Zugriff auf das verschlüsselte Backup, nicht auf den Key.

Und das Szenario ist gar nicht so theoretisch sondern Standardpraxis.

ljrk,
@ljrk@todon.eu avatar

@Ulrich @Proteus @bsi Das war auch nur ein Tippfehler meiner Seite – hätte FUD sein sollen :'D

protonprivacy,
@protonprivacy@mastodon.social avatar

By popular request, now supports — on all devices, for everyone.

Passkeys provide a secure and convenient alternative to passwords.

✨ Save, store and edit passkeys in Proton Pass.

https://proton.me/blog/proton-pass-passkeys

protonprivacy,
@protonprivacy@mastodon.social avatar

@bru We are fans of Firefox as well, and look forward to the submission to the extension store getting approved.

There are few services that actually replace the the password completely with a passkey, so you can log in as normal on Firefox until the new submission is approved.

protonprivacy,
@protonprivacy@mastodon.social avatar

@bru We can confirm that it's been approved now.

dominic, French

Les sont enfin désormais supportées par de @protonprivacy sur tous les appareils compatibles et les types de comptes (autant gratuits que payants). Ne manque plus que la possibilité de classer les données par dossiers ou étiquettes (labels).

https://www.lesnumeriques.com/appli-logiciel/proton-pass-integre-le-support-des-passkeys-sur-tous-les-appareils-n219742.html

dominic,

@protonprivacy Oh, it has been changed in the plan ? On last october it was 20 vault in paid plan, as it is said in this page for exemple : https://proton.me/blog/password-sharing

Thank you !

protonprivacy,
@protonprivacy@mastodon.social avatar

@dominic Yes, it's changed since about a month ago.

Belganon, French
@Belganon@mastodon.social avatar

, le gestionnaire de de @protonprivacy, prend désormais en charge les . Peu de sites utilisent déjà cette technologie, mais le nombre augmente de plus en plus. Une nouvelle couche de pour vos connections, plus performante et sûr que la

https://proton.me/blog/proton-pass-passkeys

protonprivacy,
@protonprivacy@mastodon.social avatar

@error_500 @Belganon Proton's encryption provides privacy by default - the content of your emails, files on Proton Drive, calendar, passwords on Proton Pass etc. remains inaccessible to us, and therefore we cannot share it with any third-parties, including law enforcement included. As any legally operating company, we have to comply to the local legislation, but no legal request can bypass the encryption we provide, which has been proved multiple times in court.

Belganon,
@Belganon@mastodon.social avatar

@protonprivacy @error_500 Merci pour vos précisions que je connaissaient déjà. Je suis et resterai un utilisateur «Unlimited» 😉

mjgardner,
@mjgardner@social.sdf.org avatar

Shots fired at @bitwarden: “And many #password managers only support #passkeys on specific platforms…”

When will we be able to create and use #Bitwarden passkeys outside of the browser extension? https://mastodon.social/@protonprivacy/112134037609531372

bitwarden,
@bitwarden@fosstodon.org avatar

@mjgardner Very soon!

We can't wait to share the next step of passkey implementation with the community. Here's a hint: mobile support is next! 🔑

floyd,

: reinventing TLS client certificate authentication that is proxyable and all private keys stored in the cloud and then of course the connection is only on one side TLS authenticated and therefore MITM-able from the other (aka proxyable, yes yes CAs and stuff but ya' know). Does this sound about right?

filippo,
@filippo@abyssdomain.expert avatar

@floyd Pretty much. The idea is that this might actually be usable enough to replace phishable bearer tokens, which nothing else succeeded at replacing so far. Usability has value.

cryptgoat, German
@cryptgoat@digitalcourage.social avatar

Die neue Version vom freien ist da und bringt neben vielen Detailverbesserungen Unterstützung für : https://keepassxc.org/blog/2024-03-10-2.7.7-released/

tuxwise,

2.7.7 released:

Don't be shy, @keepassxc - post about it, here, on Mastodon 😉

https://keepassxc.org/blog/2024-03-10-2.7.7-released/

  • All
  • Subscribed
  • Moderated
  • Favorites
  • passkeys
  • DreamBathrooms
  • everett
  • osvaldo12
  • magazineikmin
  • thenastyranch
  • rosin
  • normalnudes
  • Youngstown
  • Durango
  • slotface
  • ngwrru68w68
  • kavyap
  • mdbf
  • InstantRegret
  • JUstTest
  • ethstaker
  • GTA5RPClips
  • tacticalgear
  • Leos
  • anitta
  • modclub
  • khanakhh
  • cubers
  • cisconetworking
  • megavids
  • provamag3
  • tester
  • lostlight
  • All magazines