Skip to content

Comment on Pass the Passkey: A Novel Attack Surface in Passwordless Authenticationparent

Comments

From account security POV, it is better to disallow backup or export passkeys. Each device should get their unique key.

This would be quite bad from usability or privacy pov, I guess.

It's ao comically bad it proves the while thing is a joke unless you're trusting Apple or Google to sync and back them up for you. One cynical angle at why the backup is being slow-rolled is because the major players have an incentive to not do it. They want you dependent on them and locked into their ecosystem.

It's completely insane to treat a credential to an account as something that cannot be backed up. It implies there's another form of recovery, which likely means that key is only as secure as the other recovery options. And when it comes all the way back to the master key to your manager itself the loop falls somewhat apart.

It's a hard problem, but passkeys aren't ready for me yet.

They want you dependent on them and locked into their ecosystem.

This is a strange conclusion to come to when clearly a lot of effort was put into developing an open standard (Credential Exchange Format) to make it easy and secure to move credentials between vendors/ecosystems, without opening end-users up to phishing attacks on credential export.

If big tech wanted to lock people in, it seems like it would have been a lot easier to just... not create an open standard.

Bug tech isn't a single entity. But I strongly believe a different group would have finished this obvious gap by now.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.