#passkeyrisks — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #passkeyrisks, aggregated by home.social.
-
@emilion in https://infosec.exchange/@emilion/116595960854703567: you misunderstand me. My point is that Scott's article is yet another one in long row that reads like an advertisement.
I am not insisting that FIDO or whatever organisation fixes things (regardless whether that is something they can do or not): I am asking for USEFUL information for users to evaluate advantages and their risks.
A similar example: #TOTP was (and still is) being heavily promoted because people use (and reuse) extremely weak passwords. TOTP does *NOT* fix that problem (apart from the shit that we got, e.g. today's https://www.heise.de/en/news/Microsoft-Authenticator-Critical-vulnerability-allows-token-theft-11296758.html).
Effectively people are told to use a password manager (the TOTP app) to fix ANOTHER problem, and nobody tells them to make backups of shared secrets (leading to account lockout).#Phishing is likely the biggest problem on the Internet, while TOTP does not fix that (and no, #Evilginx is no longer considered a "sophisticated" attack, from 2019: https://techcommunity.microsoft.com/blog/microsoft-entra-blog/all-your-creds-are-belong-to-us/855124).
People who lose trust in security-pro's who state "just use this tech, it's great" are right. We need to do a better job.
#Passkeys #PasskeyRisks #Passwords #PasswordRisks #PasswordManager #AuthenicatorApps #MicrosoftAuthenticator
-
@ScottHelme : why do security people not mention any disadvantages of authentication mechanisms, and even lie about certain aspects?
"private key never leaves your device": if this were true, then a bricked, lost, stolen or simply replaced device by a new one, would mean that the user loses access to all of their passkeys on the former device.
"no password to steal": session cookies continue to be stealable.
"stops phishing attacks": not while *creating* a passkey, not when an attacker manages to obtain a valid certificate for a site with the particular domain name and is able to send visitors there, and in specific cases using subdomains and faulty server webauthn implementations.
"Your device now knows where your passkey can be used, and it will not let you use it anywhere else, which is a protection that can't be offered for passwords": it *can* (but is uncommon, it beats me why).
"The public key […] here isn't an additional piece of sensitive information in there to be compromised and all the attacker has managed to gain access to is the public key of the user": in case of a server breach, the attacker can add their own passkey public key or replace yours.
Please stop misleading people (like happened with TOTP).
#Passkeys #PasskeyRisks #VendorLockIn #TOTP #Passwords #Passkey