• Optional@lemmy.world
    link
    fedilink
    English
    arrow-up
    21
    ·
    3 days ago

    And yet were almost immediately converted to local storage for adoption reasons. Per the article.

    • eleijeep@piefed.social
      link
      fedilink
      English
      arrow-up
      12
      ·
      3 days ago

      Yes, and it was a huge mistake, as a passkey stored on insecure media is effectively just a password with extra steps as far as the cryptographic guarantees are concerned.

      The argument that restricting them to secure devices such as TPMs would hurt adoption and prevent passkeys being migrated to other devices is a completely bogus one.

      Firstly, all consumer devices now ship with TPMs or a secure enclave equivalent, so the argument that users simply don’t have the hardware is no longer true. Even if it was true before, there’s no value in a software passkey when it can be just as easily stolen as a saved password or browser cookie.

      Secondly, the problem of migration has already (now) been solved by the FIDO spec writers and passkey migration has a well-defined protocol to support it. Moving to software implementations was never required to solve this problem.

      So why did they allow this to happen? In my view it started because the usual Big Tech suspects saw passkeys as an opportunity to enhance their ecosystem lock-in by adding another repository of important data that they manage for the user in their OS product, instead of it being a separate ecosystem managed by a piece of hardware that the user purchases such as a Yubikey.

      This is why the question of migration was expedited in the first place, not because migrating keys from secure devices is hard, but rather because people could see that vendor lock-in was going to occur with the software passkey implementations.

      • Optional@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        ·
        3 days ago

        So why did they allow this to happen? In my view it started because the usual Big Tech suspects saw passkeys as an opportunity to enhance their ecosystem lock-in by adding another repository of important data that they manage for the user in their OS product, instead of it being a separate ecosystem managed by a piece of hardware that the user purchases such as a Yubikey.

        Microsoft.