• RustyNova@lemmy.world
    link
    fedilink
    arrow-up
    103
    arrow-down
    7
    ·
    3 months ago

    I kinda hate the push towards passkeys. If you have two factor Auth, going to passkeys makes you go back to 1 factor, aka less secured.

    There’s also more and more 2FA fatigue attacks going on, and they can affect passkeys too, and if you don’t have a 2FA that involves the user writing a code on the 2FA device, passkeys could be quite possibly worse than passwords

      • jonjuan@programming.dev
        link
        fedilink
        English
        arrow-up
        35
        arrow-down
        2
        ·
        3 months ago

        encrypt them with a password if you wish.

        SSH keys without passphrases are just fancy credential files sitting in your .ssh/ directory, basically like writing your passwords on paper and leaving it in your desk drawer.

        • ThunderQueen@lemmy.world
          link
          fedilink
          arrow-up
          6
          arrow-down
          1
          ·
          3 months ago

          I had mine on paper for years before i learned about Keepass. I trusted it more than a cloud based manager because someone would have to physically be in my room.

          I am a lot more careful these days but that is not beyond the pale for a lot of folks haha

      • Evotech@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        3 months ago

        It’s not about encryption/security it’s about creating something that can’t be phished.

        We know that 2fa is secure. But if an attacker can trick you into giving them the code, or typing it in a fake box. Then they own you.

        Passkeys are made so that there’s nothing to give, nothing to type. You must control the device.

    • YtA4QCam2A9j7EfTgHrH@infosec.pub
      link
      fedilink
      arrow-up
      16
      arrow-down
      2
      ·
      3 months ago

      Yeah. Passkeys are something I would love if they were a second factor because they are so much better than any other 2fa. And I use my yubikeys as second factors where I can. But why the hell would I not want a password too?

      • nialv7@lemmy.world
        link
        fedilink
        arrow-up
        10
        ·
        3 months ago

        Passkeys are always supposed to be protected by another layer of authentication. e.g. a password should be required to unlock the passkey. If your passkey don’t do that, stop using it.

      • jj4211@lemmy.world
        link
        fedilink
        arrow-up
        7
        arrow-down
        1
        ·
        3 months ago

        If I provide passkey support and still require a password, most users will get annoyed and not bother. If I provide it as a replacement for password, then I can get them onboard more often. I’d rather have them using passkey than sticking with password.

    • nialv7@lemmy.world
      link
      fedilink
      arrow-up
      11
      ·
      3 months ago

      It’s different. It’s still two factors if implemented correctly: 1. Possession of the passkey (better if you have a physical token, but passkey on your phone is passable). 2. Knowledge of your password (or bio authentication if you use face id or w/e).

      Note you are not giving your password to the website, and if a hacker gets hold of your password they still can’t do anything without your passkey device.

        • nialv7@lemmy.world
          link
          fedilink
          arrow-up
          11
          ·
          3 months ago

          Passkey should ask for a password for unlocking. If it doesn’t then it’s not implemented correctly.

          • jj4211@lemmy.world
            link
            fedilink
            arrow-up
            6
            ·
            3 months ago

            It’s client specific and my phone requires whatever can unlock the phone and chrome requires either windows hello or a pin if under linux.

            Certain implementations do whatever, and as far as the backend is concerned, there’s no way of knowing, unless you want to get into the business of locking down specific vendor keys…

            But I say MFA is overrated versus just getting away from generally crappy password factors. Also passkeys are less phish-able than OTP type solutions.

            • nialv7@lemmy.world
              link
              fedilink
              arrow-up
              2
              ·
              3 months ago

              Yes, it’s implementation specific, in this case your phone, or your browser is the passkey “device”. And as long as it’s protected by some form of authentication it’s OK (though I would recommend a hardware token over phones/browsers). If it doesn’t then you shouldn’t be using that “passkey”. Yes, there is no way for the website you are authenticating with to know whether your passkey is safe or not, choosing a secure passkey implementation is (unfortunately) the user’s job. But it’s the same with more traditional 2FAs, e.g. you can store your TOTP secret securely or insecurely, and the website will have no way to know.

      • twice_hatch@midwest.social
        link
        fedilink
        English
        arrow-up
        4
        arrow-down
        1
        ·
        3 months ago

        You are supposed to have two redundant ones. Hooked up to every service. One leaves the house with you, the other stays in a safe, and you rotate them periodically

        and nobody is gonna fucking do that lol

        Mine are USB-A and USB-C so no two computers can use both. One of them randomly quit working (something in the OS dropped support for it maybe?) but then I think started working again?

        At an old job I had a lot of control over my own infra and I used my HSM to log in to my forge. I haven’t used it daily in years now.

  • BootLoop@sh.itjust.works
    link
    fedilink
    arrow-up
    32
    ·
    3 months ago

    If this isn’t referring to the Git CLI that prompts the user for username and password for a GitHub remote repository and GitHub rejecting password auth, then disregard this rant.

    Git and GitHub are two seperate pieces of software. Git is the local client that does all the work and can optionally sync with a remote repository that can be stored in GitHub or GitLab or any other compatible remote. When Git asks for a password to authenticate, it has nothing to do with GitHub. GitHub then rejects that authentication method that Git provided because it believes that the method is insecure.

  • ohellidk@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    14
    arrow-down
    2
    ·
    3 months ago

    Still using Github, the American company owned by Micro$oft, known for deleting repos? I’d consider switching away from them. Of you’re able to.

  • philosloppy@lemmy.world
    link
    fedilink
    arrow-up
    10
    ·
    3 months ago

    I don’t know anything about passkeys but if Microsoft is pushing for them I am immediately suspicious. I am admittedly paranoid but if you have been an adult using a computer over the past ~15 years and aren’t paranoid you haven’t been paying enough attention

    • twice_hatch@midwest.social
      link
      fedilink
      English
      arrow-up
      1
      ·
      3 months ago

      If by “passkey” they mean an HSM I’m okay with it

      I’d still rather have TOTP as my 2nd factor so I don’t have to plug shit in

      • philosloppy@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        3 months ago

        TOTP is the superior option, IMO, but I’m no expert on security so maybe they’re insecure? it sure seems like some folks would rather do anything but time-based onetimes.

        hardware keys are a pain in the neck, just one more thing to be lost.

      • JackbyDev@programming.dev
        link
        fedilink
        English
        arrow-up
        1
        ·
        3 months ago

        I’ve plugged my phone in so many times and it doesn’t detect shit. I’d rather stick with totp/email.

    • dai@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      3 months ago

      My passkeys are stored in keypass, which I share between multiple devices. Phone, home servers, desktop pc and a flashdrive that stays in my car.

      Obviously the flash drive needs to be manually updated but the other devices use syncthing to keep everything up to date.

      I get there are some people that have concerns over such a configuration but I’m happy bopping away knowing that if my phone dies, I’ve still got access to accounts / can easily be back up and running on a fresh device.