• becausechemistry@piefed.social
    link
    fedilink
    English
    arrow-up
    63
    ·
    2 days ago

    What a terrible headline.

    Better: “Windows has such terrible security architecture that a compromised application can steal a user’s passwords, passkeys, and literally anything else.”

      • Optional@lemmy.world
        link
        fedilink
        English
        arrow-up
        21
        ·
        2 days ago

        And yet were almost immediately converted to local storage for adoption reasons. Per the article.

        • eleijeep@piefed.social
          link
          fedilink
          English
          arrow-up
          12
          ·
          2 days ago

          Yes, and it was a huge mistake, as a passkey stored on insecure media is effectively just a password with extra steps as far as the cryptographic guarantees are concerned.

          The argument that restricting them to secure devices such as TPMs would hurt adoption and prevent passkeys being migrated to other devices is a completely bogus one.

          Firstly, all consumer devices now ship with TPMs or a secure enclave equivalent, so the argument that users simply don’t have the hardware is no longer true. Even if it was true before, there’s no value in a software passkey when it can be just as easily stolen as a saved password or browser cookie.

          Secondly, the problem of migration has already (now) been solved by the FIDO spec writers and passkey migration has a well-defined protocol to support it. Moving to software implementations was never required to solve this problem.

          So why did they allow this to happen? In my view it started because the usual Big Tech suspects saw passkeys as an opportunity to enhance their ecosystem lock-in by adding another repository of important data that they manage for the user in their OS product, instead of it being a separate ecosystem managed by a piece of hardware that the user purchases such as a Yubikey.

          This is why the question of migration was expedited in the first place, not because migrating keys from secure devices is hard, but rather because people could see that vendor lock-in was going to occur with the software passkey implementations.

          • Optional@lemmy.world
            link
            fedilink
            English
            arrow-up
            4
            ·
            2 days ago

            So why did they allow this to happen? In my view it started because the usual Big Tech suspects saw passkeys as an opportunity to enhance their ecosystem lock-in by adding another repository of important data that they manage for the user in their OS product, instead of it being a separate ecosystem managed by a piece of hardware that the user purchases such as a Yubikey.

            Microsoft.

  • Optional@lemmy.world
    link
    fedilink
    English
    arrow-up
    31
    ·
    2 days ago

    Malware installed on a device running macOS, iOS, and Android, for instance, has no ability to defeat this isolation unless the OS itself is compromised through some sort of exotic zero-day exploit. So far, these assumptions have been proven correct in real-world practice.

    The lone exception is Windows.

    Mmmmm.

    • unskilled5117@feddit.org
      link
      fedilink
      English
      arrow-up
      1
      ·
      11 hours ago

      From my understanding it is the same on linux though, theres no sandbox preventing an app or malware from accessing anothers app data

  • m-p{3}@lemmy.ca
    link
    fedilink
    English
    arrow-up
    40
    ·
    3 days ago

    IMO storing Passkeys in Google Password Manager is a bad idea in general.

    • Samsy@lemmy.ml
      link
      fedilink
      English
      arrow-up
      32
      ·
      3 days ago

      IMO storing Passkeys in Google Password Manager is a bad idea in general.

      I’ve adjusted it

    • Zak@lemmy.world
      link
      fedilink
      English
      arrow-up
      24
      ·
      3 days ago

      Using a big tech option for something like a password manager is a bad idea in general. Eggs, baskets, etc…

  • warm@kbin.earth
    link
    fedilink
    arrow-up
    13
    ·
    2 days ago

    It’s nothing then that hasn’t already existed basically. You have to store the passkeys somewhere and somehow, but when your whole system is compromised, then your passkeys, like your passwords in managers can be compromised too.