Re: OT: Passkey usage

Tim via users <[email protected]>
Newsgroups gmane.linux.redhat.fedora.general
Organization Me, organised? Are you kidding?!
Message-ID <[email protected]>
Robert McBroom:
> > Lots of sites are promoting the use of a generated passkey vs a 
> > password. Some mention of using a passkey generated for site A on site 
> > B. Seems to be tied to the device. How is this better than a password?

Samuel Sieb:
> It's more secure in some ways.

                      ^^^^

Of course that is all moot if the site has really dumb ideas about
password/credential resets that lets unauthorised people abuse it, and
many do.

> > Doesn't seem to be as useful as a password generator and keeper. The 
> > mechanism for using a passkey on multiple devices is not clear.

> You generally can't.

This is one area where it becomes a real pain, and I'll give you a
real-world example:

The biggest service provider in Australia, Telstra, decided to require
passkeys generated by them for email.  *And*, every different device,
every different application (even on the same device), requires a
unique passkey to access your mail.  Not that they told their users,
nor their support staff.  You can't create your own passkey, so you
could make something that you can remember or be able to type, only
their pseudo-random thing (that can be another failure, if someone
figures out how non-random their generator is).

The generator is buried in an odd place in their webmail app that you
have to go hunting for.  You have to trigger it off, then copy and
paste it into the application you want to authorise *IF* *YOU* *CAN*
(try doing that on some mobile phones and it's damn hard, not to
mention that some people don't know how to).  Or, you have to retype a
lengthy lot of nonsense that's hard to type (remember many of the
symbols are hidden on mobile phone on-screen keyboards, and there's
various characters that are hard to tell apart on their stupid choice
of font, the classic il1| mess is there, as well as 0 versus O).

So this lady takes her phone and laptop to Telstra's shop for in-person 
help in getting her email working again.  They can only get mail
working on one thing at a time, every time they set one device up, it
nobbles the other, and they do not know why.

Then she comes to see me.  First I have to figure out what the problem
really is (not too hard, it was a moment of guesswork as to the reason,
but more trouble about actually managing it), then spend a ridiculous
amount of time going through each application setting up new passkeys
for each of them.  Made worse by some *crappy* phone apps not letting
you change a password.  You had to erase the account (probably losing
all your mail), then start afresh.

Of course the different pass per thing negates the point of a
centralised password manager (something I don't like as vendor lock-in, 
and single-point of failure, not to mention difficulty of use for non-
technical people, especially choosing which out of 5 passkeys to pick
from it for the one service), so for minimum pain each thing has to
store the passkey within itself (something that a lot of security
people vehemently advise against).

Colour me unimpressed!

Ignoring the mammoth pain and timewasting involved.  If someone can
work out their not-actually-random generator coding, that's a security
flaw.  If someone can work out a way around their detection that you're
using a different thing that needs its own passkey (and don't say
that's impossible), there's now several passes to the same account that
might be crackable - and there's plenty of services that still,
stupidly, allow people to do numerous failed connection attempts
without restriction.  Not to mention that for the other services that
do lock you out after 3 failed attempts, if they don't do that with
intelligence (i.e. distinguish between attempts from around the world
versus you directly connected to them on their network), repeated
attempts to crack your account by someone else locks you out of your
account.

Security is always a pain, and some organisations make it a nightmare.

-- 
 
uname -rsvp
Linux 3.10.0-1160.119.1.el7.x86_64 #1 SMP Tue Jun 4 14:43:51 UTC 2024 x86_64
(yes, this is the output from uname for this PC when I posted)
 
Boilerplate:  All unexpected mail to my mailbox is automatically deleted.
I will only get to see the messages that are posted to the mailing list.
 

-- 
_______________________________________________
users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.