Re: OT: Passkey usage
Tim via users <[email protected]>
| Newsgroups | gmane.linux.redhat.fedora.general |
|---|---|
| Organization | Me, organised? Are you kidding?! |
| Message-ID | <[email protected]> |
Tim: > > As long as the system isn't weak against replay of a certificate > > (something listens to yours, copies it, then sends the same thing > > to a bad system to impersonate you). It shouldn't be possible, > > there's supposed to be cross-checking, and maths that do something > > unique each time you use your credentials, but some badly designed > > systems have failed that way. Patrick O'Callaghan: > As the passkey is never sent over the wire, there's nothing to copy. > The server sends a unique one-time challenge which the device signs > using the private key. The server verifies the signature using the > stored public key in order to authenticate the device. The write-up I read mentioned a Microsoft server (no surprises) being vulnerable to a replay flaw. It didn't specify exactly what info was vulnerable. So, based on what you've said, the one-time challenge is probably the flaw (not being so "one-time"). At any rate, it's a complicated thing to get right, beyond many ordinary users. As a tangentially related thing - how many people use PGP with email? Ideally we all should, whether that be signing or encryption. But most do not. Most because it's not simple enough, some because they'd rather have less proof that *they* said something, and some because encryption would be forbidden in their country. Personally I'm not that concerned that a TLA could decrypt my messages since I'm not some kind of counter-revolutionary planning something, it's probably enough that some felon couldn't easily read a private message saying on what dates I would be out, or exploiting medical information. But if you're a whistleblower on government transgressions, you really do want actually secure messaging. > The potential weakness is when the private key store itself is not > secure. Ideally, it should be in a secure hardware enclave. e.g. a TPM > or similar on the device, or a hardware token such as a Yubikey, but > this makes it impossible to copy. Since people usually want to be able > to log in from multiple devices and no-one wants to have to register > each device independently, this creates a problem And as I mentioned, people being unaware of having to individually register each thing. Every attempt /that/ user had (even with technical support doing it for them) resulted in the newly registered device unregistering the previously registered device. The service provider was incompetent, and created chaos. -- uname -rsvp Linux 3.10.0-1160.119.1.el7.x86_64 #1 SMP Tue Jun 4 14:43:51 UTC 2024 x86_64 (yes, this is the output from uname for this PC when I posted) Boilerplate: All unexpected mail to my mailbox is automatically deleted. I will only get to see the messages that are posted to the mailing list. -- _______________________________________________ users mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/[email protected] Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new