Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Please, please, please stop using #passkeys to encrypt user data.

Please, please, please stop using #passkeys to encrypt user data.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
passkeys
10 Indlæg 6 Posters 12 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • timcappalli@infosec.exchangeT This user is from outside of this forum
    timcappalli@infosec.exchangeT This user is from outside of this forum
    timcappalli@infosec.exchange
    wrote sidst redigeret af
    #1

    Please, please, please stop using #passkeys to encrypt user data. Please 🙏🏻

    https://blog.timcappalli.me/p/passkeys-prf-warning/

    jasonkarns@indieweb.socialJ stf@chaos.socialS glyph@mastodon.socialG i@toot.pouyan.netI 4 Replies Last reply
    1
    0
    • timcappalli@infosec.exchangeT timcappalli@infosec.exchange

      Please, please, please stop using #passkeys to encrypt user data. Please 🙏🏻

      https://blog.timcappalli.me/p/passkeys-prf-warning/

      jasonkarns@indieweb.socialJ This user is from outside of this forum
      jasonkarns@indieweb.socialJ This user is from outside of this forum
      jasonkarns@indieweb.social
      wrote sidst redigeret af
      #2

      @timcappalli I think it’s even worse than this! Your do a great job explaining why it’s problematic for users who -don’t- know what’s happening (and also the increased risk of loss for everyone)

      But there are second order affects on -security-. A user who -knows- their passkey is encrypting their data must now keep that key much longer than they would otherwise need to. Auth keys should be safe for frequent rotation and replacement, which means keeping their scope tight.

      1 Reply Last reply
      0
      • timcappalli@infosec.exchangeT timcappalli@infosec.exchange

        Please, please, please stop using #passkeys to encrypt user data. Please 🙏🏻

        https://blog.timcappalli.me/p/passkeys-prf-warning/

        stf@chaos.socialS This user is from outside of this forum
        stf@chaos.socialS This user is from outside of this forum
        stf@chaos.social
        wrote sidst redigeret af
        #3

        @timcappalli isn't that what age is also pushing?

        timcappalli@infosec.exchangeT i@toot.pouyan.netI 2 Replies Last reply
        0
        • timcappalli@infosec.exchangeT timcappalli@infosec.exchange

          Please, please, please stop using #passkeys to encrypt user data. Please 🙏🏻

          https://blog.timcappalli.me/p/passkeys-prf-warning/

          glyph@mastodon.socialG This user is from outside of this forum
          glyph@mastodon.socialG This user is from outside of this forum
          glyph@mastodon.social
          wrote sidst redigeret af
          #4

          @timcappalli haha oops https://github.com/glyph/tokenring

          (I don't think this *quite* qualifies for what you're talking about, as anything speaking ctap2 directly is not quite in the same category as doing PRF in the browser)

          cthos@mastodon.cthos.devC 1 Reply Last reply
          0
          • stf@chaos.socialS stf@chaos.social

            @timcappalli isn't that what age is also pushing?

            timcappalli@infosec.exchangeT This user is from outside of this forum
            timcappalli@infosec.exchangeT This user is from outside of this forum
            timcappalli@infosec.exchange
            wrote sidst redigeret af
            #5

            @stf age?

            stf@chaos.socialS 1 Reply Last reply
            0
            • timcappalli@infosec.exchangeT timcappalli@infosec.exchange

              @stf age?

              stf@chaos.socialS This user is from outside of this forum
              stf@chaos.socialS This user is from outside of this forum
              stf@chaos.social
              wrote sidst redigeret af
              #6

              @timcappalli https://words.filippo.io/passkey-encryption/

              timcappalli@infosec.exchangeT 1 Reply Last reply
              0
              • stf@chaos.socialS stf@chaos.social

                @timcappalli https://words.filippo.io/passkey-encryption/

                timcappalli@infosec.exchangeT This user is from outside of this forum
                timcappalli@infosec.exchangeT This user is from outside of this forum
                timcappalli@infosec.exchange
                wrote sidst redigeret af
                #7

                @stf oh, that. yes.

                1 Reply Last reply
                0
                • timcappalli@infosec.exchangeT timcappalli@infosec.exchange

                  Please, please, please stop using #passkeys to encrypt user data. Please 🙏🏻

                  https://blog.timcappalli.me/p/passkeys-prf-warning/

                  i@toot.pouyan.netI This user is from outside of this forum
                  i@toot.pouyan.netI This user is from outside of this forum
                  i@toot.pouyan.net
                  wrote sidst redigeret af
                  #8
                  @timcappalli@infosec.exchange To add to the arguments: it also defeats the whole idea of having hardware security keys. If the secret is stolen or exposed somehow, decryption does not require access to the hardware token anymore.
                  1 Reply Last reply
                  0
                  • stf@chaos.socialS stf@chaos.social

                    @timcappalli isn't that what age is also pushing?

                    i@toot.pouyan.netI This user is from outside of this forum
                    i@toot.pouyan.netI This user is from outside of this forum
                    i@toot.pouyan.net
                    wrote sidst redigeret af
                    #9
                    @stf@chaos.social I just recalled that confer (LLM by moxie and co) is also using passkeys for encryption:

                    https://confer.to/blog/2025/12/passkey-encryption/

                    @timcappalli@infosec.exchange
                    1 Reply Last reply
                    0
                    • glyph@mastodon.socialG glyph@mastodon.social

                      @timcappalli haha oops https://github.com/glyph/tokenring

                      (I don't think this *quite* qualifies for what you're talking about, as anything speaking ctap2 directly is not quite in the same category as doing PRF in the browser)

                      cthos@mastodon.cthos.devC This user is from outside of this forum
                      cthos@mastodon.cthos.devC This user is from outside of this forum
                      cthos@mastodon.cthos.dev
                      wrote sidst redigeret af
                      #10

                      @glyph you’re also setting the explicit expectation that the hardware token is required for access. Which is not the same as “whoops we added another confusing thing to your passkey”

                      1 Reply Last reply
                      0
                      • jeppe@uddannelse.socialJ jeppe@uddannelse.social shared this topic
                      Svar
                      • Svar som emne
                      Login for at svare
                      • Ældste til nyeste
                      • Nyeste til ældste
                      • Most Votes


                      • Log ind

                      • Har du ikke en konto? Tilmeld

                      • Login or register to search.
                      Powered by NodeBB Contributors
                      Graciously hosted by data.coop
                      • First post
                        Last post
                      0
                      • Hjem
                      • Seneste
                      • Etiketter
                      • Populære
                      • Verden
                      • Bruger
                      • Grupper