Rocksolid Light

Welcome to Rocksolid Light

mail  files  register  newsreader  groups  login

Message-ID:  

"There is such a fine line between genius and stupidity." -- David St. Hubbins, "Spinal Tap"


computers / misc.phone.mobile.iphone / Passkeys - transition

SubjectAuthor
* Passkeys - transitionAlan Browne
`* Re: Passkeys - transitionJolly Roger
 `- Re: Passkeys - transitionAlan Browne

1
Passkeys - transition

<ByaqN.215628$7sbb.35810@fx16.iad>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=11887&group=misc.phone.mobile.iphone#11887

  copy link   Newsgroups: comp.sys.mac.system misc.phone.mobile.iphone
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!usenet.blueworldhosting.com!diablo1.usenet.blueworldhosting.com!peer03.iad!feed-me.highwinds-media.com!news.highwinds-media.com!fx16.iad.POSTED!not-for-mail
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
Content-Language: en-US
Newsgroups: comp.sys.mac.system,misc.phone.mobile.iphone
From: bitbucket@blackhole.com (Alan Browne)
Subject: Passkeys - transition
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit
Lines: 35
Message-ID: <ByaqN.215628$7sbb.35810@fx16.iad>
X-Complaints-To: abuse@usenetserver.com
NNTP-Posting-Date: Thu, 18 Jan 2024 14:26:41 UTC
Organization: UsenetServer - www.usenetserver.com
Date: Thu, 18 Jan 2024 09:26:41 -0500
X-Received-Bytes: 2194
 by: Alan Browne - Thu, 18 Jan 2024 14:26 UTC

Starting to look at passkeys and have used the demo at
https://www.passkeys.io/

Haven't committed whole hog to it yet but will transition during 2024.
This is a part of my "abandoning the assholes of the rental software
economy", to whit: agilebits (1Password).

While passkeys don't absolutely replace passwords they do replace the
use of them. Thus, if one loses all of his devices (a house fire, for
example), the ability to log into, eg, Apple, provides for the recovery
of the passkey private/public keys. So - still need to remember ones
AppleID password.

(If that para seems bizarre, do note that passkeys is device oriented
and assumes only the proper owner of the device can open the device
based on biometrics, device specific password or PIN. So if one lost
all of their devices they would be locked out of their accounts - in the
case of Apple (and presumably others), the private/public key pair are
encrypted and saved with your AppleID).

A "cool" thing about it: I set up a passkey for the site above from my
Mac, and the private key was wrapped and securely shared with my other
devices. Thus, just using Face ID on my iPhone I could log in. Yeah,
that Apple Country Club experience. (Not sure how this is implemented
if one is Windows or Google "oriented", but there is surely a similar
mechanism).

Curious to know if others have begun using passkeys and with which sites.

<re-post - 1st try seems to have been lost>

--
โ€œMarkets can remain irrational longer than your can remain solvent.โ€
- John Maynard Keynes.

Re: Passkeys - transition

<l0u15uFo14pU1@mid.individual.net>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=11899&group=misc.phone.mobile.iphone#11899

  copy link   Newsgroups: comp.sys.mac.system misc.phone.mobile.iphone
Path: i2pn2.org!i2pn.org!usenet.network!news.neodome.net!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: jollyroger@pobox.com (Jolly Roger)
Newsgroups: comp.sys.mac.system,misc.phone.mobile.iphone
Subject: Re: Passkeys - transition
Date: 19 Jan 2024 01:22:06 GMT
Organization: People for the Ethical Treatment of Pirates
Lines: 40
Message-ID: <l0u15uFo14pU1@mid.individual.net>
References: <ByaqN.215628$7sbb.35810@fx16.iad>
Mime-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 8bit
X-Trace: individual.net 1IG6aETeCFSABabSnVKkhQjihwx27BIttULsSb5QrSnBwlEbiu
Cancel-Lock: sha1:aSTkpCx7FiBM8qrjRCmjHikijFE= sha256:KymorGMv53blaWooiSACCqv93vfetak6puJGbj/559s=
Mail-Copies-To: nobody
X-Face: _.g>n!a$f3/H3jA]>9pN55*5<`}Tud57>1<n@LQ!aZ7vLO_nWbK~@T'XIS0,oAJcU.qLM
dk/j8Udo?O"o9B9Jyx+ez2:B<nx(k3EdHnTvB]'eoVaR495,Rv~/vPa[e^JI+^h5Zk*i`Q;ezqDW<
ZFs6kmAJWZjOH\8[$$7jm,Ogw3C_%QM'|H6nygNGhhl+@}n30Nz(^vWo@h>Y%b|b-Y~()~\t,LZ3e
up1/bO{=-)
User-Agent: slrn/1.0.3 (Darwin)
 by: Jolly Roger - Fri, 19 Jan 2024 01:22 UTC

On 2024-01-18, Alan Browne <bitbucket@blackhole.com> wrote:
>
> Starting to look at passkeys and have used the demo at
> https://www.passkeys.io/
>
> Haven't committed whole hog to it yet but will transition during 2024.
> This is a part of my "abandoning the assholes of the rental software
> economy", to whit: agilebits (1Password).
>
> While passkeys don't absolutely replace passwords they do replace the
> use of them. Thus, if one loses all of his devices (a house fire, for
> example), the ability to log into, eg, Apple, provides for the
> recovery of the passkey private/public keys. So - still need to
> remember ones AppleID password.
>
> (If that para seems bizarre, do note that passkeys is device oriented
> and assumes only the proper owner of the device can open the device
> based on biometrics, device specific password or PIN. So if one lost
> all of their devices they would be locked out of their accounts - in
> the case of Apple (and presumably others), the private/public key pair
> are encrypted and saved with your AppleID).
>
> A "cool" thing about it: I set up a passkey for the site above from my
> Mac, and the private key was wrapped and securely shared with my other
> devices. Thus, just using Face ID on my iPhone I could log in. Yeah,
> that Apple Country Club experience. (Not sure how this is implemented
> if one is Windows or Google "oriented", but there is surely a similar
> mechanism).
>
> Curious to know if others have begun using passkeys and with which
> sites.

I've meaning to get round to doing this. Happy to learn from your
experience in the mean time. ๐Ÿ™‚๐Ÿ‘๐Ÿผ

--
E-mail sent to this address may be devoured by my ravenous SPAM filter.
I often ignore posts from Google. Use a real news client instead.

JR

Re: Passkeys - transition

<YYwqN.236901$c3Ea.209093@fx10.iad>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=11903&group=misc.phone.mobile.iphone#11903

  copy link   Newsgroups: comp.sys.mac.system misc.phone.mobile.iphone
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!npeer.as286.net!npeer-ng0.as286.net!peer03.ams1!peer.ams1.xlned.com!news.xlned.com!peer02.iad!feed-me.highwinds-media.com!news.highwinds-media.com!fx10.iad.POSTED!not-for-mail
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
Subject: Re: Passkeys - transition
Content-Language: en-US
Newsgroups: comp.sys.mac.system,misc.phone.mobile.iphone
References: <ByaqN.215628$7sbb.35810@fx16.iad>
<l0u15uFo14pU1@mid.individual.net>
From: bitbucket@blackhole.com (Alan Browne)
In-Reply-To: <l0u15uFo14pU1@mid.individual.net>
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit
Lines: 76
Message-ID: <YYwqN.236901$c3Ea.209093@fx10.iad>
X-Complaints-To: abuse@usenetserver.com
NNTP-Posting-Date: Fri, 19 Jan 2024 15:56:40 UTC
Organization: UsenetServer - www.usenetserver.com
Date: Fri, 19 Jan 2024 10:56:40 -0500
X-Received-Bytes: 3913
 by: Alan Browne - Fri, 19 Jan 2024 15:56 UTC

On 2024-01-18 20:22, Jolly Roger wrote:
> On 2024-01-18, Alan Browne <bitbucket@blackhole.com> wrote:
>>
>> Starting to look at passkeys and have used the demo at
>> https://www.passkeys.io/
>>
>> Haven't committed whole hog to it yet but will transition during 2024.
>> This is a part of my "abandoning the assholes of the rental software
>> economy", to whit: agilebits (1Password).
>>
>> While passkeys don't absolutely replace passwords they do replace the
>> use of them. Thus, if one loses all of his devices (a house fire, for
>> example), the ability to log into, eg, Apple, provides for the
>> recovery of the passkey private/public keys. So - still need to
>> remember ones AppleID password.
>>
>> (If that para seems bizarre, do note that passkeys is device oriented
>> and assumes only the proper owner of the device can open the device
>> based on biometrics, device specific password or PIN. So if one lost
>> all of their devices they would be locked out of their accounts - in
>> the case of Apple (and presumably others), the private/public key pair
>> are encrypted and saved with your AppleID).
>>
>> A "cool" thing about it: I set up a passkey for the site above from my
>> Mac, and the private key was wrapped and securely shared with my other
>> devices. Thus, just using Face ID on my iPhone I could log in. Yeah,
>> that Apple Country Club experience. (Not sure how this is implemented
>> if one is Windows or Google "oriented", but there is surely a similar
>> mechanism).
>>
>> Curious to know if others have begun using passkeys and with which
>> sites.
>
> I've meaning to get round to doing this. Happy to learn from your
> experience in the mean time. ๐Ÿ™‚๐Ÿ‘๐Ÿผ

Not a whole lot to say, so far.

- Amazon, works (Safari, Chrome / Mac, iPhone) - can turn off 2FA (need
to do this one-by-one for each browser, alas).

- Apple, doesn't work (as a sign in on the Apple sites (ID, Store)) but
it is set up for that eventuality if it occurs. OTOH, my Apple ID's
keychain is the repository for the Passkeys, so it's propagated
(securely) to my other devices.

- GitHub

- test site as mentioned

- My banks don't support Passkeys (yet?)

And of course since I use Passwords on my Mac, when I log into a known
site I get a prompt to use Passwords for the account username which of
course supplies (also) the site password. Sort of end-running the
purpose of Passkeys.

So - until this is all "burned in" as to habits, it's not paying off in
any great way (other than turning off 2FA on Amazon).

Not that many sites on board, alas:
https://www.passkeys.io/who-supports-passkeys

Offhand, people with a "password habit" are going to find transitioning
a little tedious as each site needs to be visited to set up the passkey,
which means (of course) using the current password (of course).

This isn't a sprint.
It's no marathon.
A walk would be faster.
.... crawl on...

--
โ€œMarkets can remain irrational longer than your can remain solvent.โ€
- John Maynard Keynes.

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor