logoalt Hacker News

helix90today at 3:22 PM3 repliesview on HN

Listening to Yubikey and OnePassword talk about this, they actually say "One Person, One Device". Which really speaks to their failure to understand their users.


Replies

thewebguydtoday at 3:57 PM

Because the original FIDO/WebAuthn standard was built for device bound credentials. They imagined unique keypairs tied strictly to a specific piece of hardware. Synced passkeys were a compromise, mostly driven by Apple and Google, because per-device credentials are too much friction for general use. It's not that they failed to understand users, it's that they incorrectly assumed the level of inconvenience people are willing to tolerate to be textbook secure (the answer is almost zero inconvenience).

The device bound model also completely falls apart in the enterprise, fails to address shared devices and shift workers where employees share the same PC under the same OS profile, now you're back to needing good old fashioned SSO w/ physical MFA (Yubikey) to attest who the user is in addition to attesting the device itself.

Before synced passkeys, the actual standard is a unique key pair per device. The key pair on my phone shouldn't be synced to my laptop, my laptop should generate it's own key pair.

astrospectivetoday at 4:14 PM

That is odd, I regularly use my Yubikey on multiple devices, that was the biggest draw.

show 1 reply
gortoktoday at 3:25 PM

I would love to see what you’re referencing, can you provide a link or citation to that quote?

show 1 reply