Hacker News new | ask | show | jobs
by helix90 10 days ago
Listening to Yubikey and OnePassword talk about this, they actually say "One Person, One Device". Which really speaks to their failure to understand their users.
3 comments

Because the original FIDO/WebAuthn standard was built for device bound credentials. They imagined unique keypairs tied strictly to a specific piece of hardware. Synced passkeys were a compromise, mostly driven by Apple and Google, because per-device credentials are too much friction for general use. It's not that they failed to understand users, it's that they incorrectly assumed the level of inconvenience people are willing to tolerate to be textbook secure (the answer is almost zero inconvenience).

The device bound model also completely falls apart in the enterprise, fails to address shared devices and shift workers where employees share the same PC under the same OS profile, now you're back to needing good old fashioned SSO w/ physical MFA (Yubikey) to attest who the user is in addition to attesting the device itself.

Before synced passkeys, the actual standard is a unique key pair per device. The key pair on my phone shouldn't be synced to my laptop, my laptop should generate it's own key pair.

I would love to see what you’re referencing, can you provide a link or citation to that quote?
the video requires signing up for Yubikey spam. https://app.livestorm.co/yubico-y/securing-trusted-actions-a...
That is odd, I regularly use my Yubikey on multiple devices, that was the biggest draw.
The Yubikey is the "one device". But most people don't buy Yubikeys so the "one device" is, in practice, a smartphone.
Even then, unless you use one for work, where work can issue you a new one if you lose it, you're going to need (at least) two Yubikeys if you want to go that route, because not having a backup is a bad idea.