News: 1647874809

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

FIDO Alliance says it has finally killed the password

(2022/03/21)


There's a new proposal on eliminating passwords, but it relies on putting a lot of security eggs into OEM security baskets.

The FIDO Alliance has been trying to eliminate passwords since its inception in 2012. Ten years on it has yet to see that dream realized but the organization said it has finally come up with a mechanism that will, "for the first time be able to replace passwords as the dominant form of authentication on the internet."

FIDO has a long history of authentication innovation, being responsible for the USB hardware keys that were everywhere for a while (and are still used in many secure settings), as well as being part of the team (with W3C) that published the WebAuthn security specification.

[1]

Unfortunately, security implementations with extra bits (like physical keys) break what FIDO said is a key rule in the world of consumer products: "It has to 'just work' without requiring additional devices or inconveniences," the paper said. That goes for enterprise solutions as well – users won't take well to anything that makes their jobs more cumbersome.

[2]

[3]

It's to that end that FIDO announced, in partnership with W3C, a new version of WebAuthn that addresses the chains keeping the world bound to passwords.

FIDO's latest vision for passwordless

FIDO's new solution to the password problem has been staring us in the face, or rather we've been staring at it, for years: our smartphones.

"A smartphone is something that end-users typically already have. Virtually all consumer-space two-factor authentication mechanisms today already make use of the user's smartphone," FIDO said.

The alliance also pointed out that existing multi-factor security software is prone to phishing. One-time passwords can be entered into malicious sites, and login prompts don't necessarily distinguish between legitimate and fake sites. Ergo, we've gotta get rid of passwords altogether.

[4]

The smartphone's role in all of this is key, which means two things, according to FIDO. It needs to be a roaming authenticator, and the cryptographic identity bound to a particular device needs to be able to be relocated without requiring a password to do so.

[5]Would-be password-killer FIDO Alliance aims to boost uptake with new UX guidelines

[6]Password killer FIDO2 comes bounding into Azure Active Directory hybrid environments

[7]GitHub upgrades two-factor authentication with WebAuthn support

[8]Google shores up G Suite against hapless users in the enterprise: App whitelist, physical security keys, and more

This framework for passwordless authentication relies heavily on mobile devices, and thus also on the security of the underlying OS. That's by design, FIDO said.

"This shift from letting every service fend for themselves with their own password-based authentication system, to relying on the higher security of the platforms' authentication mechanisms, is how we can meaningfully reduce the internet's over-reliance on passwords at a massive scale," FIDO said.

The second component of the proposal, which would turn devices into roaming authenticators, requires Bluetooth, which would be used as a proximity logon protocol. This should come as no surprise to anyone familiar with FIDO's [9]previous work .

Bluetooth under this proposal would be used for both proximity-based authentication and to authenticate a new device, eliminating the need for passwords when switching to a new smartphone.

FIDO is putting your security in OEM hands

FIDO makes clear that the whitepaper detailing its proposal is not a change in its standards. Rather, "it is a change we expect authenticator vendors to make in their authenticator implementation," FIDO said.

The paper acknowledges that FIDO's proposal wouldn't necessarily boost security to [10]AAL3 levels, but said it would still be better than using plain passwords of phishable second factors. That may be the case, but a key question remains: will businesses be OK with trusting their security to an OEM?

[11]

FIDO cites Apple's adoption of " [12]Passkeys ," which use iOS biometrics and iCloud Keychain public keys to verify identities, as one example of its proposal in action. For supported apps, Passkeys are able to authenticate users without a password of any kind, not even one that iOS autofills in the background.

Time will tell if enterprises are willing to trust in Apple, Samsung, Microsoft, and the rest of Big Tech to be the ultimate arbiters of their organization's credentials. ®

Get our [13]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YjivQ4Mlat5narqOrI6JzwAAAM4&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YjivQ4Mlat5narqOrI6JzwAAAM4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YjivQ4Mlat5narqOrI6JzwAAAM4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YjivQ4Mlat5narqOrI6JzwAAAM4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2021/06/24/wouldbe_passwordkiller_fido_alliance_aims/

[6] https://www.theregister.com/2020/02/25/fido2_azure_ad_hybrid/

[7] https://www.theregister.com/2019/08/23/github_upgrades_its_twofactor_authentication_with_webauthn_support/

[8] https://www.theregister.com/2019/08/01/google_rolls_out_advanced_protection_beta_for_g_suite/

[9] https://fidoalliance.org/fido-alliance-equips-u2f-for-mobile-and-wireless-applications/

[10] https://pages.nist.gov/800-63-3-Implementation-Resources/63B/AAL/

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YjivQ4Mlat5narqOrI6JzwAAAM4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[12] https://developer.apple.com/documentation/authenticationservices/public-private_key_authentication/supporting_passkeys

[13] https://whitepapers.theregister.com/



So much fail

fredblogggs

'"A smartphone is something that end-users typically already have..."'

I don't. Know why? Because they're expensive and designed primarily to benefit carriers and manufacturers. They are riddled with buggy proprietary software and firmware and untrustworthy as all hell.

'This framework for passwordless authentication relies heavily on mobile devices, and thus also on the security of the underlying OS. That's by design, FIDO said.'

So it's broken by design, then.

It's not very difficult for a human of ordinary intelligence to examine a password and determine whether it's strong or weak. It's also not very difficult to avoid phishing attacks: block all email from people you don't trust, use a provider that enforces DKIM (most do) or do so yourself, use a plain-text MUA, type URIs instead of clicking links, and stop answering phone calls if you haven't already (99% of all phone calls are spam and/or scam). While this may not quite be enough if you are a spy or a CEO, it will suffice for the other 99.99% of us.

However, I defy anyone, even an expert in the field, to look at a USB dongle or smartphone and tell whether its authentication functionality is strong, weak, defective, or malicious. It basically can't be done, especially if the software and firmware are proprietary -- let's not even start on hardware -- so therefore this is a step backwards from passwords. And worse, the more trust is placed in such devices by upstream service providers like banks, the harder it will be to avoid the consequences of unknowingly using an insecure, defective, or malicious device for authentication. Oh well, your life savings are gone and you can't get them back. Good thing we have unlimited lives in which to start over!

I'll stick with my strong passwords in a physical notebook kept in a hidden safe, thanks. That's never failed me and I don't expect it ever will. If you won't let me use a password to authenticate myself, I'll take my business elsewhere.

Re: So much fail

DJO

Also many really high security establishments don't allow smartphones on site.

Smartphones are already a nice theft target, this would just make them more attractive to steal.

As for using Bluetooth... might as well use semaphore, it's about as secure.

I do not trust my smartphone

alain williams

and do not like biometrics (I cannot change my face).

Passwords work

Re: I do not trust my smartphone

b0llchit

(I cannot change my face)

I'd be happy to "change" your face for you. I have hammers and knives readily available. You may even pick the tools. Please leave me a message if you are interested in a price list for various levels of change.

--> Can do beauty adjustment too (see nurse' iconic image)

@b0llchit - Re: I do not trust my smartphone

Anonymous Coward

You're doing it for free ?

Re: @b0llchit - I do not trust my smartphone

b0llchit

The act of remodeling is free.

You do have to pay my hourly rate, the use of tools, my travel expenses and the paperwork (aka stay-out-of-jail papers).

Doctor Syntax

My first rule is to minimise the number of entities which I will trust. Apart from myself, who I usually do trust, that means entities which have earned my trust. So what do I make out of FIDO cites Apple's adoption of "Passkeys," ?

In the article that includes a link to documentation about Passkeys, at least that's what the link indicates. And it's a link that does nothing without javascript being enabled. Javascript, just to read documentation.

A body consisting of a list of the usual suspects offers as an example of what it's about something that requires javascript just to read what it's about? Of course I'm going to trust it. About as far as I can throw it.

@Doctor Syntax - Dear Doctor,

Anonymous Coward

All this is not being done for you. It's in their interest only.

The main idea here is for you to be identified even if you don't want it. With a USB key it takes a voluntary action for you to prove your identity. With a mobile phone tied to your identity and leaking information to whoever happens to want it, you're entirely out of the loop. You're no longer needed for their plan to work.

I find it frightening that all this is slowly overflowing from Internet realm to the rest of our real lives.

Seems I'm a bit slow today

Will Godfrey

Three commentards already covered all my concerns. Not happening here, that's for sure!

Re: Seems I'm a bit slow today

b0llchit

Stupid ideas need to be repeated often enough until everybody simply gives up complaining about the stupid idea.

That is how we introduce old new features that do not benefit the users in any way. It is also an effective way to take control away from the users. And, of course, get even more data about the users to (ab) use and empty their pockets a bit more in the process.

What is not to like?

2FA or begone!

binaryspiral

Password and a second method of authentication - both of which I can change and neither dependent on one entity (myself, OEM, or otherwise)...

This is garbage.

The way I read this...

msknight

Instead of the bad guys tying you to a chair, shining a light in your face and slapping you until you reveal your password... this way, they just tie you to the chair. Your watch will read your biometrics and squeal.

Or am I understanding this wrong?

Parent wakes up in the morning and the watch is on their wrist. Screams at child... "Johnny! What did you just buy on e-bay with daddy's ID?"

Microsoft already nailed this

cawfee

As someone who actively enabled passwordless auth on their Microsoft account - I'm an advocate for this.

Not only do I have to not worry about a password (even though I use 1password for everything else), it actively has 2FA built in: I log in > I get an auth prompt on my phone > I approve it > I have to select the correct number shown to me on my computer from the list > If I choose correctly it logs me in.

It's pretty simple and stops bots from trying to crack my password. If everyone else takes a leaf from the MS book, I'm here for it - one overarching auth platform.

But this is just one positive opinion against, I'm sure, plenty of people who would rather comment negatively than try :)

Re: Microsoft already nailed this

fredblogggs

What happens when you lose the phone, or someone steals it?

There are only two possibilities:

1. You're locked out forever. The good news is that the thief/attacker still has to guess your password. You chose a strong one, right?

2. There's some means of recovery without the "second factor", which is really just another way of saying that there's only one real factor.

Similar questions can be asked about what happens when (not if) you get SIM-swapped, or forget the password part. They all devolve to one of the two possibilities: either there's only one real factor, or you're locked out forever. Then what if both things happen? Authentication is about providing an actor's identity. How do you do that? What *is* identity, anyway? Is it the human being, or is it the device the human is using, or is it the credential(s)? Nothing in FIDO's, or Microsoft's, proposed solutions address these fundamental problems.

Re: Microsoft already nailed this

lostsomehwere

No, there is two factor authentication if you need to set up the app on a new phone, I did it recently and it easy enough to complete, but clearly had steps to validate identity.

This is for the general public and it's better than P455w%d1 , I too welcome it.

Mobile phone

tiggity

I have one, but would not trust it for "ID", or much at all really.

Don't use biometrics on it.

Don't have any apps installed on it that involve my financial details (not difficult as I do not do online or phone banking, and if I am going to make purchases online I will do it on my PC where I have a lot more control of being able to monitor for malicious activities and have various IP / JavaScript blocking / whitelist* tools in use) - no way I am doing it on a phone where anything could be going in under the hood.

In general use very few apps on the phone (hence I have a cheap and cheerful one)

Obviously I'm not "the norm" being FB, insta, tiktok etc lacking & generally (bar the odd game or listening to some music from the sd card I when stuck on a long & dreary public transport journey) just using phone for calls & texts

* apols for not using whatever is the PC phrase used for this these days

What's the fallback mechanism?

2+2=5

Smartphone luddites aside... in the real world people drop and break their phones.

So what's the fallback mechanism? How do you authenticate yourself to your bank and the phone store to buy a replacement phone? What's that Skippy: they just take their bank card to the phone store? But won't the bank then ping the banking app on the phone for approval?

What's that again Skippy? They'll know it's me because I'm their only customer that goes round talking to an imaginary kangaroo?

I've been saying they should do this for years

DS999

I sit here with my phone next to me, if I wanted to login to a web site my PC could connect to my phone via Bluetooth with a challenge it gets from the site. If I have authenticated myself to my phone in the manner I specify (could be Face ID, could be a fingerprint, could be a password) within the time limit I specify (so you don't need to re-auth yourself to login to a different site two minutes after you last authenticated yourself) the operating system forwards the challenge to the Secure Element (or Android equivalent) and receives a response it forwards via Bluetooth which your PC sends to the web site, logging you in.

The OS cannot compromise your security, the private keys allowing the challenge/response mechanism to work are in the Secure Element where the OS can't get to them. This would also be brand agnostic, it wouldn't matter if you had an iPhone, a Galaxy, a Pixel or a Chinese phone. It is simply taking advantage of a secure area of the SoC that the OS has limited ability to communicate with. Presumably someone would also sell dedicated dongle type devices that can perform only this function, for those who are paranoid Apple/Google will steal their Reg account, or don't own a smartphone but don't want to deal with passwords any longer.

So what happens if your phone is stolen? The thief would have to get into your phone, and then bypass the "FIDO" authentication you have set (before you can follow whatever process is defined for disabling FIDO) If you are paranoid, you could use a different method for that than for accessing the phone itself, so i.e. your phone uses Face ID but accessing FIDO uses a password that's different than your phone's password.

Yeah most people will just use Face ID or fingerprint for both, but this is still WAY more secure since only someone who steals their phone (and can jump through other hoops to fool their phone's biometrics) can exploit them, versus the situation today where half the world's population can potentially exploit them.

Oh my God!

heyrick

" A smartphone is something that end-users typically already have. "

Yes. And they get stolen, hacked, borrowed, and the issues regarding OS updates (or lack of them) is infamous.

" Virtually all consumer-space two-factor authentication mechanisms today already make use of the user's smartphone "

Wrong! With the partial exception of my bank, every single two factor jobbie except Google's pain in the arse "enter this number" that doesn't appear to work unless you're using Chrome... with the exception of that, everything sends me an SMS. So my phone number is the important part, not the phone type. I could be using an old Nokia... I forget the number, the famous feature phone one. And it would work.

I say partial for the bank, can as it wants you to authorise using their app. But after about thirty seconds it will offer to send a code via SMS instead.

" and thus also on the security of the underlying OS "

Count me out. My attitude towards the internet is "they're all out to get you", and sites that I feel I can trust are whitelisted (but all their third party resources are not). I don't believe in scanning to see if something is malicious, I believe in assuming it is until shown otherwise.

My phone as my single and sole method of authentication everywhere? Guys, April 1st is in a week and a half.

" is how we can meaningfully reduce the internet's over-reliance on passwords at a massive scale "

Are you willing to be held legally liable for when it goes horribly wrong? (notice I said when, not if)

You don't fix crap passwords and sites doing passwords badly by getting rid of all of them and using a single point of failure instead.

Plus, I have multiple identities that I use online. Oh, they're all "me" but the email address differs (depending on my level of trust when signing up). Will the phone authentication cope with that, or do you expect everybody to just hand over all of their private information "because authentication"?

" proximity-based authentication "

Why do I get a bad feeling about this? Oh, yes, something by the door of a shop will happily require you to login in order to benefit from all their special offers of the day. It's cool, it just happens automatically as you go in. Just don't ask what information they're busy extracting from you.

" but said it would still be better than using plain passwords of phishable second factors "

The thing is, passwords can be changed. Identities, only if you're of importance to the government...

" to be the ultimate arbiters of their organization's credentials "

They can't be trusted with what they currently have access to. Screw the idea of handing over more information.

Who are these people?

steelpillow

The FIDO Alliance is basically a bunch of platform creators and bankers.

Yay, the platform creators want to manage our online security for us. No surprise that the likes of Google, Apple and Microsoft want to control the keys to our lives.

The bankers want them to as well. No more being sued by ten million angry users because you let online crims steal their cash, now you just turn around and sue Google, Apple and Microsoft instead.

There are also a handful of governments, presumably hoping to move their currencies totally online and pretend they know what they are doing.

I really looked, but could not see one consumer group or user representative on the membership list.

"Let me guess, Ed. Pentescostal, right?"
-- Starcap'n Ra, ra@asuvax.asu.edu

"Nope. Charismatic (I think - I've given up on what all those pesky labels
mean)."
-- Ed Carp, erc@unisec.usi.com

"Same difference - all zeal and feel, averaging less than one working brain
cell per congregation. Starcap'n Ra, you pegged him. Good work!"
-- Kenn Barry, barry@eos.UUCP