Hacker News new | past | comments | ask | show | jobs | submit login

I'm just not going to participate in this. I don't want to use extra devices, second devices, anything like that. I'm just not interested. Thankfully there are enough people like me around that this will never achieve any sort of meaningful widespread use. I think it's a fine option for people who want it but I don't.



While roaming authenticators are indeed separate devices, platform authenticators aren't; they're built into your existing device. If you're using a MacBook, you already have a Secure Enclave which you access through TouchID.


The most obvious problem, though, is that it seems like you're out of luck on older/new/temporary/public/borrowed/reset/etc devices, which is a big change from just being able to log in wherever you need with just a secure password.


FIDO traded off convenience for security, and is incrementally building back usability features to what will hopefully be a more secure world. In particular, I'd be rather concerned about using passwords in most of the scenarios you describe where the OS is adversarial.

The FIDO Alliance made an announcement last week where major vendors commit to expanding support for multi-device FIDO credentials ("Passkeys") and using a phone as a roaming authenticator (This is admittedly another device). Both of which significantly mitigate your concerns without any security tradeoffs. See https://fidoalliance.org/apple-google-and-microsoft-commit-t...


How exactly are you bringing your "secure" passwords to the devices you mentioned? If the answer is "install and sync a password manager", that's something my mom will never do (short of having Chrome remember her password).

So either the passwords weren't secure, or we're only building for power users, or we're ossifying on the browser password manager (and keeping passwords) as the way to manage credentials.


I use a Thinkpad X220 with OpenBSD.


If you're on OpenBSD then you're likely a person that skews more towards security on a security/usability spectrum than the average person. May I ask why you'd prefer passwords or magic links over WebAuthn with something like a Yubikey that's permanently attached to your Thinkpad?


I don't want to use any dongles or anything. Maybe some day browsers will interface with fprintd, I have a fingerprint reader already which I trust.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: