Ask HN: Why is WebAuthn so sluggish to take off?
by Phil Tadros
April 23, 2023

2023-04-23 07:09:56
![]() |
|
Passkeys is a new FIDO standard that will let the private keystore be backed by the cloud. It was added to WebAuthn fairly recently. Having keys tied to specific physical devices was a terrible & frustratingly limited scheme that never had any hope. Now that there’s something a little bit looser, there’s some small hope WebAuthn starts to become interesting & viable. https://developer.chrome.com/blog/webauthn-conditional-ui/
One other big problem is that there are so very some ways for builders to make use of this tech. There are a really humbling quantity of eventualities & flows one can set-up. Lots of the most direct paths proceed to have the consumer already arrange an account through common electronic mail/password, so customers nonetheless find yourself doing the identical account administration in any case. I am lacking the hyperlink to the great great information I spent a pair commute rides studying, but it surely was one of many longest most technical items I’ve learn in fairly some time. “Introducing the WebAuthn API” is probably a fairly okay substitute. https://medium.com/webauthnworks/introduction-to-webauthn-ap… |
![]() |
|
That makes sense (as long as device asks for PIN every time you use webauthn). Bank card uses the same logic: you present both card and PIN code and it counts as two factors.
|
![]() |
|
I think it’s because it’s a pain to have one key per device. To solve this, you’d need a service like iCloud Keychain (for Apple devices), but that only works for Safari and other Apple stuff. I think once 3rd party apps (like 1Password – see https://www.future.1password.com/) begin supporting the syncing of keys, you may see extra use. Alternatively, should you might use iCloud Keychain with Chrome and Firefox, possibly that may work, too. Wanting ahead to this future!
|
![]() |
|
Please, if you back with Ally bank, email them and tell them you want Webauthn, not SMS. Ask to have the email forwarded to the head of development.
Please and thank you. |
![]() |
|
We use it at work and for whatever reason every time I get it working one one device, it stops working on another. That and it seems to be fragile across the VPN.
|
![]() |
|
What does WebAuthn on Firefox on Linux look like? I got the impression it was impossible to use without a blessed bigco device and browser.
|
What's Your Reaction?
Excited
0
Happy
0
In Love
0
Not Sure
0
Silly
0