frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

UK rolls out passkeys across Gov.uk services

https://www.biometricupdate.com/202505/uk-govt-commits-to-passkeys-in-another-big-step-to-a-passwordless-world
19•giuliomagnifico•2h ago

Comments

coldpie•1h ago
I wrote about this here[1] but it seems like Passkeys are fundamentally incompatible with open source software. I tried them out, and was initially quite excited for them. But it turns out the spec has first-class support for banning passkey clients, which I feel makes the spec incompatible with open source software. The spec authors feel this is a good thing and regularly threaten open source software with bans for not following the spec, and they even maintain a list of non-compliant clients[2], which relying parties could use to ban clients that allow users to manage their own data how they wish instead of how the spec demands.

It's a pretty ugly situation, and I'm quite disappointed by this. It could've been a cool technology, but until they straighten out the story of whether users are allowed to own their own data, I cannot support it.

[1] I initially wrote this as a pro-Passkey article, explaining how the marketing around Passkeys is ludicrously confusing for what is actually a pretty simple tech. But then I found the spec authors threatening open-source implementations with bans and had to revoke my endorsement. https://www.smokingonabike.com/2025/01/04/passkey-marketing-...

[2] https://passkeys.dev/docs/reference/known-issues/

donmcronald•1h ago
> I suspect we’ll see [biometrics] required by regulation in some geo-regions.

I don't know a ton about the implementation, but the above or the “option” of requiring some kind of TPM or secure enclave worries me. I think it’s only a matter of time before a few select companies usurp control of identity.

Ultimately, I think we’ll be forced into subscriptions for authentication once government services are captured.

nand_gate•1h ago
Ugly indeed, hopefully a successor that is actually open can emerge.
coldpie•1h ago
I think all they need to do is remove attestation from the spec, or at least put very strong language around it that it should only be used for extremely secure environments where the data is not considered to be owned by the user, for example an account at your job. For end-user software, where they're currently promoting Passkeys, attestation is unacceptable. But, their behavior on the bug trackers indicates they don't even seem interested in having the conversation.
jerf•1h ago
An open successor is basically impossible at this point. Years and years.

What can happen is that the open source and "noncompliant" passkey implementations spread to the point that it becomes impractical to block them, or something that can only be deployed to internal security where an organization can control their authentication mechanisms tightly because they provide the authentication tokens to their employees, and regardless of what the spec writers think or want, the de facto spec simply diverges from the de jure spec. It's not like that hasn't happened to basically every spec ever.

The good news is, I think the market is going to pushed pretty heavily in this direction for a long time. Bitwarden right now provides pretty much exactly the experience I am looking for from passkeys; I auth with my tool, and as long as I am authed, it provides the passkey. It already has mechanisms for not staying logged in indefinitely and requiring periodic refreshes, and I think passkey mechanisms that involve people basically still having to authenticate every time are going to be systematically disfavored in the market to ones that don't. Passkeys are a legitimate advance if I can do one log in in the browser or my password manager and be logged in to all my sites without further intervention; they're actually a downgrade if I now have to go through the effort of setting up a passkey and also still authenticating every time I want to use one. Whether or not it is abstractly a good idea, you can't just spec your way to something like this in practice.

blibble•1h ago
I wouldn't worry about this too much, at least whilst the attestations in the spec remain anonymous

this necessitates sharing attestation signing keys between many devices

if someone starts banning non-trusted attestations then attackers will extract and leak yubikey's/microsoft's/... attestation signing keys

and which point anyone can sign whatever attestation they want

then the other side has to decide whether they lock out & ban thousands of innocent users, or accept the loss of control

coldpie•1h ago
> then the other side has to decide whether they lock out & ban thousands of innocent users, or accept the loss of control

My worry is more that relying parties will ban all providers except for (more or less) iOS and Android and Windows clients. That would cover probably 99% of users, but as a side-effect, effectively completely ban open source software from logging in to the service. It's not hard to see a well-meaning person flipping the switch to only allow big-name providers in the name of "security," especially given the existence of the spooky non-compliant list actively maintained by the spec authors.

It's true we could work around this by stealing the tokens from approved software, but I am extremely uninterested in having my authentication rely on stolen attestation tokens.

A brief history of the numeric keypad

https://www.doc.cc/articles/a-brief-history-of-the-numeric-keypad
1•ThomPete•51s ago•0 comments

App to Monitor Code Progress

https://github.com/txstc55/GMTU-Python
1•txstc55•4m ago•1 comments

Exploring Top AI Resume Builders; Five Unusual, Fun Careers That Pay Pretty Well

https://www.huddleandgo.work/ss
1•absinnovation•8m ago•1 comments

Rust Dependencies Scare Me

https://vincents.dev/blog/rust-dependencies-scare-me/?
2•vsgherzi•9m ago•1 comments

Nothing Radicalizes You Against Dirty Diesels Like Riding a Motorcycle

https://www.jalopnik.com/1852318/riding-motorcycle-radicalizes-against-dirty-diesels/
1•rntn•11m ago•0 comments

Show HN: I Built Cursor for CSV

https://www.tablab.app/csv/view
1•scottgpaulin•11m ago•0 comments

State of Docs Report 2025

https://www.stateofdocs.com/2025/
1•wayneshng•11m ago•0 comments

Claude Code: Anthropic's Agent in Your Terminal

https://www.latent.space/p/claude-code
1•swyx•13m ago•0 comments

Stability by Design

https://potetm.com/devtalk/stability-by-design.html
1•potetm•14m ago•0 comments

High-income groups disproportionately contribute to climate extremes

https://www.nature.com/articles/s41558-025-02325-x
2•colinprince•16m ago•0 comments

Show HN: Extension for full-text browser history search

https://rearview-ai.vercel.app/
7•ApbNfMR•17m ago•1 comments

5 Common Antipatterns in Payment Systems Design

https://news.alvaroduran.com/p/5-common-antipatterns-in-payment
1•ohduran•17m ago•0 comments

Bill Gates Accuses Elon Musk of 'Killing Children' by Cutting Foreign Aid

https://www.nytimes.com/2025/05/08/us/bill-gates-elon-musk-killing-children.html
4•breadwinner•19m ago•1 comments

Supporting Independent Businesses Should Be as Easy as Finding Starbucks

https://www.electro-app.com/home
2•piotrsirko•19m ago•0 comments

Engineers create a robot that can jump 10 feet high–without legs

https://techxplore.com/news/2025-04-robot-feet-high-legs.html
1•PaulHoule•21m ago•0 comments

$100K/day cloud bill isn't a Bug – it's by Design

https://old.reddit.com/r/aethernet/comments/1khyt39/100kday_cloud_bill_isnt_a_bug_its_by_design
1•todsacerdoti•21m ago•0 comments

Hard-Earned Lessons from 2 Years of Improving AI Applications

https://blog.ragas.io/hard-earned-lessons-from-2-years-of-improving-ai-applications
1•amrrs•22m ago•0 comments

Open Source SLM Trained for MCP

https://osmosis.ai/blog/applying-rl-mcp
3•KaseyZhang•23m ago•1 comments

Apple Says Google Searches Down on Safari and Google Says Searches Are Up

https://www.seroundtable.com/apple-vs-google-search-changes-39380.html
1•belter•24m ago•0 comments

Photo Library Export Tool for Mac

https://apps.apple.com/en/app/fotomediathek-export/id6741324048
1•HackerMichl•24m ago•0 comments

Structured Outputs by Example

https://structuredoutputsbyexamples.com/
1•jxnl•24m ago•0 comments

I built a meeting scheduler in a month, and it got 500 signups in 24 hours

https://www.warmcal.com
2•ac1990•25m ago•1 comments

Why Google Search Deal Is Critical for Firefox's Future

https://www.omgubuntu.co.uk/2025/05/mozilla-says-google-search-deal-vital-to-firefoxs-survival
1•StanAngeloff•27m ago•0 comments

Don't Look at Stock Markets. Look at the Ports

https://www.theatlantic.com/economy/archive/2025/05/trump-tariff-shipping-ports/682673/
3•paulpauper•29m ago•0 comments

Here’s How To Handle A Recession If The Job Market Were To Plummet

https://www.forbes.com/sites/eliamdur/2025/05/03/heres-how-to-handle-a-recession-if-the-job-market-were-to-plummet/
1•paulpauper•29m ago•0 comments

How to start a school with your friends

https://prigoose.substack.com/p/how-to-start-a-university
1•geverett•31m ago•1 comments

Details Avoid Bias

https://www.overcomingbias.com/p/details-avoid-bias
1•paulpauper•31m ago•0 comments

Fighting Unwanted Notifications with Machine Learning in Chrome

https://blog.chromium.org/2025/05/fighting-unwanted-notifications-with.html
2•feross•31m ago•0 comments

Level-5 CEO says games being made 80-90% by AI "aesthetic sense" a must for devs

https://automaton-media.com/en/news/level-5-ceo-says-games-are-now-being-made-80-90-by-ai-making-aesthetic-sense-a-must-for-developers/
1•msephton•33m ago•1 comments

QUIC restarts, slow problems: udpgrm to the rescue

https://blog.cloudflare.com/quic-restarts-slow-problems-udpgrm-to-the-rescue/
1•emot•42m ago•0 comments