{"id":9830,"date":"2024-12-19T12:12:59","date_gmt":"2024-12-19T19:12:59","guid":{"rendered":"https:\/\/jasonsblog.ddns.net\/?p=9830"},"modified":"2024-12-19T12:14:06","modified_gmt":"2024-12-19T19:14:06","slug":"microsoft-wont-let-customers-opt-out-of-passkey-push","status":"publish","type":"post","link":"https:\/\/jasonsblog.ddns.net\/index.php\/2024\/12\/19\/microsoft-wont-let-customers-opt-out-of-passkey-push\/","title":{"rendered":"Microsoft Won\u2019t Let Customers Opt Out of Passkey Push"},"content":{"rendered":"\n<p>According to Microsoft&#8217;s website, this can be a face scan, fingerprint or pin. From the wording in the article below, they might be taking Authenticator PINs or maybe FIDO keys. Normally such things are used as a second factor to go along with a password, but they&#8217;re moving towards the only thing being needed. Seems like a play to make devices easier to get into for law enforcement and the government as opposed to being a security measure. I use FIDO keys for second factor authentication with some services that support it, but I still need my password, so physical possession of the key alone won&#8217;t get you in.<\/p>\n\n\n\n<p><a href=\"https:\/\/www.theregister.com\/2024\/12\/18\/microsoft_passkey_push\/\">https:\/\/www.theregister.com\/2024\/12\/18\/microsoft_passkey_push\/<\/a><\/p>\n\n\n<div class=\"wp-block-ub-divider ub_divider ub-divider-orientation-horizontal\" id=\"ub_divider_ddc1c079-b773-41de-b5ac-15c704f9ba23\"><div class=\"ub_divider_wrapper\" style=\"position: relative; margin-bottom: 2px; width: 100%; height: 2px; \" data-divider-alignment=\"center\"><div class=\"ub_divider_line\" style=\"border-top: 2px solid #ccc; margin-top: 2px; \"><\/div><\/div><\/div>\n\n\n<h5 class=\"wp-block-heading\">Enrollment invitations will continue until security improves<\/h5>\n\n\n\n<p>Microsoft last week lauded the success of its efforts to convince customers to use passkeys instead of passwords, without actually quantifying that success.<\/p>\n\n\n\n<p>The software megalith credits passkey adoption to its enrolment user experience, or UX, which owes its unspecified uptake to unavoidable passkey solicitations \u2013 sometimes referred to as &#8220;nudges.&#8221;<\/p>\n\n\n\n<p>&#8220;We&#8217;re implementing logic that determines how often to show a nudge so as not to overwhelm users, but we don&#8217;t let them permanently opt out of passkey invitations,&#8221; explained Sangeeta Ranjit, group product manager, and Scott Bingham, principal product manager, in a <a target=\"_blank\" rel=\"noreferrer noopener\" href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2024\/12\/12\/convincing-a-billion-users-to-love-passkeys-ux-design-insights-from-microsoft-to-boost-adoption-and-security\/\">blog post<\/a>.<\/p>\n\n\n\n<p>The corporation&#8217;s onboarding strategy seems to suit its corporate address: One Microsoft Way.<\/p>\n\n\n\n<p>Ranjit and Bingham describe that strategy in a post titled &#8220;Convincing a billion users to love passkeys: UX design insights from Microsoft to boost adoption and security.&#8221; But they don&#8217;t disclose how many customers love passkeys enough to actually use them.<\/p>\n\n\n\n<p>They do reveal that the Windows maker&#8217;s latest sign-in experience led to a 10 percent decline in password use and a 987 percent increase in passkey use. And they anticipate that given the reimagined sign-in experience, &#8220;hundreds of millions of new users will create and use passkeys over the coming months.&#8221;<\/p>\n\n\n\n<p>Microsoft did not immediately respond to a request to put a number on current passkey adoption.<\/p>\n\n\n\n<p>It was only in May \u2013 on World Password Day no less \u2013 that Redmond <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2024\/05\/02\/microsoft_google_passkeys\/\" rel=\"noreferrer noopener\">made passkeys available<\/a> to Microsoft consumer accounts. The biz at the time described the occasion as the culmination of a ten-year journey that began in 2015 with passwordless sign-in via Windows Hello and Windows Hello for Business.<\/p>\n\n\n\n<p>But really the possibility of a future without passwords dates back a decade further \u2013 to 2004, when Microsoft co-founder Bill Gates <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2004\/02\/25\/who_needs_passwords\/\" rel=\"noreferrer noopener\">predicted<\/a> the death of the password at the RSA Security conference. It was wishful thinking at the time \u2013 password problems led to security breaches then, as they do today \u2013 though it now appears to be within the realm of possibility.<\/p>\n\n\n\n<p>The Fast Identity Online Alliance (FIDO) has been <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2013\/02\/13\/fast_identity_alliance_launched_with_lenovo_and_paypal_support\/\" rel=\"noreferrer noopener\">pursuing the same goal<\/a> since 2013. With the publication of the <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2018\/04\/11\/fido_takes_a_bite_out_of_passwords_with_two_authentication_standards\/\" rel=\"noreferrer noopener\">WebAuthn authentication standard<\/a> and the development of the FIDO2 Project, tech giants Apple, Google, and Microsoft gained a common means to implement passkeys. And they&#8217;ve begun doing so.<\/p>\n\n\n\n<p>Apple introduced passkey support in iOS 16 and macOS Ventura in September 2022. Google did so shortly thereafter in <a target=\"_blank\" rel=\"noreferrer noopener\" href=\"https:\/\/blog.chromium.org\/2022\/12\/introducing-passkeys-in-chrome.html\">Chrome<\/a> and later in <a target=\"_blank\" rel=\"noreferrer noopener\" href=\"https:\/\/android-developers.googleblog.com\/2023\/02\/bringing-together-sign-in-solutions-and-passkeys-android-new-credential-manager.html\">Android<\/a> and <a target=\"_blank\" rel=\"noreferrer noopener\" href=\"https:\/\/security.googleblog.com\/2023\/05\/so-long-passwords-thanks-for-all-phish.html\">Google Accounts<\/a>. Microsoft introduced passkey support <a target=\"_blank\" rel=\"noreferrer noopener\" href=\"https:\/\/support.microsoft.com\/en-us\/account-billing\/set-up-a-security-key-as-your-verification-method-2911cacd-efa5-4593-ae22-e09ae14c6698\">in Windows 11 version 23H2<\/a>, and is starting to see more adoption thanks to its insistent UX design.<\/p>\n\n\n\n<p><a target=\"_blank\" rel=\"noreferrer noopener\" href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/security-101\/what-is-passkey\">Passkeys<\/a> rely on public key cryptography. When a user elects to create a passkey \u2013 or does so just to make the solicitations stop \u2013 a private key is created. That key gets stored securely on a device (such as a PC or a phone), where it&#8217;s associated with the device&#8217;s unlock mechanism (a biometric signal or a PIN). The corresponding public key is stored on the server for the associated application.<\/p>\n\n\n\n<p>Thereafter, the user can log in more efficiently. Selecting an app&#8217;s passkey login option prompts the server to check with the device to authenticate using the cryptographic key pair. No password entry or 2FA step is required.<\/p>\n\n\n\n<p>The benefit of this approach is that there&#8217;s no secret stored on the server that can be compromised and stolen \u2013 public keys need no protection. And each passkey is associated with a specific application, so credential reuse attacks aren&#8217;t a thing.<\/p>\n\n\n\n<p>Passkeys are not foolproof though. A compromised device might expose private keys, and a successful social engineering attack could dupe a user into creating a passkey for a malicious service.<\/p>\n\n\n\n<p>There are also potential problems if the user loses access to a device that stores passkeys \u2013 another means of authenticating to a passkey-linked service would be required, which might involve passwords or a more involved recovery process. Also, passkey portability between credential providers (across platforms or password manager applications) is still <a target=\"_blank\" rel=\"noreferrer noopener\" href=\"https:\/\/blog.1password.com\/fido-alliance-import-export-passkeys-draft-specs\/\">a work in progress<\/a>.<\/p>\n\n\n\n<p>At the 11th annual FIDO Tokyo Seminar last week, the FIDO Alliance <a target=\"_blank\" rel=\"noreferrer noopener\" href=\"https:\/\/fidoalliance.org\/passkey-adoption-doubles-in-2024-more-than-15-billion-online-accounts-can-leverage-passkeys\/\">declared<\/a>, &#8220;More than 15 billion online accounts can use passkeys&#8221; \u2013 which does not mean that many are actually doing so. The group also claims that Google has reported 800 million Google Accounts now use passkeys, which is up from the 400 million figure Google <a target=\"_blank\" rel=\"noreferrer noopener\" href=\"https:\/\/blog.google\/technology\/safety-security\/google-passkeys-update-april-2024\/\">reported<\/a> in April. The folks at FIDO further observed that Amazon introduced passkeys this year, and now has 175 million accounts using the technology.<\/p>\n\n\n\n<p>Microsoft is apparently on its way to a billion passkey users and the eventual elimination of passwords \u2013 but hasn&#8217;t revealed its progress. Given enough persistent, unavoidable passkey enrollment notifications, it&#8217;s only a matter of time.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>According to Microsoft&#8217;s website, this can be a face scan, fingerprint or pin. From the wording in the article below, they might be taking Authenticator PINs or maybe FIDO keys. Normally such things are used as a second factor to go along with a password, but they&#8217;re moving towards the only thing being needed. Seems [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[],"class_list":["post-9830","post","type-post","status-publish","format-standard","hentry","category-tech"],"blocksy_meta":[],"featured_image_src":null,"author_info":{"display_name":"Jason","author_link":"https:\/\/jasonsblog.ddns.net\/index.php\/author\/jturning\/"},"_links":{"self":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/9830","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/comments?post=9830"}],"version-history":[{"count":3,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/9830\/revisions"}],"predecessor-version":[{"id":9833,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/9830\/revisions\/9833"}],"wp:attachment":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/media?parent=9830"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/categories?post=9830"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/tags?post=9830"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}