Passkeys on Django with Mohamed ElKalioby

This video features Mohamed ElKalioby at DjangoCon US 2023 in Durham, North Carolina, USA.

Passkeys on Django with Mohamed ElKalioby
0:17:01
Published November 22, 2023
823 views

Passkeys is a state-of-the-art technology that extends Web Authentication API allowing the user to use a key stored on a device to log in on a new device. The technology is supported by Apple, Google, and Microsoft and is available now on recent iOS/iPad, Andriod as well as Mac OS X Ventura.
Passkeys allow the users to log in only through their private keys. It doesn't require the entry of a username and/or password, which provides a faster as well as safer environment for the users.
Google released Passkeys for all users to log in with on May 3, 2023.
The talk will discuss what is Passkeys and how it is more secure and phishing resistant, also it will show how to integrate them in your current Django project in a few lines of code.

This talk was presented at: https://2023.djangocon.us/talks/passkeys-on-django/

LINKS:
Follow Mohamed ElKalioby 👇

Follow DjangCon US 👇
https://fosstodon.org/@djangocon
https://twitter.com/djangocon

Follow DEFNA 👇
https://www.defna.org/

Video production by the presenter and DjangoCon US 2023 volunteers.

Summary

Passwords are vulnerable to theft, keylogging, phishing, and reuse, while WebAuthn uses asymmetric cryptography and device-based verification to provide passwordless or second-factor authentication that is resistant to phishing. Passkeys extend WebAuthn by allowing credentials to be synchronized across devices through services such as iCloud Keychain and Google Password Manager, addressing the inconvenience of device-bound keys. Mohamed ElKalioby explains the registration and authentication flows, shows how a passkey blocks a phishing attack by checking the relying party’s domain, and demonstrates integrating passkeys into Django with the django-passkeys package, including settings, URL routes, login-form changes, and credential management.

Key takeaways

  • WebAuthn authenticators create key pairs and sign server challenges without exposing biometric data to the website.
  • Passkeys improve on device-bound WebAuthn credentials by synchronizing private keys or using a nearby device to authenticate.
  • Domain binding makes passkeys resistant to phishing because an authenticator will not authorize a credential for an unregistered site.
  • The django-passkeys package provides authentication support and user interfaces for managing passkeys in Django applications.
  • Integration involves installing the package, configuring the authentication backend and relying-party settings, adding URL routes, and updating the login form.
  • Passkey-as-a-service providers can simplify implementation for web and mobile applications.

Summarised automatically from the transcript.

Transcript

2,522 words · auto-generated Show

Automatically transcribed, so expect mistakes in names and technical terms.

0:23

Hello and welcome to my first ever Dijunk WhoCon talk. I am Muhammad Kalyoubi and today I will be talking about pass keys and how to use them on Dijunk So let's start by who I am. I'm leading the software development team for Center of Genomic Medicine King, First I'm Specialist Hospital and Research Center in the art. I am main contributor of Dijango MF2, which has been stored around 200 times on GitHub and downloaded more than 170,000 times. I am the main contributor to Django Pass keys which is stored more than 100 times in around 6 months. So let's start by why passwords are not enough. I think everyone knows the answer of this question, but let's build a common account So passwords can be hacked, passwords can be key logged by

1:12

MLW which can snitch username and password or logging to a website using your own PC or a mobile It can be fixed like sometimes you get an an email that you have a problem when we were renewing your Netflix subscription. So you need to click here to fix the payment issue. When you click here you find yourself on a website which looks like Netflix. But once you put your information in there you are giving the information to the attacker so that they can hold your They can have your username and password and they are repeatable and since you are using we now have your Netflix account most probably you can be using the same password on your Facebook or your Twitter account So we have access to more accounts just because we have access to one password.

2:03

So what is the security principle to have a secure web application? In general, the user should be identified by something he knows like a password, something he has like a key or a chord, and something he is like a biometric. Most of our websites today depend mainly on the password as they are easy to implement and they are very common to the users and they know how to act with it. The use of a key was available for web applications in 2014 when the universal second factor protocol was was introduced but the problem the protocol needed the user to buy a specific USB device which has like the security which acts like a security key And this security key costs between $25

2:50

to $50, which caused that that protocol was not widely adopted by the users. And in the same time, we have now mobile phones which have access to our biometrics through the face ID, IRS recognition and or fingerprints. So there was a question why we cannot use this biometrics to be able to identify our users. So a weapon The web authentication protocol was introduced. So the web authentication protocol is extensional extension for the universal second factor protocol. It allows accessing authenticators suppose the client authenticated protocol. Work started in 2016 and become a working student in March 2019.

3:36

It's a product of the feedwall lines and it depends on asymmetric encryption with a random challenge. And this enables a passwordless authentication and or a secure second factor method. The syndicators would be responsible for the refining the relaying party which is the website, so the technology should be a phishing resistant technology. So what are the supported indicators? Currently you can use any V2 tool security key on any browser on any OS. including Android, iOS or iPads. You can use your fingerprint or the PIN code on Windows Hello You can use your screen unlock pattern, your fingerprint

4:22

sensor and or your face iris detection method on Android. You can use your face ID, touch ID. On both meh iOS and make i6 So let's see what is the user experience when he tries to register and use such authentication method. So in this demo we will see how the users can register a device. So he will start by logging to the service by using his username and password. Then he will be enrolling to the new security service. He will say enroll he will put the device name so that he can refer to it later He will say start, the browser will ask him to use the device, he will ask that he's going with the platform. Windows hello can ask him between the windows

5:08

the fingerprint and the pin. So he I selected the fingerprint now. As you can see, we have the device registered on our account so how the user can now use that create key to indicate to the service. Here as we can see in this demo the browser then the user putting his username and pass so he can so it just First login, he selects his username, he says he put his fingerprint and he is done. It's done in less than five seconds and this is as one of the most secure ways to log into the web service like we will see later So let's see what's happening behind the scene when the user tries to register a new WebOS

5:54

in device. So it starts when the application requests adding a new what was in method. So the server sends the site information, the user information and the challenge. The browser asks the user to select the device and forward the information to it. The device will prompt the user to verify the request and then generate a key pair. The device will send the public key and the sign change back to the browser with the device info. The application sends the info back to the server. The server decryptes received challenge with the received private public key and validated against the sent challenge at the start of the cycle. Here it worth mentioning that we don't hold any user biometric and there is nothing we know about the user. biometric features.

6:40

So now we know how the how the registration process works for the user to register is key. So let's see how what happened behind the scenes during the authentication of the user so that it can happen so quickly. So it starts by the application requests the login to the service, the server sends a challenge, the browser asks the user to select a device and it forwards the site information and the challenge to the device. The device asks the user to confirm his identity and then validates the site. Once the site is validated, the the device can The device will send the encrypted challenge and the device info and the user identity to the browser. The application forwards the information to the server and the server decrypts the received challenge using the safe public key on the device for the user and compare it with them.

7:33

So now let's see how WebOSN is a fishing resistant technology So here we will assume that there is a phishing attack against the bank. com. The attackers are trying to gain access to their customer accounts to be able to reach their bank accounts and transfer money outside So they were able to feed the user to use hlebank. com and in a life man in the middle attack scenario the Attacker will enter the information received on the phishing website on the real thebank. com and since the username and password are correct, the bank. com will ask the user to confirm his identity using the web OC.

8:19

The attacker will ask the user to confirm his identity, hoping to pick up the credentials so that he can use it on the bank. com Now the user will click authorize, then the user will put his fingerprint and or their verification method But now the authenticator will stop him because currently the current authenticator doesn't have any credential for the bank. com This will lead to stopping of the whole attack and fear of gaining access to the user account since the attacker will never be able to confirm his credentials since there is no signage for the authenticator from the bank. com.

9:04

So as Web was N as was a very secure technology, why it was not widely adopted by the service providers and by the users, mainly because it has It had few challenges and mainly that the keys were device bounded. So if the user uses an iPhone, an iPad and a macOS He need to create three keys on each device and this cause the services that they need a fallback method for the users to login. because if you has register G key first on the your iPad on your iPad and now you want to log into your iPhone you need to use another method like an email verification or an OTP so that the user can log in again and once they if the user is going to use the device frequently

9:50

they need to register the device The challenges that affected the WebOSN what are the things that Pi's keys are trying to solve So let's start by defining what is pass keys. Pass keys is a work between Apple, Microsoft and Google to expand the support of FIDO standard, that's the availability of passwordless sign-in. It is all started when Apple opens the support for pass keys in iOS 16, iPad 16. 1 and macOS Ventura allowing the user to sync the private keys on their keychains. On May 3, 2003, Google allowed the users to stop using their password toolkit to log into

10:39

their Google accounts and start using pass keys instead. So what is pass keys all about? It's a way for the user to use a key stored on another device to log in to login or to the service. The user can ask a nearby device to sign the request on their behalf. Keys can be used on the application's website and mobile application, and preferably the keys should be syncable between devices. So what is the current state of pass keys? Currently Apple stores a private key generated on any device on the iCloud keychain protected by a pane

11:24

and is sync it to all devices. Google store all private keys generated on Android on your Google Password Manager On Windows, keys are stored on TPM. And on Chrome on Mac OX X stores the key on the device. Ceferian Chromium -based browser can ask iOS slash Android devices to request to sign the requests through BLE. On Android and iOS keys can be shared between the app and the web application. Passwords vaults are now evolving to be pass keys vaults Firefox doesn't support pass keys but support webs in. So how can we integrate this very nice technology to our current web applications

12:11

protecting our users and our data? So Django Pass Keys is an authentication backend for pass keys. It is easy to integrate in your current authentication of authentication flow. include the interface for the users to manage their pass keys, allow knowing if the user is using pass key or not, allow knowing if the user is using a passkey from another platform works with the Django 2. 0 plus and Python 3. 7 plus and is down get downloaded around 2000 times a month So how to add pest keys to your Dejango? First you need to install it using pip install Dejango keys Then you add pass keys to your installed apps,

12:57

collects the static files, then you have to migrate do the database migrations Then you need to add the volume to your settings file. You need to modify ruthentification backend to be passkeys. backend. paskeys model backend Then you need to provide the domain where your website is hosted. Then you need to provide the server name, which is like a user-friendly name for you for the website to be identified on the authenticator. Next, you need to identify which type of authenticators you are going to use. Are you going to use rooming syndicators, which is like cross-platform authenticators like security keys as a room between devices? Or do you want to use the platform authenticators

13:42

like the touch ID and Windows Hello. Then you need to add the pass keys to URL patterns Now in the login view we need to change the call to the authenticate to be could to have the request as the first parameter to be able to see what's inside it Next in the login template we need to add an input hidden input called pass keys to be able to hold the to hold the result of the pass key to the the hold of the pass key authentication and we need to give an ID for the form to be able to auto submit it once Pass keys results is available.

14:29

Finally we need to add a link somewhere in for the users to be able to manage their keys by referring to the pass keys home. And you are done. So let's see pesky is in action. On the left we have an iPad which doesn't have the pass key to use for the secure service and on the right is my Android phone it has the key registered as we registered it in the first demo So now we will try to use them. So on the iPad we will just say first login. The iPad will ask me which device to use. I will select the iPhone or the Android device. It will give me an QR code And now we will take the Android phone and we'll try to scan the QR code and using the camera of the Android. So now we scan the code, we open the link.

15:15

Now it asks me to verify the connection request and now they are trying to communicate to connect together. Once they are connected, the Android phone will ask me to verify myself. I verify myself, I put my fingerprint, and now the iOS was able to log in securely to the service. using the p pk account. So if you don't need to Host your own passkeys and you want a simpler solution or if you are using a mobile application I I recommend that you use a passkey as a service like just pass. me Just Pass. me is a FIDO2 and OpenID service. They allow having pass key on

16:00

web applications and mobile applications on both iOS and Android. Users can log in by PAS keys or social or email if allowed by the site. They have the Django Flutter Firebase Assyntic plugins and they are free up to one 1003 monthly active users So in conclusion, we discussed why passwords aren't enough. What is WebOS N API and how is it featuring resistant? What were the challenges in Web Authentication and how pass keys solved it? the state of pest keys, how to integrate space keys in your Dujango application.

16:46

So I will be available on Twitter, GitHub or the conference tag for any questions. Thank you

Questions this talk answers

Why aren’t passwords enough for secure web applications?

Passwords can be stolen through hacking, keyloggers, and phishing, and password reuse lets an attacker compromise multiple accounts after obtaining one password.

Discussed at 0:23

What is WebAuthn and how does it work?

WebAuthn is a Web Authentication API based on asymmetric encryption and a random challenge. It lets a device authenticator verify the user and sign a challenge, enabling passwordless login or a secure second factor without the server storing biometric data.

Discussed at 3:36

Why is WebAuthn phishing-resistant?

The authenticator checks that the request comes from the site for which its credential was created. In a phishing or man-in-the-middle attack, it has no credential for the attacker’s domain and refuses to authenticate.

Discussed at 8:13

What problem do passkeys solve compared with traditional WebAuthn credentials?

Traditional WebAuthn credentials were tied to individual devices, forcing users with multiple devices to register each one or use a fallback login method. Passkeys address this by allowing private keys to sync through platform credential stores such as iCloud Keychain or Google Password Manager, and by allowing a nearby device to authenticate another device.

Discussed at 9:50

How do I add passkey authentication to a Django application?

Install Django Passkeys, add it to the installed apps, collect static files, migrate, configure the authentication backend, site domain, server name, and authenticator types, then add its URLs and update the login form and view to handle passkey results. The package also provides an interface for users to manage their passkeys.

Discussed at 12:11

Note: We understand that names change, people change, and bodies change. We respect each individual's journey and privacy. If you have any concerns about a video or need us to remove content, please don't hesitate to contact us. We will handle your request with care and promptly address any issues.

More videos from DjangoCon US