Live data from Hacker News

Bringing passkeys to Android and Chrome

android-developers.googleblog.com

111–120 of 264 posts

Re: Bringing passkeys to Android and Chrome

#111

Earlier quoted context omitted.

The second most popular top level comment chain is: > Unless I can back it up and import it into a new device from a competitor, then there is no way I am going to use this unless forced. I do not trust one company anymore. Which is the same sentiment as this thread. The first comment was just talking about the open standard of Apple's implementation and weakness of 2FA loss/recovery. https://news.ycombinator.com/ite…

Yup - GP made the mistake of treating HN as a single person with a coherent opinion. It's not, and it's extremely tiring and intellectually uninteresting to repeatedly see people doing that.

No. While I have tried to counter these group think posts you talk about, I only find them interesting because I think it is human nature to do it. I know I do it all the time.

Re: Bringing passkeys to Android and Chrome

#112
> A passkey on a phone can also be used to sign in on a nearby device. For example, an Android user can now sign in to a passkey-enabled website using Safari on a Mac. Similarly, passkey support in Chrome means that a Chrome user, for example on Windows, can do the same using a passkey stored on their iOS device.

> Since passkeys are built on industry standards, this works across different platforms and browsers - including Windows, macOS and iOS, and ChromeOS, with a uniform user experience.

I see no mention of Linux in these examples, which tells me that users having access to their keys is not a primary concern for these implementations?

Re: Bringing passkeys to Android and Chrome

#113
post #101

Earlier quoted context omitted.

Bitwarden will do TOTP, and its CLI tool is quite usable. If you want it fully local, just stand up a docker of their server software (which is open source) or the open source reimplementation (vaultwarden).

> Bitwarden will do TOTP Not disputing this, but it requires a “pro” account which is $10 a year. No big deal to me, in fact I find it a great deal, but I think it’s fair to be clear about this as not to provide false expectations.

Fair. And self-hosting an instance in the cloud is probably comparable in cost.

Re: Bringing passkeys to Android and Chrome

#114
post #27

Passkeys sound like another way for companies like Google and Apple to lock you into their walled garden. Having each walled garden randomly generating a key for every single domain instead of using the actual domain name as part of the key is a great way to lock regular people into their respective ecosystems.

[deleted]

Re: Bringing passkeys to Android and Chrome

#115
post #76
post #27

Passkeys sound like another way for companies like Google and Apple to lock you into their walled garden. Having each walled garden randomly generating a key for every single domain instead of using the actual domain name as part of the key is a great way to lock regular people into their respective ecosystems.

My understanding of passkeys is that they are using WebAuthn under the hood (hence the nod to the w3c/FIDO at the end, and the fact that the passkey in the screenshot was associated with tribank.us). They are solving a very real problem. WebAuthn uses private keys, but those private keys are tied to the device where they were created. This is a blessing and a curse. It's a blessing because it eliminates a whole trove…

[deleted]

Re: Bringing passkeys to Android and Chrome

#116

Earlier quoted context omitted.

It's not particularly surprising. Apple has a much better reputation at customer service than Google does – they have actual stores you can walk into. Now I'm not sure whether they can help you unlock your Apple ID if you prove to them that you're the owner of the account, but I can at least visualize Apple having the scale to do that. Google on the other hand has a horrendous reputation for locking out people out of…

> but I can at least visualize Apple having the scale to do that. > Google on the other hand has a horrendous reputation for Neither are true nor false but definitely exaggerations. All you're doing is displaying personal biases by providing them with benefit-of-the-doubts. They too have a reputation for locking people out, and are well known for turning data over, but one that HN in gernal prefers to ignore.

> Neither are true nor false but definitely exaggerations.

Google does not kill services. That does not happen. Google definitely does not deplatform people killing all their accounts and all their access. That also does not happen.

Re: Bringing passkeys to Android and Chrome

#117

Earlier quoted context omitted.

It's not particularly surprising. Apple has a much better reputation at customer service than Google does – they have actual stores you can walk into. Now I'm not sure whether they can help you unlock your Apple ID if you prove to them that you're the owner of the account, but I can at least visualize Apple having the scale to do that. Google on the other hand has a horrendous reputation for locking out people out of…

Apple, on the other hand, has terrible problems with working with others that google does not. Apple will happily tell you that if you want grandma to have a whatever color text bubble, you should buy her an iPhone, to name a recent example, rather than adopt the standard everyone else is using. I bought a Macbook last holiday season and couldn't even set it up until my wife set up her iPhone on my account to activat…

> I bought a Macbook last holiday season and couldn't even set it up until my wife set up her iPhone on my account...

I have no idea what you mean by this. You do not need, and have never needed, to own an iPhone to use an Apple computer.

> I bought my wife a iWatch last week and briefly thought of getting myself one but you can't use it without an iPhone...

This, on the other hand, makes a little more sense. The Apple Watch is designed as a companion device to an iPhone. Much of its functionality relies upon the phone (e.g. displaying notifications from the phone, installing watch apps which pair with corresponding phone apps) -- it can't do much on its own.

Re: Bringing passkeys to Android and Chrome

#118
Can we have this but self-hostable and open source, please? Something like Bitwarden that you can stuff onto your own device? I know there are hosted services for handling auth on the server backend, but what about the other way around?

I use Krypton but that's not maintained (and already broken on some websites like Github). I trust the secure storage module of my phone and I trust my computer's TPM, unlike many other Linux users; surely it should be possible to integrate with the OS somehow to make it secure, right? The last example I saw used USB over IP to inject a virtual FIDO device, which works great, but the implementation is clearly not ready for prime time.

Re: Bringing passkeys to Android and Chrome

#119

Earlier quoted context omitted.

Be precise: what threat is added here that is added by a third party holding encrypted keys? Like this isn't particularly different from me backing up my (encrypted) disk which contains my (further encrypted) keys to the cloud somewhere.

In the second instance, you are controlling the where and how of your keys being backed up. If you are smart you will have backed up your keys to multiple locations, for disaster recovery. One of the fundamentals of privacy is having control of your data, which the first option does not provide.

Why not?

What is concerning about giving encrypted keys to someone? If I give my encrypted key to you, right now, I retain control of my data. One of the fundamentals of encryption is that you can freely share the ciphertext without giving up control of your data.

Re: Bringing passkeys to Android and Chrome

#120

Earlier quoted context omitted.

The second most popular top level comment chain is: > Unless I can back it up and import it into a new device from a competitor, then there is no way I am going to use this unless forced. I do not trust one company anymore. Which is the same sentiment as this thread. The first comment was just talking about the open standard of Apple's implementation and weakness of 2FA loss/recovery. https://news.ycombinator.com/ite…

> I do not trust one company anymore. Especially when that company is Google.

Yeah Google is more evil than all of those other totally non-evil companies that act in your best interests at all times. It's not like other companies have the same incentive to profit from you!

You believing $company is not as bad as Google definitely has nothing to do with marketing!

Post reply on HN