Live data from Hacker News

Passkeys: The beginning of the end of the password

blog.google

1–10 of 1001 posts

Re: Passkeys: The beginning of the end of the password

#2
Let’s say I have a passkey in Chrome and no password. How do I add a passkey to iOS so that I can login via both mechanisms?

Is my understanding correct that if I only used Passkeys that I’d be permanently locking my account to a third party service to the vendor I used to login with in the first place?

Re: Passkeys: The beginning of the end of the password

#3

Let’s say I have a passkey in Chrome and no password. How do I add a passkey to iOS so that I can login via both mechanisms? Is my understanding correct that if I only used Passkeys that I’d be permanently locking my account to a third party service to the vendor I used to login with in the first place?

At least for the Google account, it looks like you can add multiple passkeys.

Re: Passkeys: The beginning of the end of the password

#4
I hate this, I hate every part of this.

The attempt to get rid of passwords has been the biggest assault on the free internet in recent history, and people are asleep at the wheel as it's happening.

They want to tie you to an external service, so they can tie you to your phone, which they also manage with another external service.

All of these schemes are braindead with obtuse, user-unfriendly backup/transfer/restore options. They fail at even making things "simple" for regular users.

Re: Passkeys: The beginning of the end of the password

#5
How is this more secure? They say "with a fingerprint, a face scan or a screen lock PIN", but basically all phones let you fall back to PINs if you dont want to do face or fingerprints. Pins are flat out not secure - typically just 4 digits.

Yeah its probably better than 80% of people having "password123", but it seems strictly worse than a password + password manager? Or at least just having proper 2FA.

Re: Passkeys: The beginning of the end of the password

#6
It looks like a good change for the average user, a secret stored on the device is likely a whole lot safer than just having a password. Having it as the only factor seems less secure than password + good extra factor like TOTP on device though.

I also wonder how a lost/broken/replaced device is dealth with, especially given Google's less-than-stellar account lockout history.

edit: I guess this is still MFA since you need both the physical device and a fingerprint and phone unlock code

Re: Passkeys: The beginning of the end of the password

#10
post #3

Let’s say I have a passkey in Chrome and no password. How do I add a passkey to iOS so that I can login via both mechanisms? Is my understanding correct that if I only used Passkeys that I’d be permanently locking my account to a third party service to the vendor I used to login with in the first place?

At least for the Google account, it looks like you can add multiple passkeys.

Sure. But am I still locking my ability to access that account permanently to Google? Can I login via Chrome on an Apple/Windows platform and add a passkey there?

I’m also a bit worried that this permanently entrenches these as the platform vendors because no one is going to port to a new platform unless you’re already a major tech company (maybe).

Post reply on HN