Live data from Hacker News

Passkeys: The beginning of the end of the password

blog.google

21–30 of 1001 posts

Re: Passkeys: The beginning of the end of the password

#22

And if you have your google account banned/disabled for whatever reason, then what?

Indeed I wouldn’t trust Google or Apple to be the only place my passkeys are stored. I’m currently a 1Password user and their upcoming support looks like it could address this issue (I’m not in any way affiliated with them)

https://www.future.1password.com/passkeys/

Re: Passkeys: The beginning of the end of the password

#23
post #3

Earlier quoted context omitted.

At least for the Google account, it looks like you can add multiple passkeys.

Sure. But am I still locking my ability to access that account permanently to Google? Can I login via Chrome on an Apple/Windows platform and add a passkey there? I’m also a bit worried that this permanently entrenches these as the platform vendors because no one is going to port to a new platform unless you’re already a major tech company (maybe).

For Chrome on desktop OS, it will popup a QR code that you can scan it by passkey-registered phone like[1].

If your desktop/laptop has TPM, TrustZone or other similar devices, it can register Passkey too.

[1] https://9to5google.com/2022/10/12/android-chrome-passkey-sup...

Re: Passkeys: The beginning of the end of the password

#24
post #4

I hate this, I hate every part of this. The attempt to get rid of passwords has been the biggest assault on the free internet in recent history, and people are asleep at the wheel as it's happening. They want to tie you to an external service, so they can tie you to your phone, which they also manage with another external service. All of these schemes are braindead with obtuse, user-unfriendly backup/transfer/restore…

[flagged]

Re: Passkeys: The beginning of the end of the password

#25
post #3

Earlier quoted context omitted.

At least for the Google account, it looks like you can add multiple passkeys.

Sure. But am I still locking my ability to access that account permanently to Google? Can I login via Chrome on an Apple/Windows platform and add a passkey there? I’m also a bit worried that this permanently entrenches these as the platform vendors because no one is going to port to a new platform unless you’re already a major tech company (maybe).

Google actually outlines that very scenario near the bottom of their announcement:

> Using passkeys does not mean that you have to use your phone every time you sign in. If you use multiple devices, e.g. a laptop, a PC or a tablet, you can create a passkey for each one. In addition, some platforms securely back your passkeys up and sync them to other devices you own. For example, if you create a passkey on your iPhone, that passkey will also be available on your other Apple devices if they are signed in to the same iCloud account. This protects you from being locked out of your account in case you lose your devices, and makes it easier for you to upgrade from one device to another.

> If you want to sign in on a new device for the first time, or temporarily use someone else's device, you can use a passkey stored on your phone to do so. On the new device, you’d just select the option to "use a passkey from another device" and follow the prompts. This does not automatically transfer the passkey to the new device, it only uses your phone's screen lock and proximity to approve a one-time sign-in. If the new device supports storing its own passkeys, we will ask separately if you want to create one there.

Re: Passkeys: The beginning of the end of the password

#26
post #5

How is this more secure? They say "with a fingerprint, a face scan or a screen lock PIN", but basically all phones let you fall back to PINs if you dont want to do face or fingerprints. Pins are flat out not secure - typically just 4 digits. Yeah its probably better than 80% of people having "password123", but it seems strictly worse than a password + password manager? Or at least just having proper 2FA.

> How is this more secure?

The three factors of authentication are:

1. Something you have

2. Something you know

3. Something you are

Passkeys are typically 1+2 or 1+3 — you'd need to have physical access to the device either way.

Re: Passkeys: The beginning of the end of the password

#28
I really wish these “password killers” would acknowledge that we will never eliminate passwords. Ever. There’s too many under-funded applications deployed out there that have no resources to add passkey support. Password managers are an excellent place to progressively enhance the user authentication story and could support more advanced schemes like passkeys while remaining compatible with the registry of deeds site from 1999. Instead, it’s always presented as some other thing (usually conveniently tied to Chrome) that you have in lieu of your password manager.

Re: Passkeys: The beginning of the end of the password

#30

Earlier quoted context omitted.

Sure. But am I still locking my ability to access that account permanently to Google? Can I login via Chrome on an Apple/Windows platform and add a passkey there? I’m also a bit worried that this permanently entrenches these as the platform vendors because no one is going to port to a new platform unless you’re already a major tech company (maybe).

Google actually outlines that very scenario near the bottom of their announcement: > Using passkeys does not mean that you have to use your phone every time you sign in. If you use multiple devices, e.g. a laptop, a PC or a tablet, you can create a passkey for each one. In addition, some platforms securely back your passkeys up and sync them to other devices you own. For example, if you create a passkey on your iPhon…

> For example, if you create a passkey on your iPhone, that passkey will also be available on your other Apple devices if they are signed in to the same iCloud account.

In addition to this, you can AirDrop a passkey from one device to another, even if they don't belong to the same iCloud account.

Post reply on HN