I don't want to give Google my fingerprint or my face. A password in a password manager + 2FA is fine.
You're not. You're storing a private key on a device, and using something like a fingerprint or pin to unlock it and use it to authenticate. The fingerprint data is also only stored on the local device.
Passkeys: The beginning of the end of the password
61–70 of 1001 posts
Re: Passkeys: The beginning of the end of the password
#62From the Google Blog I clicked on "Today, passkeys for Google Accounts are available. You can try them out here"
However, I got: "Passkeys aren’t allowed on this account. Contact your admin for help"
And the Workspace admin page doesn't seem to include any options for Passkeys.
Re: Passkeys: The beginning of the end of the password
#63Those passkeys are either insecure or unreliable. Let me explain: Those passkeys are asymmetric cryptographic keypairs where the private key is securely stored on a device, unlockable (for use, not reading) only by convincing your devices security processor to do so by pin/fingerprint/pattern. Which in itself can be secure, given you do trust that magic security processor (which you shouldn't, see yesterday's news fo…
Re: Passkeys: The beginning of the end of the password
#64I'm still salty about this. Called it passkey too. http://www.multipasskey.com/susdemo/ . Built this 5-6yrs ago and applied to YC. Crickets. Hope to see this take off, with my approach I made it where you don't even need to "register", you can go to a site and just have an account. I did the fingerprint, face scan, PIN approach for more security, but my favorite was NFC ring. Basically you have an NFC ring you wear o…
How so? I just created two passkeys for my Google account — one for Chrome, and one for my Apple Keychain.
Re: Passkeys: The beginning of the end of the password
#65Just a heads-up if you're planning to use passkeys with iOS/macOS: Might be fixed already, but last time I tried it out it seemed like iOS only stored a single passkey per domain. If you first store a passkey for a@domain and then later on store a passkey for a different user b@domain the a@domain passkey is overwritten without any warning. Or at least this seemed to be the case a couple of months ago when I tried it…
Re: Passkeys: The beginning of the end of the password
#66I'm still salty about this. Called it passkey too. http://www.multipasskey.com/susdemo/ . Built this 5-6yrs ago and applied to YC. Crickets. Hope to see this take off, with my approach I made it where you don't even need to "register", you can go to a site and just have an account. I did the fingerprint, face scan, PIN approach for more security, but my favorite was NFC ring. Basically you have an NFC ring you wear o…
This is the concern, but exporting passkeys to other ecosystems seems like it'll come with time, even if via third-party tools or like how browsers will prompt you to "import your " upon setup.
Re: Passkeys: The beginning of the end of the password
#67Currently I can just message them the password or even write it down on a post-it note and they'll have everything they need to complete the task as me. How does it work with passkeys? Does the spec allow my passkey HSM to securely share the secret by encrypting it against the recipient's passkey HSM? Can it use the concept of leaf certificates to sign a short-lived certificate allowing access to that credential without sharing the credential's secret itself?
I can't advocate for passkeys until the concerns above are resolved. The push for passkeys seems like yet another attempt to remove control from the user.
Re: Passkeys: The beginning of the end of the password
#68I hate this, I hate every part of this. The attempt to get rid of passwords has been the biggest assault on the free internet in recent history, and people are asleep at the wheel as it's happening. They want to tie you to an external service, so they can tie you to your phone, which they also manage with another external service. All of these schemes are braindead with obtuse, user-unfriendly backup/transfer/restore…
Okay, but the alternative is users managing a separate password for every service, which is impossible to do securely without using a password-manager, and the password-manager is basically a weaker version of an external service like Google's.
Re: Passkeys: The beginning of the end of the password
#69I hate this, I hate every part of this. The attempt to get rid of passwords has been the biggest assault on the free internet in recent history, and people are asleep at the wheel as it's happening. They want to tie you to an external service, so they can tie you to your phone, which they also manage with another external service. All of these schemes are braindead with obtuse, user-unfriendly backup/transfer/restore…
Passwords are terrible for a world where people have hundreds of them and are lazy. And password managers are a bandaid solution. Arguing effectively that passwords were fine for computing in 1970 isn't an answer. So if you don't like passkeys it's reasonable to ask for your alternative.