Live data from Hacker News

Passkeys: The beginning of the end of the password

blog.google

61–70 of 1001 posts

Re: Passkeys: The beginning of the end of the password

#61

I don't want to give Google my fingerprint or my face. A password in a password manager + 2FA is fine.

You're not. You're storing a private key on a device, and using something like a fingerprint or pin to unlock it and use it to authenticate. The fingerprint data is also only stored on the local device.

Yeah. Except if the usual Qualcom spy chips (also available in Google Pixel) phone home all your biometrics...

Re: Passkeys: The beginning of the end of the password

#62
Anyone know if it's possible to use this with Google Workspace accounts yet?

From the Google Blog I clicked on "Today, passkeys for Google Accounts are available. You can try them out here"

However, I got: "Passkeys aren’t allowed on this account. Contact your admin for help"

And the Workspace admin page doesn't seem to include any options for Passkeys.

Re: Passkeys: The beginning of the end of the password

#63

Those passkeys are either insecure or unreliable. Let me explain: Those passkeys are asymmetric cryptographic keypairs where the private key is securely stored on a device, unlockable (for use, not reading) only by convincing your devices security processor to do so by pin/fingerprint/pattern. Which in itself can be secure, given you do trust that magic security processor (which you shouldn't, see yesterday's news fo…

The point of passkeys isn’t to be perfect — the point is to replace passwords, which are already far more imperfect than passkeys. The bonus points with a password is that every site that uses them has to secure them properly and theft of passwords, in plain-text, hashed, etc form is common.

Re: Passkeys: The beginning of the end of the password

#64

I'm still salty about this. Called it passkey too. http://www.multipasskey.com/susdemo/ . Built this 5-6yrs ago and applied to YC. Crickets. Hope to see this take off, with my approach I made it where you don't even need to "register", you can go to a site and just have an account. I did the fingerprint, face scan, PIN approach for more security, but my favorite was NFC ring. Basically you have an NFC ring you wear o…

> What I don't like bout Google doing this is that the big providers use this to tether and lock you in to their platform.

How so? I just created two passkeys for my Google account — one for Chrome, and one for my Apple Keychain.

Re: Passkeys: The beginning of the end of the password

#65
post #38

Just a heads-up if you're planning to use passkeys with iOS/macOS: Might be fixed already, but last time I tried it out it seemed like iOS only stored a single passkey per domain. If you first store a passkey for a@domain and then later on store a passkey for a different user b@domain the a@domain passkey is overwritten without any warning. Or at least this seemed to be the case a couple of months ago when I tried it…

For me at least it works. I have multiple accounts for the same domain and iOS/macOS prompt me to choose from the last one used, or I can choose to pick from a collection.

Re: Passkeys: The beginning of the end of the password

#66

I'm still salty about this. Called it passkey too. http://www.multipasskey.com/susdemo/ . Built this 5-6yrs ago and applied to YC. Crickets. Hope to see this take off, with my approach I made it where you don't even need to "register", you can go to a site and just have an account. I did the fingerprint, face scan, PIN approach for more security, but my favorite was NFC ring. Basically you have an NFC ring you wear o…

> What I don't like bout Google doing this is that the big providers use this to tether and lock you in to their platform.

This is the concern, but exporting passkeys to other ecosystems seems like it'll come with time, even if via third-party tools or like how browsers will prompt you to "import your " upon setup.

Re: Passkeys: The beginning of the end of the password

#67
How do you handle delegation in this case? Let's say I want to delegate access to my account to a partner/friend/employee on a service that doesn't support multiple users per account, charges extra for it or outright doesn't want me to delegate access to someone else (so it's not always possible to rely on the website's cooperation).

Currently I can just message them the password or even write it down on a post-it note and they'll have everything they need to complete the task as me. How does it work with passkeys? Does the spec allow my passkey HSM to securely share the secret by encrypting it against the recipient's passkey HSM? Can it use the concept of leaf certificates to sign a short-lived certificate allowing access to that credential without sharing the credential's secret itself?

I can't advocate for passkeys until the concerns above are resolved. The push for passkeys seems like yet another attempt to remove control from the user.

Re: Passkeys: The beginning of the end of the password

#68
post #56
post #4

I hate this, I hate every part of this. The attempt to get rid of passwords has been the biggest assault on the free internet in recent history, and people are asleep at the wheel as it's happening. They want to tie you to an external service, so they can tie you to your phone, which they also manage with another external service. All of these schemes are braindead with obtuse, user-unfriendly backup/transfer/restore…

Okay, but the alternative is users managing a separate password for every service, which is impossible to do securely without using a password-manager, and the password-manager is basically a weaker version of an external service like Google's.

Weaker? The UX for signing in on a new device seems better. Maybe that's the same thing as weaker. I'm not seeing any reason in all of this to switch from a password manager though.

Re: Passkeys: The beginning of the end of the password

#69
post #60
post #4

I hate this, I hate every part of this. The attempt to get rid of passwords has been the biggest assault on the free internet in recent history, and people are asleep at the wheel as it's happening. They want to tie you to an external service, so they can tie you to your phone, which they also manage with another external service. All of these schemes are braindead with obtuse, user-unfriendly backup/transfer/restore…

Passwords are terrible for a world where people have hundreds of them and are lazy. And password managers are a bandaid solution. Arguing effectively that passwords were fine for computing in 1970 isn't an answer. So if you don't like passkeys it's reasonable to ask for your alternative.

Whatever an alternative would be, it should be decentralized.
Post reply on HN