Live data from Hacker News

Passkeys: The beginning of the end of the password

blog.google

101–110 of 1001 posts

Re: Passkeys: The beginning of the end of the password

#101

Earlier quoted context omitted.

> And just a daily reminder that biometrics are usernames, they are not passwords. I think you should stop giving out this daily reminder. This meme has outlived its usefulness. Using face id to unlock a local key store to enable my device to sign a signed challenge from a site I want to log into with the private key stored on my device is not a 'username' in any meaningful sense. The problem is, the metaphor about p…

> If my non-technical parents said they were migrating all their accounts to passkeys, I would be very pleased. I wouldn't be worried about their inability to change their biometrics My 76 yr old dad can't do it. His phone is some shitty android trash that when he's setting up his biometrics, he shakes a bit, and it never stores the finger data correctly. I have to hold his finger and his phone at the same time to ev…

This is so true - most older people I've worked with have major problems with touch devices. No one has come up with a satisfactory solution. This is not a new problem - I remember working with my grandfather in his 80's on a 286 equipped with a mouse - his arthritis prevented him from accurately positioning the mouse. Today's touch interfaces are far worse. And fingerprint scans are very difficult to get right and use with older people. Maybe face scans are fine but I've never trusted them. Regardless of security logins, there are a host of other issues - complex navigation, complex and confusing layouts (especially desktop), and hard to manipulate controls. One example, a simple zoom or skype call - why hasn't anyone ever developed a simple device to allow for same without having to use intricate controls. I've always imagined something similar to the video enabled nest or alexa devices but with physical knobs and push buttons. There's a very large market being ignored for some reason.

Re: Passkeys: The beginning of the end of the password

#102
Auth is as secure as the weakest link - in the case of this it's your email and/or customer service

To put it another way, it's not really any more secure than passwords.

Sure, there's a lower risk of password breaches, but if you're the target audience for passkeys, you probably also use a password manager with unique passwords per site (even if that manager is the one built into your browser and synced across your devices).

Re: Passkeys: The beginning of the end of the password

#103
post #54

What happens if you lose all your hardware factors (eg if you have a home fire)? Are you just locked out of all your accounts with this approach?

Not if the Passkey was synced (ex: you used iCloud keychain). If the passkey was not synced, then I would have to assume it would be the same if you lost a physical hardware key.

How do you access iCloud without your passkey?

Re: Passkeys: The beginning of the end of the password

#104

Earlier quoted context omitted.

Not if the Passkey was synced (ex: you used iCloud keychain). If the passkey was not synced, then I would have to assume it would be the same if you lost a physical hardware key.

How do you access iCloud without your passkey?

Call Tim, he'll vouch for you.

Re: Passkeys: The beginning of the end of the password

#105
post #87

Earlier quoted context omitted.

Also tangible and understandable is a registry of users who have access to your accounts, that allows you to grant and revoke access (at possibly different levels), without having to reset all your own credentials. I've got to quit commenting, but humans are undeniably the weakest link in security. While I understand the perceptions and even share some of the concerns expressed in this thread about the loss of contro…

> It's a few extra steps up front, but once it's working, it's so much easier. It's a few extra steps per site . Every time you get a new device you need to go back to every site you've ever visited and update the credentials. It is maybe feasible for a few important accounts but it doesn't scale. Whatever solution we have needs to be syncable and able to be exported to a safe once and continue to be usable by new si…

The now-unfortunately-named "Password managers" help with this by providing various mechanisms to sync keys with multiple devices, so that every time you get a new device, you simply need to authenticate and transfer the key store to the new device.

The device's hardware security facilities are there to protect the keystore. They aren't /the/ keystore.

Find a key manager. iCloud Keychain, Microsoft Authenticator, Bitwarden, something. Use that. Concerns about migrating devices dissolve away.

Re: Passkeys: The beginning of the end of the password

#106
post #45

Earlier quoted context omitted.

> The only use-case for biometrics is deanonymization, sold to you under the auspices of security, primarily used for corporate surveillance. Please provide evidence that biometric data has ever been extracted from a major platform (IE Apple/enclave). Absence of evidence != evidence of absence, I know, but you’re selling it as the only use case so surely you have proof.

> Please provide evidence that biometric data has ever been extracted from a major platform Why extract it from a platform when it can be extracted easily from the person? Imagine your password was written on every surface you touched (fingerprint) or is prominently displayed on your social media accounts (face).

I don’t understand how this could work actually. From a couple of photos on the social media you can likely recover the 3d geometry of the face. From that, if the signing algorithm is known, you should be able to replicate these passkeys.

If the algorithm is not known, it’s only a matter of time it’d be leaked or reverse engineered. And then suddenly there’d be a massive, difficult to fix security breach. Just like the breaches that we have now, with voice based authentication.

Can someone explain, how this can be mitigated?

Re: Passkeys: The beginning of the end of the password

#107
post #45

Earlier quoted context omitted.

> The only use-case for biometrics is deanonymization, sold to you under the auspices of security, primarily used for corporate surveillance. Please provide evidence that biometric data has ever been extracted from a major platform (IE Apple/enclave). Absence of evidence != evidence of absence, I know, but you’re selling it as the only use case so surely you have proof.

> Please provide evidence that biometric data has ever been extracted from a major platform Why extract it from a platform when it can be extracted easily from the person? Imagine your password was written on every surface you touched (fingerprint) or is prominently displayed on your social media accounts (face).

How does my use of faceID on my iPhone promote de-anonymization if it doesn’t leave my phone?

Everything you’ve described can be done whether or not I use biometric to sign into a device, or even own a device?

Re: Passkeys: The beginning of the end of the password

#109
post #93

Earlier quoted context omitted.

[flagged]

To avoid being a propagandized lemming you have to have a basic understanding of what is happening... passkeys aren't tied to Google or to any other specific provider. Note that this announcement is just about Google supporting logging to with passkeys to their platform. But you don't have to have anything to do with Google to use passkeys with other sites/apps that support them.

Disguising a proprietary development under an industry standard umbrella is a typical move from Corporate Utopia playbook. That's why it is so easy to spot when somebody tries to manipulate public opinion using social media accounts.

It would be a totally different situation if customers were actually interested in a particular solution. Otherwise, it's all astroturfing and nothing can really change that.

Also it's always a good tone to put a disclaimer, e.g. "Googler".

Re: Passkeys: The beginning of the end of the password

#110
I wrote about my experience with passkey support on other services here: https://news.ycombinator.com/item?id=35758918. That experience was mostly negative. For anyone implementing this, the user experience matters and requires usability testing of a lot of combinations.

In comparison to those, Google’s support seems better. It worked, was transparent about what was going on, and gave me the option to create the key on either the device I was using or another one if I wanted. The one hitch was that when I already had a 2FA key on the same platform authenticator, it just said I already had a registered key on this device and didn’t do anything. I would have expected some sort of upgrade flow for people who previously registered their devices for 2FA, or at least to more directly tell me to delete the existing security key on the device (which is what I did, and which worked).

Post reply on HN