Live data from Hacker News

Passkeys: The beginning of the end of the password

blog.google

201–210 of 1001 posts

Re: Passkeys: The beginning of the end of the password

#201
post #153

Earlier quoted context omitted.

> use this to tether and lock you in to their platform. You could say this about Google's proprietary authenticator app in the past, but now that they support Passkeys, arguably the opposite is true. Importantly, you can now (with FIDO CTAP 2.2 and tunnel services [1]) use an out-of-platform Passkey to log into your account cross-device, e.g. you can use an iOS Passkey to log into an account on a Windows Chrome insta…

The article says "Instead, passkeys let users sign in to apps and sites the same way they unlock their devices: with a fingerprint, a face scan or a screen lock PIN." Does that not rather imply that, if I log in with faceid on an iphone, my login will be tied to my ability to faceid on an iphone, and hence only available on iphones and macs? As a user, that's sounding a lot like platform lock-in to me. And as a devel…

Ever site I've accessed with a passkey lets you tie it to an existing account with a username/password, Google login, Apple login, iPhone, YubiKey, etc. I've not used a passkey where that was the _only_ auth I could create on an account.

Re: Passkeys: The beginning of the end of the password

#202

I'm still salty about this. Called it passkey too. http://www.multipasskey.com/susdemo/ . Built this 5-6yrs ago and applied to YC. Crickets. Hope to see this take off, with my approach I made it where you don't even need to "register", you can go to a site and just have an account. I did the fingerprint, face scan, PIN approach for more security, but my favorite was NFC ring. Basically you have an NFC ring you wear o…

Apple, Google and Microsoft are all supporting passkeys

https://developer.apple.com/passkeys/

https://arstechnica.com/information-technology/2022/10/passk...

Re: Passkeys: The beginning of the end of the password

#203
post #153

Earlier quoted context omitted.

> use this to tether and lock you in to their platform. You could say this about Google's proprietary authenticator app in the past, but now that they support Passkeys, arguably the opposite is true. Importantly, you can now (with FIDO CTAP 2.2 and tunnel services [1]) use an out-of-platform Passkey to log into your account cross-device, e.g. you can use an iOS Passkey to log into an account on a Windows Chrome insta…

The article says "Instead, passkeys let users sign in to apps and sites the same way they unlock their devices: with a fingerprint, a face scan or a screen lock PIN." Does that not rather imply that, if I log in with faceid on an iphone, my login will be tied to my ability to faceid on an iphone, and hence only available on iphones and macs? As a user, that's sounding a lot like platform lock-in to me. And as a devel…

You can use your device passcode instead of FaceID.

Re: Passkeys: The beginning of the end of the password

#204
post #50

Earlier quoted context omitted.

1. You're tricked into visiting evil.example and don't realize it. 2. evil.example: confirm 2fa code to log in. 3. evil.example starts logging into good.example as you, triggering good.example to send the 2fa code. 4. You see the 2fa code and enter it into evil.example. 5. evil.example has phished your 2fa code. This doesn't work with passkeys (or 2fa tokens) because those verify the domain matches.

Yes, I understand how phishing with 2fa works. But to me, passkeys sound like 2fa with your fingerprint/smartphone PIN? What's actually different there?

The difference is in step 4. With SMS or one-time code 2FA (or passwords) you're just entering text into a website, and nothing verifies you're interacting with the right website. With passkeys or FIDO tokens, though, there's a cryptographic protocol that considers the domain: your fingerprint/PIN isn't sent to the website.

Re: Passkeys: The beginning of the end of the password

#205
post #5

How is this more secure? They say "with a fingerprint, a face scan or a screen lock PIN", but basically all phones let you fall back to PINs if you dont want to do face or fingerprints. Pins are flat out not secure - typically just 4 digits. Yeah its probably better than 80% of people having "password123", but it seems strictly worse than a password + password manager? Or at least just having proper 2FA.

>with a fingerprint, a face scan or a screen lock PIN I agree - not secure. And just a daily reminder that biometrics are usernames , they are not passwords. You can change a password, a lock, a key, you cannot change biometrics, and thus they should not be used for guarding sensitive info. The only use-case for biometrics is deanonymization, sold to you under the auspices of security, primarily used for corporate su…

Biometrics are shitty usernames too. They might change, it's just outside of your control.

My apple touchID never works because I rock climb and I guess that abrades the skin too much

Re: Passkeys: The beginning of the end of the password

#206
post #80
post #62

Anyone know if it's possible to use this with Google Workspace accounts yet? From the Google Blog I clicked on "Today, passkeys for Google Accounts are available. You can try them out here" However, I got: "Passkeys aren’t allowed on this account. Contact your admin for help" And the Workspace admin page doesn't seem to include any options for Passkeys.

Same here, but note that in this post on the Google Security Blog: https://security.googleblog.com/2023/05/so-long-passwords-th... the first sentence reads, "Starting today, you can create and use passkeys on your personal Google Account." (Emphasis mine.)

Disclaimer: I work for Google but nothing I say here is Google's opinion or relies on any Google internal information.

I'm not surprised that Workspace accounts weren't included in the initial rollout. Workspace setups have interesting requirements that aren't necessarily there for personal accounts. For example, under some circumstances, if an employee gets hit by a bus, and there is critical business data which is stored in the employee's account, an appropriately authorized Workspace admin is supposed to be able to gain access to the employee's account. But what is the right thing to do for passkey access? Especially if the user uses passkey to authenticate to some non-:Google resource like, say, Slack which has been set up for corporate use? Should the workspace admin be able to impersonate the corporate employee in order to gain access to non-Google resources via passkey? What about if the employee (accidentally) uses their corporate account to set up a passkey to a personal account, such as for example E*Trade? Maybe the Workspace admin should have a setting where passkey creation is disabled except for an allowlist of domains that are allowed for corporate workflows? It's complicated, and if I were the product manager, I'd want to take my time, understand all of the different customer requirements (where customer === the Workspace administrator who is paying the bills) before rolling out support for Workspace accounts.

Re: Passkeys: The beginning of the end of the password

#207
post #4

I hate this, I hate every part of this. The attempt to get rid of passwords has been the biggest assault on the free internet in recent history, and people are asleep at the wheel as it's happening. They want to tie you to an external service, so they can tie you to your phone, which they also manage with another external service. All of these schemes are braindead with obtuse, user-unfriendly backup/transfer/restore…

But you still need a password to use a passkey right? So passwords aren’t going away, they’re just being used to a more secure way. My mom can’t tell if a website is fake if it’s made to look exactly like Facebook, for example. So in a sense passwords are actually awful for users because they’re required to remember dozens of passwords and verify that a website is legit. If they just reuse the same password everywher…

> remember dozens of passwords and verify that a website is legit

Or use a password manager to solve both of these issues

Except you're not tied to a magic phone

Re: Passkeys: The beginning of the end of the password

#208
> Instead, passkeys let users sign in to apps and sites the same way they unlock their devices: with a fingerprint, a face scan or a screen lock PIN.

So, for the vast majority that does not have hardware that supports fingerprint reading or face-scanning, this grand new alternative to passwords is... passwords?

I get that it's nice for phones, but that's only about 50% of the web's traffic.

Re: Passkeys: The beginning of the end of the password

#209
post #135

WebAuthN is great, but I can't help but feel that Passkeys are actually a step backwards. At least on iOS, there is no way of preventing them from being synced to iCloud, which is the opposite of what I want for high-stakes credentials like bank accounts or government e-signatures. I've tried to raise [1] a related issue (i.e. the inability for relying parties to opt out of credential syncing, if not an explicit requ…

My cynical assessment of Passkeys is: If Google/Amazon/Apple/Meta/whoever locks your account out, you now lose access everywhere. This isn’t a theoretical risk. You’ll see lots of people complain about this online. Also, Passkey providers now get sweet sweet metadata about your accounts around the web. But yeah, authn is hard to do right. Equally, asking your users to fall into $BIG_PROVIDER’s arms seems wrong. My pe…

I don’t know about privacy, but the lockout risk doesn’t seem worse than losing your phone or Yubikey. You should have multiple independent ways to log in for any account you care about. Passkey will be one way.

Possibly two ways, if you have both Android and iOS devices and you register both? (I assume Android and iOS remain independent.)

Post reply on HN