Live data from Hacker News

Passkeys: The beginning of the end of the password

blog.google

281–290 of 1001 posts

Re: Passkeys: The beginning of the end of the password

#281
post #259
post #135

WebAuthN is great, but I can't help but feel that Passkeys are actually a step backwards. At least on iOS, there is no way of preventing them from being synced to iCloud, which is the opposite of what I want for high-stakes credentials like bank accounts or government e-signatures. I've tried to raise [1] a related issue (i.e. the inability for relying parties to opt out of credential syncing, if not an explicit requ…

You can't even use Passkeys on iOS without using iCloud; if you opt out of iCloud, Passkeys are disabled.

Apparently so; I just saw that as well (and edited my post). Bizarre.

Between that and completely removing anonymous attestation (i.e. implicit device binding), it makes me wonder what Apple's motives here really are...

Re: Passkeys: The beginning of the end of the password

#282
post #222

I'm still salty about this. Called it passkey too. http://www.multipasskey.com/susdemo/ . Built this 5-6yrs ago and applied to YC. Crickets. Hope to see this take off, with my approach I made it where you don't even need to "register", you can go to a site and just have an account. I did the fingerprint, face scan, PIN approach for more security, but my favorite was NFC ring. Basically you have an NFC ring you wear o…

> What I don't like bout Google doing this is that the big providers use this to tether and lock you in to their platform. This is not what they want. They want to a) ensure passwords/accounts aren't being shared to ensure a single account is tied to a single user. They want this for all apps so they can recognize revenue for every user. b) They want more information on you as a user (as opposed to your family member…

Can you explain how passkeys explicitly reaches that end goal, when all of that is already currently possible without passkeys?

Re: Passkeys: The beginning of the end of the password

#283

What are the legal implications of passkeys? Are there any case law examples yet? My understanding is it's 100% impossible to 'prove' I know a password or not as it could be written on a piece of paper somewhere, and it's entirely possible for that paper to be shredded and therefore any proof of that password is gone, forever. I remember hearing you cannot be compelled to hand over a password. Biometrics et al on the…

You don't have to enable the biometric part of this as you can still protect your device with a passcode/password only if you want. I just tested it and was able to use it with just my device PIN, no biometrics.

The part about not being able to be compelled to hand over a password or decrypt something is also not true in many parts of the world. See: https://en.wikipedia.org/wiki/Key_disclosure_law

Re: Passkeys: The beginning of the end of the password

#284
How does google make money? By having information about users and providing that to people who want to 'target' users. So in the interest of making a 'better' user experience we now have google passkeys. Is Google making this to help users or perhaps does it provide more ability to target users. Hmmm.....

You are not googles customers. Advertisers and other agent wanting to target you are google customers.

Channeling someone, "just say no to google." Or "friends don't let friends use google passkeys".

Re: Passkeys: The beginning of the end of the password

#285
post #135

WebAuthN is great, but I can't help but feel that Passkeys are actually a step backwards. At least on iOS, there is no way of preventing them from being synced to iCloud, which is the opposite of what I want for high-stakes credentials like bank accounts or government e-signatures. I've tried to raise [1] a related issue (i.e. the inability for relying parties to opt out of credential syncing, if not an explicit requ…

My cynical assessment of Passkeys is: If Google/Amazon/Apple/Meta/whoever locks your account out, you now lose access everywhere. This isn’t a theoretical risk. You’ll see lots of people complain about this online. Also, Passkey providers now get sweet sweet metadata about your accounts around the web. But yeah, authn is hard to do right. Equally, asking your users to fall into $BIG_PROVIDER’s arms seems wrong. My pe…

[deleted]

Re: Passkeys: The beginning of the end of the password

#286
post #222

I'm still salty about this. Called it passkey too. http://www.multipasskey.com/susdemo/ . Built this 5-6yrs ago and applied to YC. Crickets. Hope to see this take off, with my approach I made it where you don't even need to "register", you can go to a site and just have an account. I did the fingerprint, face scan, PIN approach for more security, but my favorite was NFC ring. Basically you have an NFC ring you wear o…

> What I don't like bout Google doing this is that the big providers use this to tether and lock you in to their platform. This is not what they want. They want to a) ensure passwords/accounts aren't being shared to ensure a single account is tied to a single user. They want this for all apps so they can recognize revenue for every user. b) They want more information on you as a user (as opposed to your family member…

I think it's simpler than that. Expenditure is linked to trust. Companies and platforms that erode trust, make less money in the long run - they have to continually exert energy to attract customers. Companies / platforms that focus on building and retaining your trust have to work less hard to have you part with your money.

Re: Passkeys: The beginning of the end of the password

#287
post #153

I'm still salty about this. Called it passkey too. http://www.multipasskey.com/susdemo/ . Built this 5-6yrs ago and applied to YC. Crickets. Hope to see this take off, with my approach I made it where you don't even need to "register", you can go to a site and just have an account. I did the fingerprint, face scan, PIN approach for more security, but my favorite was NFC ring. Basically you have an NFC ring you wear o…

> use this to tether and lock you in to their platform. You could say this about Google's proprietary authenticator app in the past, but now that they support Passkeys, arguably the opposite is true. Importantly, you can now (with FIDO CTAP 2.2 and tunnel services [1]) use an out-of-platform Passkey to log into your account cross-device, e.g. you can use an iOS Passkey to log into an account on a Windows Chrome insta…

> You could say this about Google's proprietary authenticator app in the past

There's many implementations of OTP. I've never used google's and I've been fine.

Re: Passkeys: The beginning of the end of the password

#288

Earlier quoted context omitted.

My cynical assessment of Passkeys is: If Google/Amazon/Apple/Meta/whoever locks your account out, you now lose access everywhere. This isn’t a theoretical risk. You’ll see lots of people complain about this online. Also, Passkey providers now get sweet sweet metadata about your accounts around the web. But yeah, authn is hard to do right. Equally, asking your users to fall into $BIG_PROVIDER’s arms seems wrong. My pe…

I don’t know about privacy, but the lockout risk doesn’t seem worse than losing your phone or Yubikey. You should have multiple independent ways to log in for any account you care about. Passkey will be one way. Possibly two ways, if you have both Android and iOS devices and you register both? (I assume Android and iOS remain independent.)

So if passkey is just yet another way to log in, then all the security aspects are moot, no? The attacker could still attack the other login methods. E.g., even if the passkey is a secure surface, it does not replace the insecure attack surfaces.
Post reply on HN