Live data from Hacker News

Passkeys: The beginning of the end of the password

blog.google

331–340 of 1001 posts

Re: Passkeys: The beginning of the end of the password

#331
post #158

Dumb questions: 1. what's the backup login mechanism when you lose your mobile device? 2. with Passkeys enabled/used, will this stop google from randomly locking my account because I happen to be a person who travels a lot and they constantly think I'm a fraudster attempting to log into my own account. 3a. can I use my google passkey for logging into non-Google sites? 3b. can I use my google passkey (biometric) to lo…

> 1. what's the backup login mechanism when you lose your mobile device? Passkeys are synced to the cloud by default on iOS and Android, which is probably a good idea for many use cases, but might not be what you want in some instances. > will this stop google from randomly locking my account because I happen to be a person who travels a lot and they constantly think I'm a fraudster attempting to log into my own acco…

>Passkeys are synced to the cloud by default on iOS and Android, which is probably a good idea for many use cases,

Gtfo.

Re: Passkeys: The beginning of the end of the password

#332

> passkeys are resistant to online attacks like phishing, making them more secure than things like SMS one-time codes. What is the scenario in which SMS one-time codes are prone to fishing, but passkeys are not?

https://en.wikipedia.org/wiki/SIM_swap_scam

Yeah okay, but then just don't do 2fa via SMS. How are passkeys better than a 2fa app on my smartphone?

Re: Passkeys: The beginning of the end of the password

#333

Came to HN today figuring there would be a thread about this, after getting an email about it from Google themselves, riddled with things causing me to wonder if the message was spoofed: 1. "Dear User" -- other emails I've gotten from Google say "Hello" or "Hi " or have no salutation at all. 2. The main section begins with "Passkey support will be integrated because they’re easier to use, and safer than most other fo…

> I've seen countless "how to spot phishing" guides

One of the things you'd see those guides mention a lot is the call to action. The bad guys want you to do something for them, otherwise they wouldn't send you email.

In contrast the Google email you're complaining about says, "No action is required from you" which is my favourite type of letter from every company. Can I forget all about this and take no action? You bet I can.

Re: Passkeys: The beginning of the end of the password

#334

I'm still salty about this. Called it passkey too. http://www.multipasskey.com/susdemo/ . Built this 5-6yrs ago and applied to YC. Crickets. Hope to see this take off, with my approach I made it where you don't even need to "register", you can go to a site and just have an account. I did the fingerprint, face scan, PIN approach for more security, but my favorite was NFC ring. Basically you have an NFC ring you wear o…

Cool idea about the NFC ring. Is there anything like that now? Any application?

Re: Passkeys: The beginning of the end of the password

#335
Argh.

Passwords are amazing. I loathe many of the attempts at replacing them simply because the _average_ user has proven to be unable to manage them.

The three factors of authentication are a thing because they all protect against somewhat orthogonal threat vectors.

Possession "have" is nice because it binds the authentication to a single thing in the real world (as opposed to some digital thing that can be copied endlessly). Biometrics, if nice, is something that is relatively unique and always carried with you (mostly identification), and bind the factor to a person, secrets like passwords are nice because they essentially bind the factor to the intent, in that a user displays their secret behaviour (of which passwords are one) as opposed to not displaying the behaviour.

Articles that solely focus on the downsides of passwords, often neglect downsides of the other factor types. What are ways the strong personal binding of the "are" factor can be abused if there is no intent? FaceID/TouchID on sleeping or otherwise inattentive persons is a prime one.

All factor-types can work in ways that complement eachother. Removing or at least weakening passwords is not a good way forward, we need to work on fusing all the factor-types jnto a single strong 3-factor auth

Re: Passkeys: The beginning of the end of the password

#336
I don't use my google account for much anymore, but I love the idea. I tried very hard to use it and... it didn't work.

I went to my google account and clicked "Create a passkey", but apparent my "device doesn't support creating passkeys" (Linux, Firefox).

The page said my Pixel 2 has an automatically created passkey, so maybe I could experience the "use another device to sign in" flow. Opened a private window and my only option was a password (but there was a feedback prompt asking why I still wanted to use a password).

I tried again with Firefox on Android, but the "Create a passkey" button doesn't even appear. Same story with Chrome on Android.

Is it just me, or does the future look a lot like Internet Explorer in the early 2000s?

Re: Passkeys: The beginning of the end of the password

#337
post #294

The paragraph in the section, "What are passkeys?" tells me that they: are new, are easier, let me use biometrics, and are resistant to attacks. But, it doesn't tell me what passkeys actually are. Compare passkeys to traditional authentication factors. What's a password? A secret word or phrase that only you know. What are biometrics? Parts of your body that can help uniquely identify you, like your fingerprint or re…

From what I can find the word passkey is just a synonym for password. So yes, none of this makes any sense.

It makes sense if you want to move from two factor authentication to just the second factor while making it seem new and cool?

It seems to be smoke and mirrors for you register a bunch of TPM/HSM.

Re: Passkeys: The beginning of the end of the password

#338
post #135

WebAuthN is great, but I can't help but feel that Passkeys are actually a step backwards. At least on iOS, there is no way of preventing them from being synced to iCloud, which is the opposite of what I want for high-stakes credentials like bank accounts or government e-signatures. I've tried to raise [1] a related issue (i.e. the inability for relying parties to opt out of credential syncing, if not an explicit requ…

My cynical assessment of Passkeys is: If Google/Amazon/Apple/Meta/whoever locks your account out, you now lose access everywhere. This isn’t a theoretical risk. You’ll see lots of people complain about this online. Also, Passkey providers now get sweet sweet metadata about your accounts around the web. But yeah, authn is hard to do right. Equally, asking your users to fall into $BIG_PROVIDER’s arms seems wrong. My pe…

Giving your passwords to a company that cares about money more than you is risky. But losing devices with passkeys is a big problem too. Even if passkeys are saved to your Google, Apple, or Microsoft account, if that account itself is behind a passkey, how do you access it if your phone holding the key breaks? If a disaster or fire happens, all your devices could be gone.

Passwords are good because you remember them in your head, so long as the head works, so do the passwords. This might be an obvious statement, but it's clear passkey providers kind of glance over it.

Re: Passkeys: The beginning of the end of the password

#339
post #294

The paragraph in the section, "What are passkeys?" tells me that they: are new, are easier, let me use biometrics, and are resistant to attacks. But, it doesn't tell me what passkeys actually are. Compare passkeys to traditional authentication factors. What's a password? A secret word or phrase that only you know. What are biometrics? Parts of your body that can help uniquely identify you, like your fingerprint or re…

Passwords will never be supplanted unless the new challenger can satisfy all of the following: * Easy to understand. (A password is just a word/phrase/string of characters only you know.) * Easy to use. (Using a password only requires remembering and typing it in when prompted.) * Convenient. (Only your ability to remember and type required. No other tools or gadgets required.) * Simple. (All of the above.) If someth…

It's also private.

Do you really want your only means of logging into a service identify you because it's also the only way you log into your banking?

And should you want to kill off an identity so you want to have to register everything?!

Re: Passkeys: The beginning of the end of the password

#340
I've yet to figure out how passkeys can be useful for someone who switches between multiple devices (and platforms) throughout the day, and who wants to retain control over where tokens are stored. I have switched as many of my MFA credentials as possible to TOTP and have avoided Yubikeys because I don't want to be tied to a single piece of hardware that can be easily lost, or to an identity provided that may decide to lock me out...
Post reply on HN