Live data from Hacker News

Passkeys: The beginning of the end of the password

blog.google

441–450 of 1001 posts

Re: Passkeys: The beginning of the end of the password

#441
post #294

The paragraph in the section, "What are passkeys?" tells me that they: are new, are easier, let me use biometrics, and are resistant to attacks. But, it doesn't tell me what passkeys actually are. Compare passkeys to traditional authentication factors. What's a password? A secret word or phrase that only you know. What are biometrics? Parts of your body that can help uniquely identify you, like your fingerprint or re…

I'm not sure how it's all that different from Windows Hello. > Passkeys are easy to set up and let you securely sign in to your Google Account using your fingerprint, face, screen lock, or hardware security key. You can create a passkey on this device, or use another device. When I press [Continue], Windows Security appears where I can then scan my fingerprint which I already use to sign on. A single glide of my fing…

Windows Hello can supply single-device passkeys at the platform level. Browsers and native apps will leverage Hello in the background (a la WebAuthn.DLL).

A passkey is a user facing term. Platforms have been working on technology to support that idea for years now.

There may be a difference in terms of how Windows Hello dictates the user experience vs what browsers show on other platforms - I haven't tried it recently.

Re: Passkeys: The beginning of the end of the password

#442
post #357

Earlier quoted context omitted.

You need to click on the link that is in the post: https://blog.google/technology/safety-security/one-step-clos... > Instead, your phone will store a FIDO credential called a passkey which is used to unlock your online account. The passkey makes signing in far more secure, as it’s based on public key cryptography and is only shown to your online account when you unlock your phone. It looks like a token stored on your…

Why not call it a private key then, we've been handling those since the 70's. They don't need to be rebranded, they need to be taught in high school with the same words we've always used to talk about them.

[deleted]

Re: Passkeys: The beginning of the end of the password

#443
post #157

And once again, with a Google Workspace (or whatever they call it these days) account, "Passkeys aren’t allowed on this account. Contact your admin for help". I am the admin. Doesn't appear there's any way to help.

Paying customers can't use this feature.

> If you have a Google Workspace account through your school or employer, you will not be able to use passkeys to sign in at this time.

Source: https://support.google.com/accounts/answer/13548313?sjid=507...

Re: Passkeys: The beginning of the end of the password

#444
post #153

Earlier quoted context omitted.

> use this to tether and lock you in to their platform. You could say this about Google's proprietary authenticator app in the past, but now that they support Passkeys, arguably the opposite is true. Importantly, you can now (with FIDO CTAP 2.2 and tunnel services [1]) use an out-of-platform Passkey to log into your account cross-device, e.g. you can use an iOS Passkey to log into an account on a Windows Chrome insta…

The article says "Instead, passkeys let users sign in to apps and sites the same way they unlock their devices: with a fingerprint, a face scan or a screen lock PIN." Does that not rather imply that, if I log in with faceid on an iphone, my login will be tied to my ability to faceid on an iphone, and hence only available on iphones and macs? As a user, that's sounding a lot like platform lock-in to me. And as a devel…

> Does that not rather imply that, if I log in with faceid on an iphone, my login will be tied to my ability to faceid on an iphone, and hence only available on iphones and macs?

The authenticator is given a lot of leeway in how it does authentication. In the Apple platform case, it is "the user authentication on the device which is on the iCloud account and has set up iCloud Keychain".

So on my Mac I can use TouchID. On my phone I use FaceID. Both allow me to fall back to the device password (such as when I have the lid on my Mac closed).

Re: Passkeys: The beginning of the end of the password

#445
post #294

The paragraph in the section, "What are passkeys?" tells me that they: are new, are easier, let me use biometrics, and are resistant to attacks. But, it doesn't tell me what passkeys actually are. Compare passkeys to traditional authentication factors. What's a password? A secret word or phrase that only you know. What are biometrics? Parts of your body that can help uniquely identify you, like your fingerprint or re…

If people here can't understand what passkeys are, how are the "normies" gona get it? Or maybe the wide public is not supposed to get it how it works; they should "simply" use it.

You drastically overestimate technical competence on HN. Especially as of late.

Re: Passkeys: The beginning of the end of the password

#446

Earlier quoted context omitted.

It’s a password that Google controls so when they incorrectly ban you from their services you lose access to literally everything. Or if you drop your phone in a lake you’re out of luck too.

Banning has nothing to do with it. You use passkeys as a preferred login method. If you do not have your passkey, you can tap "Try Another Way" and use your password as usual.

[deleted]

Re: Passkeys: The beginning of the end of the password

#447

I'm still salty about this. Called it passkey too. http://www.multipasskey.com/susdemo/ . Built this 5-6yrs ago and applied to YC. Crickets. Hope to see this take off, with my approach I made it where you don't even need to "register", you can go to a site and just have an account. I did the fingerprint, face scan, PIN approach for more security, but my favorite was NFC ring. Basically you have an NFC ring you wear o…

You patent your things, then disseminate. Your ideas will be burglarized, stolen, reintroduced and shown as an invention of someone else (who is a lapdog of given entity).

Re: Passkeys: The beginning of the end of the password

#448
post #294

The paragraph in the section, "What are passkeys?" tells me that they: are new, are easier, let me use biometrics, and are resistant to attacks. But, it doesn't tell me what passkeys actually are. Compare passkeys to traditional authentication factors. What's a password? A secret word or phrase that only you know. What are biometrics? Parts of your body that can help uniquely identify you, like your fingerprint or re…

Agreed, I think we have to move past the general assumption that people do not understand anything written in terms that are even remotely technical. Obviously HN is a tech savvy audience but still software service providers should provide greater clarity into how things actually work and encourage users to think about things more technically instead of just making everything a magical black box.

Re: Passkeys: The beginning of the end of the password

#449
post #341

Earlier quoted context omitted.

I don’t know about privacy, but the lockout risk doesn’t seem worse than losing your phone or Yubikey. You should have multiple independent ways to log in for any account you care about. Passkey will be one way. Possibly two ways, if you have both Android and iOS devices and you register both? (I assume Android and iOS remain independent.)

What if one loses all their devices in a natural disaster, a house fire, or burglary, or lost baggage while traveling? A password is in your head. If you lose that, there's not much use for the said password. But otherwise, it's secure. And it's pretty secure from an infosec perspective if it's a passphrase.

I think it's more likely that you'll lose your password by forgetting it? People forget many things without losing their heads.

There's no perfect solution. Having a printout of backup codes in a fireproof safe is pretty good, but it's of no use while traveling. A Yubikey is good, but it might not work (wrong USB port) and it's a device that could break.

Having multiple ways to log in reduces your risk of lockout, but also makes it more likely that someone unauthorized could get access.

Re: Passkeys: The beginning of the end of the password

#450

I’m a Linux user. I don’t have an android/iOS/macOS/Windows machine. Is there a solution? Is this being used to push Linux users off the internet? Can I just fire up emulated Android and be ok? Am I screwed? Googling indicates I am, indeed, screwed. Pretty concerned about this future.

Passkey is an open standard and there exists FOSS clients which support it.

We should try actually understanding and learning about what's going on instead of assuming that it's a Google conspiracy to kill Linux.

(google contributes heavily to linux anyways?)

Post reply on HN