Live data from Hacker News

Passkeys are now enabled by default for Google users

blog.google

11–20 of 684 posts

Re: Passkeys are now enabled by default for Google users

#11

Ugh, is this why my FIDO key started making me enter a redundant pin on the company login page (so: enter password, press FIDO key, enter PIN, press FIDO key)?

Yes. That plus the way apple implemented it.

In my case i was already on passkeys and google decided to just... forget them all on my other computers. I can't use them to get in anymore. Why? Who the heck knows.

This whole passkey shit is going to be a nightmare for UX.

Re: Passkeys are now enabled by default for Google users

#14
post #5

Why is a pin more secure than a password?

The PIN (or biometric) is not used to replace your Google account password. The PIN (or biometric) is used to authenticate to your device that holds your Passkeys, which in turn will authenticate you to your Google account (or any account that supports Passkey-based sign-in).

Re: Passkeys are now enabled by default for Google users

#15

Isn't it obvious that logging in with your face or your fingerprint is less secure? Sure, it's convenient, but any thug can just forcefully unlock your device.

I think for anyone not working in national security, any thug could just as easily get your password out of you.

Re: Passkeys are now enabled by default for Google users

#16
post #5

Why is a pin more secure than a password?

The PIN is checked by the local device. It never goes over the network, and the device can limit the number of PIN attempts to a very small number, because the only way to try PINs is to have access to the device.

Re: Passkeys are now enabled by default for Google users

#17
This is an interesting direction. It's worth noting that biometrics, like fingerprints or facial recognition, aren't really 'secrets'. They can be observed or leveraged without a users knowledge or consent, and in many ways function more like a username than a password.

Re: Passkeys are now enabled by default for Google users

#19

Isn't it obvious that logging in with your face or your fingerprint is less secure? Sure, it's convenient, but any thug can just forcefully unlock your device.

Most thugs don't have physical access required to exploit this. They're on the other side of the world and are doing credential stuffing attacks.

Re: Passkeys are now enabled by default for Google users

#20
post #18
post #13

As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?

You don't.

That's the great part.
Post reply on HN