Live data from Hacker News

Passkeys are now enabled by default for Google users

blog.google

31–40 of 684 posts

Re: Passkeys are now enabled by default for Google users

#31
post #26
post #13

As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?

You go through.... account recovery? Like if you lose your password today?

If you can recover an account without the passkey, how much security is it really adding?

Re: Passkeys are now enabled by default for Google users

#32
post #2

One of my companies switched to Yubi pass keys. They were super cool -- until I tried to log in on a computer with only USB-A ports. My key is USB-C. I suppose I need to get an adapter now.

Passkeys are stored within your device, iPhone, Android, browser, or system keychain. https://passkeys.directory/ https://www.stavros.io/posts/clearing-up-some-passkeys-misco... https://support.apple.com/en-us/102195

They don’t have to be though, a yubikey can be used as a passkey as well.

Re: Passkeys are now enabled by default for Google users

#33

This is an interesting direction. It's worth noting that biometrics, like fingerprints or facial recognition, aren't really 'secrets'. They can be observed or leveraged without a users knowledge or consent, and in many ways function more like a username than a password.

Passkeys really aren't biometric authentication per se. If you use TouchID, for instance, Google isn't authenticating you based on your fingerprint. Rather, the fingerprint merely unlocks the cryptographic key pair that's then used to authenticate you.

I use Yubico Security Keys myself as passkeys. They're protected by a 6-digit PIN. But that PIN is strictly local to the device, meant to prevent snoops from logging in just by having physical access to the device (the keys get blown away after 10 consecutive unsuccessful PIN attempts). When I enter the PIN, the keys unlock, and it's those keys that get me into my Google account.

Re: Passkeys are now enabled by default for Google users

#34
post #10

Nope, not signing up. The trend from Google continues to be towards "if you lose your phone with your credentials, you will be unable to log in". And Google refuses to create a scalable system that allows you access to your account by verifying your identity in person. This is a recipe for disaster. And, possibly, a warning to move off GMail before it gets worse.

I'm about at the threshold for wanting to de-google my life. Do you have an alternative email provide you recommend?

Re: Passkeys are now enabled by default for Google users

#35

This is an interesting direction. It's worth noting that biometrics, like fingerprints or facial recognition, aren't really 'secrets'. They can be observed or leveraged without a users knowledge or consent, and in many ways function more like a username than a password.

Passwords are also not entirely secret, as they're shared by definition. Passkeys use public-private key crypto, which is more secure in every way.

Re: Passkeys are now enabled by default for Google users

#37
post #13

As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?

Passkeys are typically synced to cloud storage.

Not just typically - on iOS, you cannot use them at all without iCloud enabled.

Re: Passkeys are now enabled by default for Google users

#39
post #13

As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?

I think you’ll still need a password on your account for cases where no passkey is available, and possibly for other scenarios of heightened fraud risk. That’s why the setting they’re describing in the blog post is named “Skip password when possible”.

Disclaimer: although I worked for Google many years ago in a role entirely unrelated to Google account authentication, I have no inside info on this announcement, could be wrong about what I say in the first sentence of this comment, and am not speaking for Google here.

Re: Passkeys are now enabled by default for Google users

#40

Earlier quoted context omitted.

Passkeys are stored within your device, iPhone, Android, browser, or system keychain. https://passkeys.directory/ https://www.stavros.io/posts/clearing-up-some-passkeys-misco... https://support.apple.com/en-us/102195

They don’t have to be though, a yubikey can be used as a passkey as well.

They can be, but most people will use what is built into their mobile ecosystem of choice, with built in sync/backup. Physical secure authenticators in general use will likely remain rare, but are still useful for use cases where passkeys that can be synced or migrated are not secure enough (and you want access governed with a simple physical device).
Post reply on HN