Live data from Hacker News

Passkeys are now enabled by default for Google users

blog.google

41–50 of 684 posts

Re: Passkeys are now enabled by default for Google users

#43
A FAQ at the bottom answers some questions https://safety.google/authentication/passkey/ .

Seems that the recovery if you lose the devices with stored passkeys is still using a password.

And will it be possible to use software keys and backup them to wherever I want and use them with Google or is it going to demand TPMs or that I keep the key in a secure vault in my phone or something or the sort?

There still isn't a way to use this on desktop Linux right?

Re: Passkeys are now enabled by default for Google users

#44
post #26
post #13

As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?

You go through.... account recovery? Like if you lose your password today?

Ah right, account recovery. The one that tells me the only way to sign in to my old Google account is to use a phone that no longer exists.

Re: Passkeys are now enabled by default for Google users

#47
post #13

As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?

> What is the account recovery process if I’m locked out and don’t have my phone, say it’s lost or broken and I can’t verify my identity?

> You can always fall back to legacy authentication options such as passwords and traditional 2-step-verification. In a case where you can no longer remember your password, you can also go through Google’s Account recovery flow. We encourage you to add your email and phone number to ensure you can always access your account.

> https://safety.google/authentication/passkey/

Re: Passkeys are now enabled by default for Google users

#49

Isn't it obvious that logging in with your face or your fingerprint is less secure? Sure, it's convenient, but any thug can just forcefully unlock your device.

Most "thugs" interested in data sit in windowless offices in Manila or Delhi and effortlessly spam phishing and other attacks on weak credentials; they do not roam the streets looking for face-unlockable devices to exfiltrate. That is to say, almost all attacks are remote. And just because someone walking next to you on the street might have a black belt in martial arts, does not mean they're going to turn you into a pretzel on sight.

The reality is people are not good at creating, managing and using credentials well - and this is an existential risk for most users not realized until it's possibly too late. Any efforts to assist, support and otherwise absolve users of credential responsibility is a net win for infosec (though likely a loss for privacy).

Post reply on HN