Probably a stupid question but why can't photos of my face be used to defeat this?
If your platform uses face scanning, you can read how it protects you from that.
For FaceID on iOS, it uses additional sensors beyond just a camera.
61–70 of 684 posts
Probably a stupid question but why can't photos of my face be used to defeat this?
If your platform uses face scanning, you can read how it protects you from that.
For FaceID on iOS, it uses additional sensors beyond just a camera.
"To use passkeys, you just use a fingerprint, face scan or pin to unlock your device, and they are 40% faster than passwords — and rely on a type of cryptography that makes them more secure. " Who wrote this sentence? It's just a mess.
also, "ah yes, a several digit pin, famously more secure than a same-length password that adds even as little as letters".
So it's making a system weaker against offline attacks if someone steals your hardware in exchange for making it stronger against phishing. This is probably the correct tradeoff for most people.
Earlier quoted context omitted.
You go through.... account recovery? Like if you lose your password today?
Ah right, account recovery. The one that tells me the only way to sign in to my old Google account is to use a phone that no longer exists.
Earlier quoted context omitted.
You go through.... account recovery? Like if you lose your password today?
If you can recover an account without the passkey, how much security is it really adding?
Passkeys solves for digital identity compromise (credential theft or stuffing/spraying), but you must rely on other mechanisms (such as a I mention above) if you want to elevate identity assurance higher in the event of credential loss.
(consumer IAM is a component of my work at a fintech; auth/creds security, passkey rollout, high identity confidence when an account is recovered, etc)
On average, this might increase security (the vast majority of users are terrible at using passwords).
For proficient users who use passwords securely, this is an acute drop in security (if forced to use).
Forced phone number 2FA has the same effect; in Big G's case forcing phone number 2FA is anti-anonymity disguised as security. In this case, it's a bid for biometrics.
does this work in conjunction with multifactor authentication? like biometric + one time passcode?
My desktop doesn't have a camera, fingerprint reader or touch screen...
Nope, not signing up. The trend from Google continues to be towards "if you lose your phone with your credentials, you will be unable to log in". And Google refuses to create a scalable system that allows you access to your account by verifying your identity in person. This is a recipe for disaster. And, possibly, a warning to move off GMail before it gets worse.
I'm about at the threshold for wanting to de-google my life. Do you have an alternative email provide you recommend?
[flagged]