Live data from Hacker News

Passkeys are now enabled by default for Google users

blog.google

61–70 of 684 posts

Re: Passkeys are now enabled by default for Google users

#61

Probably a stupid question but why can't photos of my face be used to defeat this?

This has nothing to do with your face is the simple answer.

If your platform uses face scanning, you can read how it protects you from that.

For FaceID on iOS, it uses additional sensors beyond just a camera.

Re: Passkeys are now enabled by default for Google users

#62
post #23

"To use passkeys, you just use a fingerprint, face scan or pin to unlock your device, and they are 40% faster than passwords — and rely on a type of cryptography that makes them more secure. " Who wrote this sentence? It's just a mess.

also, "ah yes, a several digit pin, famously more secure than a same-length password that adds even as little as letters".

The point is more so that the pin unlocks a key on your local device and that key is much stronger than the password the typical user would select. Plus it is site specific in a way that your typical user does not do with passwords.

So it's making a system weaker against offline attacks if someone steals your hardware in exchange for making it stronger against phishing. This is probably the correct tradeoff for most people.

Re: Passkeys are now enabled by default for Google users

#63
post #44
post #26

Earlier quoted context omitted.

You go through.... account recovery? Like if you lose your password today?

Ah right, account recovery. The one that tells me the only way to sign in to my old Google account is to use a phone that no longer exists.

or to fax/email/send in government identity documents.

Re: Passkeys are now enabled by default for Google users

#64
post #31
post #26

Earlier quoted context omitted.

You go through.... account recovery? Like if you lose your password today?

If you can recover an account without the passkey, how much security is it really adding?

Depends on the recovery mechanism. Providing a government credential with a live selfie is the gold standard. If a company doesn't support that, they're being cheap at the cost of security (you can perform such an identity proof for ~$1-2/per successful proof through a vendor like Stripe Identity or ID.me).

Passkeys solves for digital identity compromise (credential theft or stuffing/spraying), but you must rely on other mechanisms (such as a I mention above) if you want to elevate identity assurance higher in the event of credential loss.

(consumer IAM is a component of my work at a fintech; auth/creds security, passkey rollout, high identity confidence when an account is recovered, etc)

Re: Passkeys are now enabled by default for Google users

#65
Simpson's Paradox lives here.

On average, this might increase security (the vast majority of users are terrible at using passwords).

For proficient users who use passwords securely, this is an acute drop in security (if forced to use).

Forced phone number 2FA has the same effect; in Big G's case forcing phone number 2FA is anti-anonymity disguised as security. In this case, it's a bid for biometrics.

Re: Passkeys are now enabled by default for Google users

#67
Is it hard to remember the one password you use for all Google services everyone's already been doing forever and will still have to do for every other site? When's the last time anyone even had to log into Google on any device? I'm signed in everywhere all the time and it almost never seems to expire...

My desktop doesn't have a camera, fingerprint reader or touch screen...

Re: Passkeys are now enabled by default for Google users

#68
post #34
post #10

Nope, not signing up. The trend from Google continues to be towards "if you lose your phone with your credentials, you will be unable to log in". And Google refuses to create a scalable system that allows you access to your account by verifying your identity in person. This is a recipe for disaster. And, possibly, a warning to move off GMail before it gets worse.

I'm about at the threshold for wanting to de-google my life. Do you have an alternative email provide you recommend?

Anything with working IMAP so you can use your own client. So, not Protonmail or Tutanota.

Re: Passkeys are now enabled by default for Google users

#69
post #5

Why is a pin more secure than a password?

It isn't, and this isn't authentication with a pin. Passkeys also requires the device. Using a pin with this is 2-factor. Pin + hardware token.

So why not just have a password that then unlocks the passkey? I already have a password manager.
Post reply on HN