Live data from Hacker News

Passkeys are now enabled by default for Google users

blog.google

71–80 of 684 posts

Re: Passkeys are now enabled by default for Google users

#71

Isn't it obvious that logging in with your face or your fingerprint is less secure? Sure, it's convenient, but any thug can just forcefully unlock your device.

In case od data leak - you cannot change your face, or fingerprints. You can change passwords though.

Good news that you can’t bring someone’s face to google and ask for access to their account…

Please don’t insert commentary when it’s clear you don’t know what you’re talking about

Re: Passkeys are now enabled by default for Google users

#72
post #31
post #26

Earlier quoted context omitted.

You go through.... account recovery? Like if you lose your password today?

If you can recover an account without the passkey, how much security is it really adding?

It at least avoids the user being phished or being compromised by reusing passwords.

But it seems in this case the account recovery is just using the password so the passkey is mostly convenience and maybe Google trying to move things away from passwords more than a complete change.

Re: Passkeys are now enabled by default for Google users

#73

Probably a stupid question but why can't photos of my face be used to defeat this?

The biometrics aren't authenticating you. They only unlock your phone, which stores the private key used to authenticate you.

I see. So really this is public/private key authentication and the face/pin/fingerprint etc is just the typical device unlock stuff.

Re: Passkeys are now enabled by default for Google users

#74
post #15

Isn't it obvious that logging in with your face or your fingerprint is less secure? Sure, it's convenient, but any thug can just forcefully unlock your device.

I think for anyone not working in national security, any thug could just as easily get your password out of you.

Reminds me of this wondeful scene in Ronin:

Everybody has a limit. I spent some time in interrogation... once.

They make it hard on you ? - They don't make it easy.

Yeah, it was unpleasant. I held out as long as I could.

All the stuff they tried. You just can't hold out for ever.

How'd they finally get to you?

They gave me a grasshopper. - What's a grasshopper?

That's two part gin, two part brandy, one part crème de menthe...

Re: Passkeys are now enabled by default for Google users

#75
post #38

As usual, the multi-device/multi-OS and recovery scenarios are simply just glossed over. I'll stick with a password vault I can sync to multiple OSes, thanks.

You can associate multiple passkeys with your account. Your account can have a passkey that is synced across Android/Chrome, and another passkey that is synced across Apple devices and browsers.

Re: Passkeys are now enabled by default for Google users

#77

Earlier quoted context omitted.

The biometrics aren't authenticating you. They only unlock your phone, which stores the private key used to authenticate you.

I see. So really this is public/private key authentication and the face/pin/fingerprint etc is just the typical device unlock stuff.

Yes, that's mostly it.

Re: Passkeys are now enabled by default for Google users

#79
post #69

Earlier quoted context omitted.

It isn't, and this isn't authentication with a pin. Passkeys also requires the device. Using a pin with this is 2-factor. Pin + hardware token.

So why not just have a password that then unlocks the passkey? I already have a password manager.

Sure, PINs can be long and alphanumeric on most phones these days.

Re: Passkeys are now enabled by default for Google users

#80
post #31

Earlier quoted context omitted.

If you can recover an account without the passkey, how much security is it really adding?

It at least avoids the user being phished or being compromised by reusing passwords. But it seems in this case the account recovery is just using the password so the passkey is mostly convenience and maybe Google trying to move things away from passwords more than a complete change.

> maybe Google trying to move things away from passwords more than a complete change

Google wants to be a gateway to everything else you do.

The next step is to get other platforms to accept Google passwordless auth.

Post reply on HN