Live data from Hacker News

Passkeys are now enabled by default for Google users

blog.google

81–90 of 684 posts

Re: Passkeys are now enabled by default for Google users

#82
post #2

One of my companies switched to Yubi pass keys. They were super cool -- until I tried to log in on a computer with only USB-A ports. My key is USB-C. I suppose I need to get an adapter now.

Passkeys are stored within your device, iPhone, Android, browser, or system keychain. https://passkeys.directory/ https://www.stavros.io/posts/clearing-up-some-passkeys-misco... https://support.apple.com/en-us/102195

Does this work with Linux Desktop ?

Re: Passkeys are now enabled by default for Google users

#84
post #11

Ugh, is this why my FIDO key started making me enter a redundant pin on the company login page (so: enter password, press FIDO key, enter PIN, press FIDO key)?

Yes. That plus the way apple implemented it. In my case i was already on passkeys and google decided to just... forget them all on my other computers. I can't use them to get in anymore. Why? Who the heck knows. This whole passkey shit is going to be a nightmare for UX.

“Weaponized” 2fa (already very common) is a huge UX fail too. In theory this could reduce those terrible flows.

Re: Passkeys are now enabled by default for Google users

#85
post #2

One of my companies switched to Yubi pass keys. They were super cool -- until I tried to log in on a computer with only USB-A ports. My key is USB-C. I suppose I need to get an adapter now.

Passkeys are stored within your device, iPhone, Android, browser, or system keychain. https://passkeys.directory/ https://www.stavros.io/posts/clearing-up-some-passkeys-misco... https://support.apple.com/en-us/102195

What if you use an old-fashioned desktop PC?

Re: Passkeys are now enabled by default for Google users

#86
I see a lot of misinformation, or misunderstanding, of Passkeys in this thread.

I highly recommend reading Steve Gibson's notes on Passkeys from his Security Now! podcast episode #870: https://www.grc.com/sn/sn-870-notes.pdf (p. 10-13)

For context, Gibson developed, and completed, an entirely secure and working solution to the problem Passkeys aims to solve, called SQRL (which I argue is better than Passkeys in a few ways). He is familiar with this problem space, and explains Passkeys in a straightforward way.

You can find this full podcast episode on Twit.tv: https://twit.tv/shows/security-now/episodes/870

You can also find a full text transcript of the episode, transcribed by a human - by hand, here: https://www.grc.com/sn/sn-870.htm

Re: Passkeys are now enabled by default for Google users

#87
post #37

Earlier quoted context omitted.

Passkeys are typically synced to cloud storage.

Not just typically - on iOS, you cannot use them at all without iCloud enabled.

Perfect! I keep iCloud off, so this is one "improvement" I can continue to sidestep for a while.

Re: Passkeys are now enabled by default for Google users

#88
post #13

As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?

Well you just get in touch with a friendly Google customer support representative /s

Re: Passkeys are now enabled by default for Google users

#89
There are a lot of interesting points being made in the conversation here.

What I haven't seen yet is a reminder that a Google Account is effectively Google's private property that they're letting you access in exchange for vacuuming up your personal data.

The only winning move is not to play.

Re: Passkeys are now enabled by default for Google users

#90
post #44
post #26

Earlier quoted context omitted.

You go through.... account recovery? Like if you lose your password today?

Ah right, account recovery. The one that tells me the only way to sign in to my old Google account is to use a phone that no longer exists.

What’s the standard then? Should it be possible to recover your account without possessing any evidence whatsoever that you are the person you say you are?
Post reply on HN