Live data from Hacker News

Passkeys are now enabled by default for Google users

blog.google

131–140 of 684 posts

Re: Passkeys are now enabled by default for Google users

#131
post #13

As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?

And if I loose for some reason access to my phone number, termination of current number to create a new line with a new phone, I loose access to Gmail forever ?

Re: Passkeys are now enabled by default for Google users

#132
post #13

As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?

And what if somebody breaks into my google/iCloud account and syncs all my passkeys to their machines?

The passkeys are encrypted before leaving your machine and Google/iCloud are only storing the encrypted passkeys and can't decrypt them.

Re: Passkeys are now enabled by default for Google users

#133
post #31
post #26

Earlier quoted context omitted.

You go through.... account recovery? Like if you lose your password today?

If you can recover an account without the passkey, how much security is it really adding?

That depends entirely on how rigorous the recovery process is.

Re: Passkeys are now enabled by default for Google users

#134

Earlier quoted context omitted.

> What is the account recovery process if I’m locked out and don’t have my phone, say it’s lost or broken and I can’t verify my identity? > You can always fall back to legacy authentication options such as passwords and traditional 2-step-verification. In a case where you can no longer remember your password, you can also go through Google’s Account recovery flow. We encourage you to add your email and phone number t…

Then what's the point of it all if a hacker can still get into my account using the traditional methods? This seems to be just opening up another avenue of attack.

My Google account is set up such that account recovery requires me to actually travel to Mountain View and present several forms of ID, and that's just how I want it to be.

Re: Passkeys are now enabled by default for Google users

#135
post #69

Earlier quoted context omitted.

It isn't, and this isn't authentication with a pin. Passkeys also requires the device. Using a pin with this is 2-factor. Pin + hardware token.

So why not just have a password that then unlocks the passkey? I already have a password manager.

If you already have a password manager it might already or might soon natively support passkeys as well (1Password already does as an example)

Re: Passkeys are now enabled by default for Google users

#136
post #13

As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?

You get a new device, load your keys from the cloud and use the same screen lock key to decrypt the downloaded keys.

Even if it's passwordless by default doesn't mean there is no passwords for recovery.

Re: Passkeys are now enabled by default for Google users

#137

Earlier quoted context omitted.

What’s the standard then? Should it be possible to recover your account without possessing any evidence whatsoever that you are the person you say you are?

Other businesses have humans on staff which will verify your identity documents. Google simply chooses not to do this, because it is expensive, and their "users" are not their customers.

Right, then you can just pay for Google's rather affordable non-free business version. Then you'll get reasonable support, well-reputed support.

Re: Passkeys are now enabled by default for Google users

#138
post #81

Always remember that passwords are protected by Fifth Amendment and similiar laws in other countries, but there is no law prohibiting officer to put your phone in front of your face to unlock it.

Why make claims for other locations when you don't know about them, and it could lead to serious consequences? In particular the UK has no such compunction.

Re: Passkeys are now enabled by default for Google users

#139

Earlier quoted context omitted.

> What is the account recovery process if I’m locked out and don’t have my phone, say it’s lost or broken and I can’t verify my identity? > You can always fall back to legacy authentication options such as passwords and traditional 2-step-verification. In a case where you can no longer remember your password, you can also go through Google’s Account recovery flow. We encourage you to add your email and phone number t…

Then what's the point of it all if a hacker can still get into my account using the traditional methods? This seems to be just opening up another avenue of attack.

If I understand it correctly it will avoid phishing, assuming people notice there's something up when they see a page asking for a traditional login for no good reason when they have passkeys. And it may be a transitionary step towards no passwords or something.

Re: Passkeys are now enabled by default for Google users

#140

Earlier quoted context omitted.

What’s the standard then? Should it be possible to recover your account without possessing any evidence whatsoever that you are the person you say you are?

Other businesses have humans on staff which will verify your identity documents. Google simply chooses not to do this, because it is expensive, and their "users" are not their customers.

They have offered this since 2017, in response to the Podesta email hack. It's free, but it's not the default, because traveling to a Google site is prohibitively expensive for the vast majority of their users.

https://landing.google.com/advancedprotection

Post reply on HN