Live data from Hacker News

Passkeys are now enabled by default for Google users

blog.google

171–180 of 684 posts

Re: Passkeys are now enabled by default for Google users

#171
post #130

Correct me if I'm wrong but isn't it fair to say that passkeys secured on your phone are more secure than 1FA (password) but less secure than "traditional" 2FA? Passkey 2FA: unlock your phone and the passkey on your phone can log you in. Traditional 2FA: remember a password AND unlock your phone (where your TOTP is stored) and you can login If I were to rate all 3 methods on a scale of 1 to 10, for convenience and se…

Nobody should be using a remembered password anymore. Most people are likely using the phone for both the password and the MFA code.

[deleted]

Re: Passkeys are now enabled by default for Google users

#172
post #13

As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?

I had a fire. I lost every single thing I own, except my landlord grabbed my phone, bless him. Otherwise I would have been totally stuck as all my TOTP apps are on there. Also, never lose your phone number. I can't get back into my Google account even though I have the username, password and recovery email because I can never get the SMS code.

Have had to recover from 0 pretty similarly. My backup approach basically started with the fact that I knew the password to a cloud storage account that I had uploaded a keepass vault to, and that keepass vault had the password to my primary backup provider. In a full no passwords world, I would have had no chance to do so.

Re: Passkeys are now enabled by default for Google users

#174

Earlier quoted context omitted.

What’s the standard then? Should it be possible to recover your account without possessing any evidence whatsoever that you are the person you say you are?

I'm willing to bet Google already has a frighteningly accurate ability to determine whether I am associated with or own a particular account.

I've been locked permanently out of a (thankfully tertiary) Gmail account because their ML didn't like that I logged in from my new house. The option was to accept a push notification to a long dead and wiped phone.

Re: Passkeys are now enabled by default for Google users

#175
post #13

As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?

I had a fire. I lost every single thing I own, except my landlord grabbed my phone, bless him. Otherwise I would have been totally stuck as all my TOTP apps are on there. Also, never lose your phone number. I can't get back into my Google account even though I have the username, password and recovery email because I can never get the SMS code.

In my country my phone number is linked to my government issued ID so I don't need any physical properties to recover it (this might take some time though but for me it's still the best option).

Re: Passkeys are now enabled by default for Google users

#176
post #13

As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?

I had a fire. I lost every single thing I own, except my landlord grabbed my phone, bless him. Otherwise I would have been totally stuck as all my TOTP apps are on there. Also, never lose your phone number. I can't get back into my Google account even though I have the username, password and recovery email because I can never get the SMS code.

> Also, never lose your phone number. I can't get back into my Google account even though I have the username, password and recovery email because I can never get the SMS code.

This is an excellent point. Google seems to be uninterested in addressing this transparently, but despite their push for phishing-resistant MFA and first factor sign-in options, they still consider a phone number to be golden evidence.

My father changed his phone number last year and never updated his Google account. Despite having a recovery email address he could access, TOTP, and printed backup codes, it was not enough. Google wanted to “verify it really was him” after a move (and IP address change) and it doesn’t even allow a password reset to be authenticated with any other recovery option. Phone number or bust.

Re: Passkeys are now enabled by default for Google users

#177
post #13

As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?

Updated my paper:

https://news.ycombinator.com/item?id=37833390

Scenarios dealing with the loss of Passkeys:

The scenarios for dealing with the loss of Passkeys are effectively the same as dealing with the loss of your Password Manager (if you use one) or otherwise stored passwords.

Dealing with the loss of all your devices that use Passkeys If you manage to lose access to all your devices that are used to authenticate via Passkeys (e.g., a house fire), then there are two main outcomes: either you have your Passkeys synchronized to a cloud provider or other external entity that still has a copy of all your Passkeys, or you do not. If you do not have a backup of all your Passkeys, they are gone, and you will need to fall back to account recovery for each affected account. If you have a backup of your Passkeys, you would need to regain access to it on a new device and then synchronize the Passkeys to it and use them as normal.

Dealing with the loss of your accounts that synchronize and store Passkeys If you use a synchronization service attached to an account, it is possible that the account can be deleted or access to it otherwise lost. In this event, you would most likely still have a working copy of your Passkeys on your devices, and depending on whether or not you can export them or reconfigure synchronization with a new account, you would be able to add them to a new account, effectively creating a new account to store and synchronize your Passkeys.

Dealing with the loss of all your Passkeys

If your Passkey account is not only deleted but also tells all your devices to delete the Passkeys, or you lose all your devices and the accounts are deleted due to inactivity then you are basically in the same situation as having lost all your devices and not having a backup. You will need to fall back to account recovery for each affected account.

Re: Passkeys are now enabled by default for Google users

#178

G: Here's a cool new security feature! HN: Yeah, but what if disaster scenario ? A1: If you're authenticating to Google because your $DAYJOB mandates it, contact your Enterprise Administrator. As part of their multi-gazillion deal with the dark side, I'm sure there is some kind of support for a recovery mechanism, and if there isn't: yeah paid holiday until they figure it out! A2: If you rely on Google for personal-s…

I mean, A2 is a problem. I'd wager that more people are selecting how to manage their personal accounts than selecting how to manage accounts for an enterprise.

Re: Passkeys are now enabled by default for Google users

#179
post #160

Correct me if I'm wrong but isn't it fair to say that passkeys secured on your phone are more secure than 1FA (password) but less secure than "traditional" 2FA? Passkey 2FA: unlock your phone and the passkey on your phone can log you in. Traditional 2FA: remember a password AND unlock your phone (where your TOTP is stored) and you can login If I were to rate all 3 methods on a scale of 1 to 10, for convenience and se…

No, if you break into a site using passkeys, it gives you literally zero information that can be used to authenticate as any of the users. Think about the prevalence of data breaches in the past decade, and the sharp rise in the effectiveness of password stuffing, and think about why this change might be a good idea. Also even with traditional 2FA, TOTP can be phished. See https://github.com/kgretzky/evilginx2 WebAut…

>No, if you break into a site using passkeys, it gives you literally zero information that can be used to authenticate as any of the users. Think about the prevalence of data breaches in the past decade, and the sharp rise in the effectiveness of password stuffing, and think about why this change might be a good idea.

An implication of that is passkeys let you use the same authenticators across multiple services safely. Instead of keeping track of unique passwords across all those services (or worse, reusing passwords), you can just have a passkey-registered phone and one or two Yubikeys for backups/convenience. You'd be a very hard target for account compromise. That setup is highly phishing-resistant and immune to credential-stuffing, without the cognitive load of passwords.

Re: Passkeys are now enabled by default for Google users

#180
post #174

Earlier quoted context omitted.

I'm willing to bet Google already has a frighteningly accurate ability to determine whether I am associated with or own a particular account.

I've been locked permanently out of a (thankfully tertiary) Gmail account because their ML didn't like that I logged in from my new house. The option was to accept a push notification to a long dead and wiped phone.

Their state handling for the push notification based MFA factors is _atrocious_. I have had to “re-delete” a long wiped phone (or two) multiple times from more than one account. It seems to have finally stuck in the past year, but I’m suspicious that one day it could bite me in the ass.
Post reply on HN