Live data from Hacker News

Passkeys are now enabled by default for Google users

blog.google

201–210 of 684 posts

Re: Passkeys are now enabled by default for Google users

#201
post #13

As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?

Passkeys are a new technology and everyone - including users, service providers, and organizations - will take time to learn and adapt. In this interim period the recommended approach is to provide passkeys as an alternative to whatever is already offered. This is the approach that Google and many other service providers are taking.

That said, you are bringing up the right questions on the general topic of account recovery that everyone should be asking even without passkeys: "How would I login if I forget my password / lose access to my password manager / lose my second factor devices" and have a plan. Introduction and adoption of passkeys do not completely eliminate the need for thinking about your account recovery situation.

However, there is one special case where using passkeys is actually better for account recovery. If you create passkeys for your Google account on an Apple device with iCloud keychain, the passkeys are synched to your iCloud, so now even if you lose all your devices because your house burned down, as long as you have access to your iCloud account, you can just get all the passkeys for your Google accounts(and other websites).

Now, you may ask: 'what if I lose access to my Apple iCloud account" -> that's a fair question! Which is why I said Account Recovery concerns do not completely go away - but they can be significantly reduced with passkeys in many cases.

Re: Passkeys are now enabled by default for Google users

#202
post #23

"To use passkeys, you just use a fingerprint, face scan or pin to unlock your device, and they are 40% faster than passwords — and rely on a type of cryptography that makes them more secure. " Who wrote this sentence? It's just a mess.

also, "ah yes, a several digit pin, famously more secure than a same-length password that adds even as little as letters".

A pin is pretty safe when it unlocks a hardware token that limits the amount of attempts.

It's basically like a chip & pin bank card.

Re: Passkeys are now enabled by default for Google users

#203
post #21
post #13

As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?

To add, it is pretty poor there is no FAQ linked to from that post to answer basic non-technical questions as to how this is intended to be used. I assume as a technical person, the answer is I should have a backup device with a friend and/or store my passkeys somehow on my Apple or Microsoft or password manager account as well. But it needs more explanation in detail from Google!

You can try this: https://support.google.com/accounts/answer/13548313?hl=en, this help center page is linked to from various parts of the product experience for regular users to get a better idea about passkeys if they are interseted.

Re: Passkeys are now enabled by default for Google users

#204

Hmmm. I don't want to be dependent on any cloud provider for my logins. Any passkey solution must be fully self hosted for me to accept it. Is there such a thing yet?

I use Yubico Security Keys as passkeys. One at home, one in my office, one on my person. All with a local PIN lock (and 10-failure-device-reset) so simply having the hardware is insufficient to log in. The only annoying thing about this setup is having to manually add each key to each new passkey-enabled account I have.

Yeah I have yubikeys, the problem is that most of the services I use don't offer to enroll more than one. Also there's the issue of limited slots on each key for passwordless.

I like the whole idea of syncing a single key. But the whole chain must be owned by me and me alone.

Re: Passkeys are now enabled by default for Google users

#205

Correct me if I'm wrong but isn't it fair to say that passkeys secured on your phone are more secure than 1FA (password) but less secure than "traditional" 2FA? Passkey 2FA: unlock your phone and the passkey on your phone can log you in. Traditional 2FA: remember a password AND unlock your phone (where your TOTP is stored) and you can login If I were to rate all 3 methods on a scale of 1 to 10, for convenience and se…

Passwordless authentication > hardware-backed MFA > TOTP/HOTP MFA > SMS MFA > no MFA

The reason being is the secret used to authenticate you is non-portable (since it's based on asymmetric crypto, it doesn't need to be shared). On the other hand, portable credentials, like TOTP/HOTP code AND passwords are responsible for almost all compromise today.

Bearer token based authentication will always be inferior to FIDO/U2F - it's not even the same ballgame.

Re: Passkeys are now enabled by default for Google users

#206
post #129

Earlier quoted context omitted.

If they're in your Google/iCloud, you're already in a game over scenario. The point of all this is to prevent that from happening. You can try to recover by revoking all your passkeys and starting over with hardware tokens, but that's likely what a sophisticated attacker is going to try as well, and they're probably faster than you. Still way way better than passwords.

If they break into my iCloud then they’re in my iCloud. They’re not in all my other accounts, because I use an encrypted password manager that isn’t iCloud.

Think of it as using iCloud as your password manager and storing your OTPs - someone breaks into your iCloud, they get access to all the passwords and OTPs to login to any service in iCloud.

Always take the security of your password manager / sync accounts seriously. Use hardwre security keys if needed on the "root accounts".

Re: Passkeys are now enabled by default for Google users

#207
post #13

As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?

I think you’ll still need a password on your account for cases where no passkey is available, and possibly for other scenarios of heightened fraud risk. That’s why the setting they’re describing in the blog post is named “Skip password when possible”. Disclaimer: although I worked for Google many years ago in a role entirely unrelated to Google account authentication, I have no inside info on this announcement, could…

You're spot on. And I work on the Google authentication team right now :)

Re: Passkeys are now enabled by default for Google users

#208

Earlier quoted context omitted.

Passkeys are typically synced to cloud storage.

That does seem circular in Google's case, no? What cloud storage?

If you are on Apple ecosystem, iCloud can sync. Other password managers like 1Password can also be used to store your passkeys. If none of the above, you can always set up a physical security key and leave it at home.

IMO if you're reading hacker news, you're fully capable of setting one up and leaving it in a safe locale for recovery.

Re: Passkeys are now enabled by default for Google users

#209
post #95
post #38

As usual, the multi-device/multi-OS and recovery scenarios are simply just glossed over. I'll stick with a password vault I can sync to multiple OSes, thanks.

The vaults have been adding passkey support (1Password already has it, for instance).

I will never willingly go back to using 1Password.

Re: Passkeys are now enabled by default for Google users

#210
post #13

As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?

I had a fire. I lost every single thing I own, except my landlord grabbed my phone, bless him. Otherwise I would have been totally stuck as all my TOTP apps are on there. Also, never lose your phone number. I can't get back into my Google account even though I have the username, password and recovery email because I can never get the SMS code.

Don't tie your google account recovery to SMS. I left that option blank.
Post reply on HN