Hottake here: The biggest mistake that the passkeys movement did is try to make it sound more marketable at the cost of oversimplification. First up, these aren’t really “no password” mechanisms. They’re closer to ssh certificates. You need to authenticate through some other mechanism and then agree to do the equivalent of creating and installing ssh certificates on your device. The ssh certificates get synchronized…
Passkeys are now enabled by default for Google users
211–220 of 684 posts
Re: Passkeys are now enabled by default for Google users
#212Hottake here: The biggest mistake that the passkeys movement did is try to make it sound more marketable at the cost of oversimplification. First up, these aren’t really “no password” mechanisms. They’re closer to ssh certificates. You need to authenticate through some other mechanism and then agree to do the equivalent of creating and installing ssh certificates on your device. The ssh certificates get synchronized…
HN crowd understands ssh certs and the difficulty of key exchange. Most others simply don't. So they need to simplify. If the result is that users are not using passwords, then aren't passkeys an alternative to passwords?
Case in point, creating a new google account as a 13yo. If you don’t have a password and you lose your one device, you lose everything. This isn’t hypothetical; it just happened to a family friend.
Not sure why the discussion got booted to the bottom of the thread. Looks like it’s a lesson not to label your comment a rant.
Re: Passkeys are now enabled by default for Google users
#213G: Here's a cool new security feature! HN: Yeah, but what if disaster scenario ? A1: If you're authenticating to Google because your $DAYJOB mandates it, contact your Enterprise Administrator. As part of their multi-gazillion deal with the dark side, I'm sure there is some kind of support for a recovery mechanism, and if there isn't: yeah paid holiday until they figure it out! A2: If you rely on Google for personal-s…
Re: Passkeys are now enabled by default for Google users
#214They've been accidentally enabling it for nearly a month if not more. And the UX has been infinitely confusing. I've been using 2fa for a decade (not an exaggeration, an understatement). I've been using u2f since the first month it was available and FUCK Google for this blog post.
A month ago I logged in and tried to check on my security tokens. Their UI was silently upconverting them. Without telling me. And the flow made it look like it was just deleting them. Hours later I realize it had re-enrolled them AND IT LOST THE DESCRIPTION I GAVE TO THEM. To be clear, it trashedt the decription I gave them during (what I didn't know at the time) was re-enrolling them as passkeys, because i sure as hell wansnt in the passkeys area. So not only did I inadvertently change them, they're now indistinguishable and unidentifiable to me. So if I want to ensure my primary and backup tokens are enrolled properly , I have to do it all over again, with all of them in my possession
Seriously, I have defended google against all sort of claims with respect to their 2FA and they can absolutely get up their own after what they pulled, and now this blog post.
Do some god damn basic (user) testing FFS. I would literally pay $1000usd right this second to scream at the people who green-lit and implemented this. And another $1000usd to ensure to people here that I know DAMN WELL what I'm talking about here. It's not like I don't have video evidence of exactly what I'm stating here on an unlisted YT video tweeted at Google Security.
Edit2: to be VERY clear, I have a video I reviewed, just now, that shows me trying to enroll an existing Security Token with a description, it disappearing, it then appearing as a Passkey with no description.
Re: Passkeys are now enabled by default for Google users
#215Earlier quoted context omitted.
I had a fire. I lost every single thing I own, except my landlord grabbed my phone, bless him. Otherwise I would have been totally stuck as all my TOTP apps are on there. Also, never lose your phone number. I can't get back into my Google account even though I have the username, password and recovery email because I can never get the SMS code.
Have had to recover from 0 pretty similarly. My backup approach basically started with the fact that I knew the password to a cloud storage account that I had uploaded a keepass vault to, and that keepass vault had the password to my primary backup provider. In a full no passwords world, I would have had no chance to do so.
Re: Passkeys are now enabled by default for Google users
#216Oh I'm seething. Screw google, so god damn much. They've been accidentally enabling it for nearly a month if not more. And the UX has been infinitely confusing. I've been using 2fa for a decade (not an exaggeration, an understatement). I've been using u2f since the first month it was available and FUCK Google for this blog post. A month ago I logged in and tried to check on my security tokens. Their UI was silently u…
(I ask mainly so that I can watch out for whatever bit you. On the face of it, the blog post seems pretty anodyne. The screenshot shows that it’s optional, not forced, since there’s a "not now" button.)
EDIT: oh, they auto converted your security keys to passkeys? With no option to roll back? Yeah, that’s not great. https://support.google.com/accounts/answer/6103523?hl=en&co=...
Re: Passkeys are now enabled by default for Google users
#217Re: Passkeys are now enabled by default for Google users
#218Earlier quoted context omitted.
And what if somebody breaks into my google/iCloud account and syncs all my passkeys to their machines?
If they're in your Google/iCloud, you're already in a game over scenario. The point of all this is to prevent that from happening. You can try to recover by revoking all your passkeys and starting over with hardware tokens, but that's likely what a sophisticated attacker is going to try as well, and they're probably faster than you. Still way way better than passwords.
If someone breaks into the cloud provider and downloads my passphrase document, nothing happens.
Re: Passkeys are now enabled by default for Google users
#219As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?
I had a fire. I lost every single thing I own, except my landlord grabbed my phone, bless him. Otherwise I would have been totally stuck as all my TOTP apps are on there. Also, never lose your phone number. I can't get back into my Google account even though I have the username, password and recovery email because I can never get the SMS code.
Re: Passkeys are now enabled by default for Google users
#220As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?