Live data from Hacker News

Passkeys are now enabled by default for Google users

blog.google

221–230 of 684 posts

Re: Passkeys are now enabled by default for Google users

#221
> What are Passkeys?

> Passkeys are a new way to sign in to apps and websites. They’re both easier to use and more secure than passwords, so users no longer need to rely on the names of pets, birthdays or the infamous “password123.” Instead, passkeys let users sign in to apps and sites the same way they unlock their devices: with a fingerprint, a face scan or a screen lock PIN. And, unlike passwords, passkeys are resistant to online attacks like phishing, making them more secure than things like SMS one-time codes.

I HATE paragraphs like this. It's as if you're purposely obfuscating what they really are.

Re: Passkeys are now enabled by default for Google users

#223
post #13

As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?

Passkeys are instead of the password. You can still login using your password. This way, you don't have to keep entering your password if you have access to a device with a passkey and can access that device.

Re: Passkeys are now enabled by default for Google users

#224

> What are Passkeys? > Passkeys are a new way to sign in to apps and websites. They’re both easier to use and more secure than passwords, so users no longer need to rely on the names of pets, birthdays or the infamous “password123.” Instead, passkeys let users sign in to apps and sites the same way they unlock their devices: with a fingerprint, a face scan or a screen lock PIN. And, unlike passwords, passkeys are res…

[deleted]

Re: Passkeys are now enabled by default for Google users

#225
post #214

Oh I'm seething. Screw google, so god damn much. They've been accidentally enabling it for nearly a month if not more. And the UX has been infinitely confusing. I've been using 2fa for a decade (not an exaggeration, an understatement). I've been using u2f since the first month it was available and FUCK Google for this blog post. A month ago I logged in and tried to check on my security tokens. Their UI was silently u…

Your comment would be more impactful if it explained clearly what the problem is. What does it mean to upconvert a security token? In fact, what’s a security token? (I ask mainly so that I can watch out for whatever bit you. On the face of it, the blog post seems pretty anodyne. The screenshot shows that it’s optional, not forced, since there’s a "not now" button.) EDIT: oh, they auto converted your security keys to…

I'm sorry, I'm not laughing at you, I'm laughing at the premise of Google acknowledging this, let alone fixing it properly enough to have a "rollback".

As far as I call tell, my physical yubikeys that went though this process have continued working with the same ultimate user experience, thank God. Minus the 45 minutes where I thought I was locking myself out due to them disappearing from the ending landing page that listed my enrolled Security Tokens, due to the buggy upgrade UX flow or the fact that I have no way of confirming which of my primary/secondary tokens are now actually enrolled because it trashed my descriptions during this upgrade.

I am actually infinitely sorry at the times I openly questioned user error when people expressed Kafka-esque nightmares wrt to google auth. I'm actually quite annoyed at myself for ever doubting them.

Re: Passkeys are now enabled by default for Google users

#226
While I believe this is a step in the right direction. I have read too many horror stories of people who were locked out of their Google and iCloud accounts with no real possibility of getting back in.

I don’t think I am alone in thinking I am on borrowed time. Someday, probably due to my own fault I will be locked out of Google and my digital life will be over.

If a private company can offer a similar login method like login.gov and let me talk to a real person when I am locked out like the USPS, I will be screaming shut up and take my money.

Re: Passkeys are now enabled by default for Google users

#227

Earlier quoted context omitted.

That does seem circular in Google's case, no? What cloud storage?

Google Password Manager. https://developers.google.com/identity/passkeys/supported-en...

Will I still have access to that if Google decides randomly to lock me out of my account?

Re: Passkeys are now enabled by default for Google users

#228

Earlier quoted context omitted.

This is accurate, but by putting your passkey backup with that external entity, you are putting all your keys in that basket. Passwords have an obvious, backup option with zero dependencies on third-parties: A printed list in a fire safe. I would not advise users go heavily with any passkey provider that does not provide a physical backup of a similar form that can be secured through non-technical means, and that can…

The problem with that is people don't have fire safes. Or homes in some cases (e.g. many unhoused people have smartphones now). Also people need to travel and do recovery without having to fly home to their safe. The idea that printing a backup is easy and an option for many people is often not the case.

And that is why most people use a single, easy to remember password for everything: even if their house burns, their devices are gone and they no longer have their phone number, they can still remember their password.

For all of its many weaknesses, a password has that one major advantage over all the other authentication methods, and unless a new method provides a similar advantage, most people will keep using a password, just like they did even with the appearance of private keys, biometrics, USB tokens, SMS or TOTP.

Re: Passkeys are now enabled by default for Google users

#229
post #13

As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?

I had a fire. I lost every single thing I own, except my landlord grabbed my phone, bless him. Otherwise I would have been totally stuck as all my TOTP apps are on there. Also, never lose your phone number. I can't get back into my Google account even though I have the username, password and recovery email because I can never get the SMS code.

> never lose your phone number

The forced SMS 2FA that banks and credit card companies have started implementing infuriates me for exactly this reason.

Re: Passkeys are now enabled by default for Google users

#230

Earlier quoted context omitted.

What’s the standard then? Should it be possible to recover your account without possessing any evidence whatsoever that you are the person you say you are?

If you travel in an other country and loose your phone or the phone gets stolen. How can you log into Gmail from anything else if you need access to travel or anything else ? Like receiving a confirmation of identity by email from the bank or another service ?

You can't, that's the point.
Post reply on HN