Live data from Hacker News

Passkeys are now enabled by default for Google users

blog.google

231–240 of 684 posts

Re: Passkeys are now enabled by default for Google users

#231
post #223
post #13

As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?

Passkeys are instead of the password. You can still login using your password. This way, you don't have to keep entering your password if you have access to a device with a passkey and can access that device.

Passkeys don't (only) replace passwords – they usually also replace another authentication factor as well.

That other factor might still be available for account recoveries (together with a password or recovery email etc.), but if either are not regularly exercised, users might forget them or lose access to them and not notice until they also lose access to their passkey(s).

That said, Google's and Apple's passkey solutions themselves are cloud-synced (with no way to opt out), so as long as users of either can still access their Google or Apple account, they would not be totally locked out.

Re: Passkeys are now enabled by default for Google users

#232
post #65

Simpson's Paradox lives here. On average, this might increase security (the vast majority of users are terrible at using passwords). For proficient users who use passwords securely, this is an acute drop in security (if forced to use). Forced phone number 2FA has the same effect; in Big G's case forcing phone number 2FA is anti-anonymity disguised as security. In this case, it's a bid for biometrics.

> In this case, it's a bid for biometrics

Biometrics are used to unlock an local, on-device key storage mechanism which contains a private key, and from that you can derive a public key, and that's what Passkeys fundamentally are, is a public/private keypair you use to validate you are logging into a website. If Google were harvesting your biometrics they were just doing it already and it has nothing to do with this.

This is an extremely basic detail of the security model that has been true since long before these were introduced, back when the iPhone started using e.g. the secure enclave; I don't know why people on this website talk so adamantly about things they clearly do not understand at all. It's honestly kind of astounding.

> For proficient users who use passwords securely, this is an acute drop in security (if forced to use).

No, it isn't, it's the moral equivalent of an SSH key to login to a server instead of using SSH password to login to a server, but now apply that to a website. And beyond that, it's objectively wrong; for instance passkeys are literally phishing resistant, and no amount of thinking you can "use passwords securely" can change that simple fact.

Re: Passkeys are now enabled by default for Google users

#233
post #134

Earlier quoted context omitted.

Then what's the point of it all if a hacker can still get into my account using the traditional methods? This seems to be just opening up another avenue of attack.

My Google account is set up such that account recovery requires me to actually travel to Mountain View and present several forms of ID, and that's just how I want it to be.

Are you joking or does Google really do in-person verification for high-value accounts (e.g. GCP or Play Store developer accounts)?

Re: Passkeys are now enabled by default for Google users

#234
post #223
post #13

As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?

Passkeys are instead of the password. You can still login using your password. This way, you don't have to keep entering your password if you have access to a device with a passkey and can access that device.

Sure, but is that adequate? Not having people practice their passwords seems to be an anti-pattern for selling premium support in password managers, while many other apps ask with planned frequency.

Re: Passkeys are now enabled by default for Google users

#236
post #13

As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?

And if I loose for some reason access to my phone number, termination of current number to create a new line with a new phone, I loose access to Gmail forever ?

Possibly. Security has made internet enabled accounts outright user hostile. Try helping a 70 year old guy get into his Gmail again. I despair over the disrespect Google and the other major internet corps show their tech-naive users.

I've heard "I'll call them" far too often, and am perpetually forced to share the bad news.

Re: Passkeys are now enabled by default for Google users

#237

Earlier quoted context omitted.

I had a fire. I lost every single thing I own, except my landlord grabbed my phone, bless him. Otherwise I would have been totally stuck as all my TOTP apps are on there. Also, never lose your phone number. I can't get back into my Google account even though I have the username, password and recovery email because I can never get the SMS code.

Don't tie your google account recovery to SMS. I left that option blank.

All the Google accounts I had to use for work eventually required a phone number.

Re: Passkeys are now enabled by default for Google users

#238
post #201
post #13

As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?

Passkeys are a new technology and everyone - including users, service providers, and organizations - will take time to learn and adapt. In this interim period the recommended approach is to provide passkeys as an alternative to whatever is already offered. This is the approach that Google and many other service providers are taking. That said, you are bringing up the right questions on the general topic of account re…

Rearranging deck chairs on the titantic.

This whole scheme depends on either users being savvy enough to do vault backups or depending on service providers being functional.

Both are quite doomed.

Users have a path for passwords - they can write them down on paper and keep them with their important things. This tends to work for most folks.

The backup story for passkeys is horrible. There is no path for my elderly relatives who don't use cloud services.

Until that is fixed, passkeys will never replace passwords.

Don't forget password sharing! That is a whole screwed up story with passkeys too.

Re: Passkeys are now enabled by default for Google users

#239
post #201
post #13

As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?

Passkeys are a new technology and everyone - including users, service providers, and organizations - will take time to learn and adapt. In this interim period the recommended approach is to provide passkeys as an alternative to whatever is already offered. This is the approach that Google and many other service providers are taking. That said, you are bringing up the right questions on the general topic of account re…

How can a user, right now, take control + ownership of backing up their own pass keys, without iCloud or Google?

This is a privilege I currently enjoy right now, and one I am not really eager to give up.

Re: Passkeys are now enabled by default for Google users

#240

No one has managed yet to explain to me how you recover access to an account using these passkeys if you somehow lose access to all your devices. Note that i said "all your devices" so the cloud backup you dream of will also be inaccessible because I can't authenticate to that either. And I know about backups... what about your average user who is likely to own a single phone and no other device? They lose access to…

https://safety.google/authentication/passkey/

> Yes, you can continue to log in using your traditional log in [sic] method, which in most cases would be using your username and password.

Post reply on HN