Live data from Hacker News

Passkeys are now enabled by default for Google users

blog.google

251–260 of 684 posts

Re: Passkeys are now enabled by default for Google users

#251
post #206

Earlier quoted context omitted.

If they break into my iCloud then they’re in my iCloud. They’re not in all my other accounts, because I use an encrypted password manager that isn’t iCloud.

Think of it as using iCloud as your password manager and storing your OTPs - someone breaks into your iCloud, they get access to all the passwords and OTPs to login to any service in iCloud. Always take the security of your password manager / sync accounts seriously. Use hardwre security keys if needed on the "root accounts".

iCloud is unfortunately impossible to adequately secure for that use case.

If you shoulder-surf somebody's phone unlock PIN and grab their phone, you have everything you need to take over their iCloud account, including their passkeys and the capability of locking out all of the victim's other trusted Apple devices and changing their iCloud password.

This was very surprising for me to witness first hand – fortunately not in the identity theft scenario, but only when observing a relative regaining access to their iCloud account using only their iPad they were logged in on.

Re: Passkeys are now enabled by default for Google users

#252
post #28

Never. You can pry my passwords from my cold, dead hands.

Someday, we will have brain reading technology to extract information from a newly dead brain, like we have to extract it from a RAM that was just turned off https://en.wikipedia.org/wiki/Cold_boot_attack

Lol just saw the creator I assume.

Re: Passkeys are now enabled by default for Google users

#253
post #13

As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?

Just happened to my in-law. She dropped her phone on the stairs, screen cracked, and became unresponsive. I gave her an older phone I had and swapped the sim fine. But she couldn't figure out how to log in to Google account because it was so adamant telling her to use her phone. Her laptop was logged out of her email, etc. Fortunately I have backup tokens for her from a previous incident heh. I have no idea what othe…

I'm don't know the specifics of how passkeys with Google work, but don't they usually require multiple synced devices?

Re: Passkeys are now enabled by default for Google users

#254

While I believe this is a step in the right direction. I have read too many horror stories of people who were locked out of their Google and iCloud accounts with no real possibility of getting back in. I don’t think I am alone in thinking I am on borrowed time. Someday, probably due to my own fault I will be locked out of Google and my digital life will be over. If a private company can offer a similar login method l…

"You might get locked out of your account" is the updated version of the old "Your hard drive will crash."

It isn't a matter of if, it's just a matter of when. Backups and a thorough disaster recovery plan is absolutely mandatory for anyone who cares about their data. Some company is going to mess something up due to no fault of your own. It is inevitable.

Unfortunately, there aren't good disaster recovery options for some aspects of lost accounts, but having multiple accounts and avoiding single-points of failure help some.

Re: Passkeys are now enabled by default for Google users

#255
1Password enabled PassKey support recently and I was "surprised" to learn that there is no way of exporting them out of 1Password. They're not included in the 1PUX format export, nor in the CSV.

That means that they're literally impossible to back up. If 1Password goes down, or the company stops operating, or anything else like that, your Passkeys are just... gone. Absolutely no way to recover them.

Re: Passkeys are now enabled by default for Google users

#256

Earlier quoted context omitted.

This is accurate, but by putting your passkey backup with that external entity, you are putting all your keys in that basket. Passwords have an obvious, backup option with zero dependencies on third-parties: A printed list in a fire safe. I would not advise users go heavily with any passkey provider that does not provide a physical backup of a similar form that can be secured through non-technical means, and that can…

The problem with that is people don't have fire safes. Or homes in some cases (e.g. many unhoused people have smartphones now). Also people need to travel and do recovery without having to fly home to their safe. The idea that printing a backup is easy and an option for many people is often not the case.

And it's a hassle to keep it in sync. If you decide to update your password you need to remember to print out a copy and store it in the safe, oh and throw out the old one.

Re: Passkeys are now enabled by default for Google users

#257
post #13

As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?

I don't know how Google solved this, but it's an old solution. Shamir secret sharing. You break apart your keys into M pieces, where you need N pieces to reconstruct the key, so let's say 3/8. Then you need 3 pieces out of the 8 pieces it's broken into to recover your key. You take each of those 8 pieces and give to trusted sources. When you need to reconstruct your key, you have at least 3 of those give you the key…

I had the same idea about a decade ago but never bothered to try to implement it. I felt like it would have suffered from the same problem all other technologies have in security: overly complex user interactions. The concept makes sense, but getting N other people to commit is overhead the average user probably doesn't want to deal with.

Re: Passkeys are now enabled by default for Google users

#259
post #201

Earlier quoted context omitted.

Passkeys are a new technology and everyone - including users, service providers, and organizations - will take time to learn and adapt. In this interim period the recommended approach is to provide passkeys as an alternative to whatever is already offered. This is the approach that Google and many other service providers are taking. That said, you are bringing up the right questions on the general topic of account re…

How can a user, right now, take control + ownership of backing up their own pass keys, without iCloud or Google? This is a privilege I currently enjoy right now, and one I am not really eager to give up.

I use 1Password [0] for syncing passkeys, and it works quite well. I would imagine other password managers are building similar features.

[0]: https://support.1password.com/save-use-passkeys/

Re: Passkeys are now enabled by default for Google users

#260
post #81

Always remember that passwords are protected by Fifth Amendment and similiar laws in other countries, but there is no law prohibiting officer to put your phone in front of your face to unlock it.

Why make claims for other locations when you don't know about them, and it could lead to serious consequences? In particular the UK has no such compunction.

Two years in prison for failing to unlock your phone in the UK (Section 49 of the Regulation of Investigatory Powers Act). Don't forget that password!
Post reply on HN