Live data from Hacker News

Passkeys are now enabled by default for Google users

blog.google

271–280 of 684 posts

Re: Passkeys are now enabled by default for Google users

#271

While I believe this is a step in the right direction. I have read too many horror stories of people who were locked out of their Google and iCloud accounts with no real possibility of getting back in. I don’t think I am alone in thinking I am on borrowed time. Someday, probably due to my own fault I will be locked out of Google and my digital life will be over. If a private company can offer a similar login method l…

Disaster recovery. This is 100% my biggest worry with 2FA/MFA. I also think this is one of the reasons stuff like PGP never took off (don't @ me regarding perfect forward secrecy): the problem has always been managing some little, precious thing and the ramifications of what happens if it put beyond use or is used by some bad actor.

There are some Google Authenticator replacements that have an export function (eg. Authenticator+ on Android, although I'm not sure if it's still maintained). You give up a bit of [theoretical] security for a whole lot of DR insurance.

Re: Passkeys are now enabled by default for Google users

#272

1Password enabled PassKey support recently and I was "surprised" to learn that there is no way of exporting them out of 1Password. They're not included in the 1PUX format export, nor in the CSV. That means that they're literally impossible to back up. If 1Password goes down, or the company stops operating, or anything else like that, your Passkeys are just... gone. Absolutely no way to recover them.

Isn't that the point of Passkeys? The user isn't allowed to interface with them directly, so social engineering can't compromise them [1]. Rather than move your passkey between devices, you're meant to generate a different passkey for each device, then register all of them with the relevant service, like SSH keys. 1: of course, a user could still be tricked into adding an attacker's passkey to their account or someth…

But 1Password syncs your passkey to all your devices, so you only have one.

Re: Passkeys are now enabled by default for Google users

#273
post #201

Earlier quoted context omitted.

Passkeys are a new technology and everyone - including users, service providers, and organizations - will take time to learn and adapt. In this interim period the recommended approach is to provide passkeys as an alternative to whatever is already offered. This is the approach that Google and many other service providers are taking. That said, you are bringing up the right questions on the general topic of account re…

Rearranging deck chairs on the titantic. This whole scheme depends on either users being savvy enough to do vault backups or depending on service providers being functional. Both are quite doomed. Users have a path for passwords - they can write them down on paper and keep them with their important things. This tends to work for most folks. The backup story for passkeys is horrible. There is no path for my elderly re…

Passkeys represent the cumulative wisdom and experience (and compromises!) of the whole industry on how to keep users safe online. Appreciate your opinions that these efforts are doomed. It is safe to say, "We'll surely find out!"

Re: Passkeys are now enabled by default for Google users

#274

1Password enabled PassKey support recently and I was "surprised" to learn that there is no way of exporting them out of 1Password. They're not included in the 1PUX format export, nor in the CSV. That means that they're literally impossible to back up. If 1Password goes down, or the company stops operating, or anything else like that, your Passkeys are just... gone. Absolutely no way to recover them.

I had a discussion with my mother advising her to switch: she is afraid of changing ISP because her email is tied to her provider.

We fixed this on mobile years ago but email is still a goddamn mess. Moral of the story: never get locked in.

Re: Passkeys are now enabled by default for Google users

#275
post #251
post #206

Earlier quoted context omitted.

Think of it as using iCloud as your password manager and storing your OTPs - someone breaks into your iCloud, they get access to all the passwords and OTPs to login to any service in iCloud. Always take the security of your password manager / sync accounts seriously. Use hardwre security keys if needed on the "root accounts".

iCloud is unfortunately impossible to adequately secure for that use case. If you shoulder-surf somebody's phone unlock PIN and grab their phone, you have everything you need to take over their iCloud account, including their passkeys and the capability of locking out all of the victim's other trusted Apple devices and changing their iCloud password. This was very surprising for me to witness first hand – fortunately…

It is a fair observation. And I can see why users tend to be alarmed about this. Although in my experience users tend to significantly underestimate the real risks of online attacks relative to these more visceral threats.

Let met ask you: has that discovery made you stop using your iPhone, or storing passwords or other critical data in your iCloud? If the answer is "No", then you're strictly better off moving to passkeys stored on iCloud as well.

Re: Passkeys are now enabled by default for Google users

#276

Earlier quoted context omitted.

That does seem circular in Google's case, no? What cloud storage?

Google Password Manager. https://developers.google.com/identity/passkeys/supported-en...

Given their awesome track record, Google is the LAST company I'd trust not to shut down or lock me out of such a critical tool.

Re: Passkeys are now enabled by default for Google users

#278

Earlier quoted context omitted.

Isn't that the point of Passkeys? The user isn't allowed to interface with them directly, so social engineering can't compromise them [1]. Rather than move your passkey between devices, you're meant to generate a different passkey for each device, then register all of them with the relevant service, like SSH keys. 1: of course, a user could still be tricked into adding an attacker's passkey to their account or someth…

But 1Password syncs your passkey to all your devices, so you only have one.

Don't worry, if you lose your passkey all you need is access to your email to receive a password reset link.

Re: Passkeys are now enabled by default for Google users

#279

Earlier quoted context omitted.

I don't know how Google solved this, but it's an old solution. Shamir secret sharing. You break apart your keys into M pieces, where you need N pieces to reconstruct the key, so let's say 3/8. Then you need 3 pieces out of the 8 pieces it's broken into to recover your key. You take each of those 8 pieces and give to trusted sources. When you need to reconstruct your key, you have at least 3 of those give you the key…

Now there is a technically savvy solution that is a technical tour-de-force. Very very cool. But also completely unrealistic for the average person to use.

How? The usage was very easy. You select a contact and add them as your recovery contact (by selecting contact from your contact list) The system adds the key in the background. If they don't have the app, the app asks you to tell them to install the app (viral growth?). The users didn't need to know any thing technical. But install app, and click yes/no like they do with a 2FA app.

Re: Passkeys are now enabled by default for Google users

#280
post #13

As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?

A lot of services, but not all, will let you add passkeys which are tied to a password manager (e.g 1password) and not a physical device. If you've got one of those set up, you can download it on a new device and then gain access that way. In the case of 1password, this means you either have to remember your master password and your access key, or you have to have this stored somewhere safe. Perhaps choose a memorable password[1] and then encrypt an sd card and use one of these[2] in your wallet or a keyring usb drive or a yubikey so in the event of a fire all you have to do is grab your wallet or keys and you're good to go. Alternatively you could store this information in a safety deposit box, or with a trusted relative, or even your lawyer if they offer such a service.

At the end of the day, it's the individual's responsibility to determine how much they value their digital security and take what they deem to be the necessary steps, expenses and precautions to protect it. The only other alternative would be for Big Tech to have some kind of integration with the state, so that your digital accounts are tied to something like your passport or social security number, so that there are procedures available for regaining your digital identities in the event of catastrophe, just like you can do with your physical identity.

I personally think that the latter is where we are heading, not necessarily because of scenarios like you've mentioned, but because it's only a matter of time until AI advances to the point where it's going to cause a dangerous breakdown in trust and the only way it's going to be fixable is with some kind of system that is tied to physical reality. The internet will end up splitting into two, with the majority spending their time on the "verified" web, which will be websites using OAuth that will require you to use an account with one of the big providers who will have verified with the government or third party agency who you actually are. And then any websites that don't require this will form a sort of new, more accessible "dark web". I honestly think the majority of people are feeling that wary and weary of the internet at this point that they will happily choose the verified web, regardless of the surveillance implications.

[1] https://xkcd.com/936/

[2] https://amzn.eu/d/ia3kFeJ

Post reply on HN