While I believe this is a step in the right direction. I have read too many horror stories of people who were locked out of their Google and iCloud accounts with no real possibility of getting back in. I don’t think I am alone in thinking I am on borrowed time. Someday, probably due to my own fault I will be locked out of Google and my digital life will be over. If a private company can offer a similar login method l…
Disaster recovery. This is 100% my biggest worry with 2FA/MFA. I also think this is one of the reasons stuff like PGP never took off (don't @ me regarding perfect forward secrecy): the problem has always been managing some little, precious thing and the ramifications of what happens if it put beyond use or is used by some bad actor.
Passkeys are now enabled by default for Google users
271–280 of 684 posts
Re: Passkeys are now enabled by default for Google users
#2721Password enabled PassKey support recently and I was "surprised" to learn that there is no way of exporting them out of 1Password. They're not included in the 1PUX format export, nor in the CSV. That means that they're literally impossible to back up. If 1Password goes down, or the company stops operating, or anything else like that, your Passkeys are just... gone. Absolutely no way to recover them.
Isn't that the point of Passkeys? The user isn't allowed to interface with them directly, so social engineering can't compromise them [1]. Rather than move your passkey between devices, you're meant to generate a different passkey for each device, then register all of them with the relevant service, like SSH keys. 1: of course, a user could still be tricked into adding an attacker's passkey to their account or someth…
Re: Passkeys are now enabled by default for Google users
#273Earlier quoted context omitted.
Passkeys are a new technology and everyone - including users, service providers, and organizations - will take time to learn and adapt. In this interim period the recommended approach is to provide passkeys as an alternative to whatever is already offered. This is the approach that Google and many other service providers are taking. That said, you are bringing up the right questions on the general topic of account re…
Rearranging deck chairs on the titantic. This whole scheme depends on either users being savvy enough to do vault backups or depending on service providers being functional. Both are quite doomed. Users have a path for passwords - they can write them down on paper and keep them with their important things. This tends to work for most folks. The backup story for passkeys is horrible. There is no path for my elderly re…
Re: Passkeys are now enabled by default for Google users
#2741Password enabled PassKey support recently and I was "surprised" to learn that there is no way of exporting them out of 1Password. They're not included in the 1PUX format export, nor in the CSV. That means that they're literally impossible to back up. If 1Password goes down, or the company stops operating, or anything else like that, your Passkeys are just... gone. Absolutely no way to recover them.
We fixed this on mobile years ago but email is still a goddamn mess. Moral of the story: never get locked in.
Re: Passkeys are now enabled by default for Google users
#275Earlier quoted context omitted.
Think of it as using iCloud as your password manager and storing your OTPs - someone breaks into your iCloud, they get access to all the passwords and OTPs to login to any service in iCloud. Always take the security of your password manager / sync accounts seriously. Use hardwre security keys if needed on the "root accounts".
iCloud is unfortunately impossible to adequately secure for that use case. If you shoulder-surf somebody's phone unlock PIN and grab their phone, you have everything you need to take over their iCloud account, including their passkeys and the capability of locking out all of the victim's other trusted Apple devices and changing their iCloud password. This was very surprising for me to witness first hand – fortunately…
Let met ask you: has that discovery made you stop using your iPhone, or storing passwords or other critical data in your iCloud? If the answer is "No", then you're strictly better off moving to passkeys stored on iCloud as well.
Re: Passkeys are now enabled by default for Google users
#276Earlier quoted context omitted.
That does seem circular in Google's case, no? What cloud storage?
Google Password Manager. https://developers.google.com/identity/passkeys/supported-en...
Re: Passkeys are now enabled by default for Google users
#277Re: Passkeys are now enabled by default for Google users
#278Earlier quoted context omitted.
Isn't that the point of Passkeys? The user isn't allowed to interface with them directly, so social engineering can't compromise them [1]. Rather than move your passkey between devices, you're meant to generate a different passkey for each device, then register all of them with the relevant service, like SSH keys. 1: of course, a user could still be tricked into adding an attacker's passkey to their account or someth…
But 1Password syncs your passkey to all your devices, so you only have one.
Re: Passkeys are now enabled by default for Google users
#279Earlier quoted context omitted.
I don't know how Google solved this, but it's an old solution. Shamir secret sharing. You break apart your keys into M pieces, where you need N pieces to reconstruct the key, so let's say 3/8. Then you need 3 pieces out of the 8 pieces it's broken into to recover your key. You take each of those 8 pieces and give to trusted sources. When you need to reconstruct your key, you have at least 3 of those give you the key…
Now there is a technically savvy solution that is a technical tour-de-force. Very very cool. But also completely unrealistic for the average person to use.
Re: Passkeys are now enabled by default for Google users
#280As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?
At the end of the day, it's the individual's responsibility to determine how much they value their digital security and take what they deem to be the necessary steps, expenses and precautions to protect it. The only other alternative would be for Big Tech to have some kind of integration with the state, so that your digital accounts are tied to something like your passport or social security number, so that there are procedures available for regaining your digital identities in the event of catastrophe, just like you can do with your physical identity.
I personally think that the latter is where we are heading, not necessarily because of scenarios like you've mentioned, but because it's only a matter of time until AI advances to the point where it's going to cause a dangerous breakdown in trust and the only way it's going to be fixable is with some kind of system that is tied to physical reality. The internet will end up splitting into two, with the majority spending their time on the "verified" web, which will be websites using OAuth that will require you to use an account with one of the big providers who will have verified with the government or third party agency who you actually are. And then any websites that don't require this will form a sort of new, more accessible "dark web". I honestly think the majority of people are feeling that wary and weary of the internet at this point that they will happily choose the verified web, regardless of the surveillance implications.