Live data from Hacker News

Passkeys are now enabled by default for Google users

blog.google

291–300 of 684 posts

Re: Passkeys are now enabled by default for Google users

#291

If I may, I'll repeat a comment I made a few days ago: Give me an implementation I can self-host, without Google, Apple, etc. having effective control (including claws in my relevant software supply chain) and with an easy user experience, where I can maintain secure backups (on my own infrastructure, thank you) and smooth transition to future devices, and ideally, if needed, securely export root keys (cause if I don…

Presumably your current password manager meets those requirements. Why not just use it (if it doesn't support passkeys today, it surely will) to manage your passkeys as well?

Re: Passkeys are now enabled by default for Google users

#292
post #13

As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?

I don't know how Google solved this, but it's an old solution. Shamir secret sharing. You break apart your keys into M pieces, where you need N pieces to reconstruct the key, so let's say 3/8. Then you need 3 pieces out of the 8 pieces it's broken into to recover your key. You take each of those 8 pieces and give to trusted sources. When you need to reconstruct your key, you have at least 3 of those give you the key…

Sounds like a great idea. Sometimes it's hard to be so in tune with the technology, and also be the salesperson!

Re: Passkeys are now enabled by default for Google users

#293
post #286

1Password enabled PassKey support recently and I was "surprised" to learn that there is no way of exporting them out of 1Password. They're not included in the 1PUX format export, nor in the CSV. That means that they're literally impossible to back up. If 1Password goes down, or the company stops operating, or anything else like that, your Passkeys are just... gone. Absolutely no way to recover them.

Currently, none of the big players in the passkey space support exporting or importing of passkeys, because the spec for doing this securely has not been agreed upon, and nobody wants to allow plaintext export of passkeys. See a recent post in the 1Password passkey AMA about this subject: https://old.reddit.com/r/1Password/comments/16to6x7/hey_redd... Re. your point about 1Password going down: Your passwords and pass…

And what a surprise that is, the one feature necessary to ensure vendor lock in doesn't happen was at 0 priority before they rolled it out.

Re: Passkeys are now enabled by default for Google users

#294
post #285

1Password enabled PassKey support recently and I was "surprised" to learn that there is no way of exporting them out of 1Password. They're not included in the 1PUX format export, nor in the CSV. That means that they're literally impossible to back up. If 1Password goes down, or the company stops operating, or anything else like that, your Passkeys are just... gone. Absolutely no way to recover them.

Is version 8 reasonably mac-like? On 7 it's still a mac application that acts like a true mac application (drag/drop works properly everywhere, expansion, properly keyboard-enabled, etc) which is well nigh impossible when running inside a chrome box. Agile Bits support kept insisting it was the same as the old native app and people kept complaining about bugs until I stopped following it.

It’s so rare that I use anything other than the 1Password Chrome extension that I couldn’t really tell you! The main app seems.. fine? But like I say, I hardly use it, so I probably wouldn’t notice details like you mention.

Do you have a different workflow where you use the main app a lot?

Re: Passkeys are now enabled by default for Google users

#295

While I believe this is a step in the right direction. I have read too many horror stories of people who were locked out of their Google and iCloud accounts with no real possibility of getting back in. I don’t think I am alone in thinking I am on borrowed time. Someday, probably due to my own fault I will be locked out of Google and my digital life will be over. If a private company can offer a similar login method l…

Disaster recovery. This is 100% my biggest worry with 2FA/MFA. I also think this is one of the reasons stuff like PGP never took off (don't @ me regarding perfect forward secrecy): the problem has always been managing some little, precious thing and the ramifications of what happens if it put beyond use or is used by some bad actor.

Gopass is my current solution. Easy to sync and move around (it's just git), supports OTP generation, everything is encrypted by GPG. I have at least three devices in separate locations with it, so my DR is covered (and I exercise it frequently).

Re: Passkeys are now enabled by default for Google users

#296
post #286

1Password enabled PassKey support recently and I was "surprised" to learn that there is no way of exporting them out of 1Password. They're not included in the 1PUX format export, nor in the CSV. That means that they're literally impossible to back up. If 1Password goes down, or the company stops operating, or anything else like that, your Passkeys are just... gone. Absolutely no way to recover them.

Currently, none of the big players in the passkey space support exporting or importing of passkeys, because the spec for doing this securely has not been agreed upon, and nobody wants to allow plaintext export of passkeys. See a recent post in the 1Password passkey AMA about this subject: https://old.reddit.com/r/1Password/comments/16to6x7/hey_redd... Re. your point about 1Password going down: Your passwords and pass…

> nobody wants to allow plaintext export of passkeys.

While noble, why? 1Password exports a plaintext file that has all of the credentials in plaintext already.

Re: Passkeys are now enabled by default for Google users

#297

If I may, I'll repeat a comment I made a few days ago: Give me an implementation I can self-host, without Google, Apple, etc. having effective control (including claws in my relevant software supply chain) and with an easy user experience, where I can maintain secure backups (on my own infrastructure, thank you) and smooth transition to future devices, and ideally, if needed, securely export root keys (cause if I don…

[deleted]

Re: Passkeys are now enabled by default for Google users

#298
Lauren Weinstein is sounding the alarm on passkeys which is flawed and that it would make a huge headache for a lot of people especilly normal folks. https://mastodon.laurenweinstein.org/@lauren/111103819626952... https://mastodon.laurenweinstein.org/@lauren/111211366080459...

Re: Passkeys are now enabled by default for Google users

#299

While I believe this is a step in the right direction. I have read too many horror stories of people who were locked out of their Google and iCloud accounts with no real possibility of getting back in. I don’t think I am alone in thinking I am on borrowed time. Someday, probably due to my own fault I will be locked out of Google and my digital life will be over. If a private company can offer a similar login method l…

Especially for normal and older folks and Google's history of very non-existent support. Not to mention that passkeys is a flawed system as well. [1] [2]

[1] https://mastodon.laurenweinstein.org/@lauren/111103819626952... [2] https://mastodon.laurenweinstein.org/@lauren/111211366080459...

Re: Passkeys are now enabled by default for Google users

#300

So what is going to happen to those who were using U2F and then later on webauthn? If you registered, say, a Yubikey, many moons ago, on your Google account. Is this Yubikey now automagically going to become a "passkey"? Or will you have to choose between logging in with your Yubikey or with a new passkey? (say something Google controls, in your phone for example)

I'm probably wrong but I expected passkey and yubikey to be interchangable. So if you are presented with a browser prompt for webauthn, you can use yubikey or passkey
Post reply on HN