Live data from Hacker News

Passkeys are now enabled by default for Google users

blog.google

301–310 of 684 posts

Re: Passkeys are now enabled by default for Google users

#301

Lauren Weinstein is sounding the alarm on passkeys which is flawed and that it would make a huge headache for a lot of people especilly normal folks. https://mastodon.laurenweinstein.org/@lauren/111103819626952... https://mastodon.laurenweinstein.org/@lauren/111211366080459...

Yup! I've had similar complaints for years now.

Modulo the whole privacy/vendor lockin issue, passkeys are not a terrible alternative to people without 2FA reusing the same basic password on every single website.

However, when you actually rely on it to secure things, it quickly becomes a massive nightmare - made even worse by it being treated as equivalent to password+2FA.

Re: Passkeys are now enabled by default for Google users

#302
post #69

Earlier quoted context omitted.

It isn't, and this isn't authentication with a pin. Passkeys also requires the device. Using a pin with this is 2-factor. Pin + hardware token.

So why not just have a password that then unlocks the passkey? I already have a password manager.

You should be able to use your password manager to handle passkeys. Enter your master password in 1Password, use passkey. And Bitwarden support is coming.

Re: Passkeys are now enabled by default for Google users

#303

If I may, I'll repeat a comment I made a few days ago: Give me an implementation I can self-host, without Google, Apple, etc. having effective control (including claws in my relevant software supply chain) and with an easy user experience, where I can maintain secure backups (on my own infrastructure, thank you) and smooth transition to future devices, and ideally, if needed, securely export root keys (cause if I don…

As I understand it (which mean I can be completely wrong), in order to utilize Passkeys, at least at the browser level, you need support within the browser.

Firefox has a build that supports passkeys, and I believe 1Password has an extension for Firefox that supports passkeys.

If "all you need" for Passkey support is a custom extension, it should be straightforward to create one that does whatever you want (including storing your private keys in plain text in your home directory, which many argue is a bad idea, but that's not the point).

Is 1Password a magically signed and authorized extension, or can any Joe pound out a quick hack using JS and Firefox?

I appreciate that the client and credential management should be sophisticated and secure, etc. But the API is the API, it's supposed to be an open API, and I can understand Chrome, Safari, and Edge, being closed source browsers, may or may not allow anyone to hack their own keystore regimen.

But, I don't think Firefox is doing that (unless the 1Password extension is magically blessed by Firefox somehow). At a minimum, you can always go the source, and rebuild Firefox to do what you want. Involved, to be sure, but possible.

Re: Passkeys are now enabled by default for Google users

#304
post #301

Lauren Weinstein is sounding the alarm on passkeys which is flawed and that it would make a huge headache for a lot of people especilly normal folks. https://mastodon.laurenweinstein.org/@lauren/111103819626952... https://mastodon.laurenweinstein.org/@lauren/111211366080459...

Yup! I've had similar complaints for years now. Modulo the whole privacy/vendor lockin issue, passkeys are not a terrible alternative to people without 2FA reusing the same basic password on every single website. However, when you actually rely on it to secure things , it quickly becomes a massive nightmare - made even worse by it being treated as equivalent to password+2FA.

Coupled with Google's very shaky support track record and you have a very dangerous combination. This will surely get ugly.

Re: Passkeys are now enabled by default for Google users

#305
post #286

1Password enabled PassKey support recently and I was "surprised" to learn that there is no way of exporting them out of 1Password. They're not included in the 1PUX format export, nor in the CSV. That means that they're literally impossible to back up. If 1Password goes down, or the company stops operating, or anything else like that, your Passkeys are just... gone. Absolutely no way to recover them.

Currently, none of the big players in the passkey space support exporting or importing of passkeys, because the spec for doing this securely has not been agreed upon, and nobody wants to allow plaintext export of passkeys. See a recent post in the 1Password passkey AMA about this subject: https://old.reddit.com/r/1Password/comments/16to6x7/hey_redd... Re. your point about 1Password going down: Your passwords and pass…

It's difficult not to see the "it's for your own security" argument as a cynical lock-in ploy.

Because you can export plain-text passwords just fine, and they give you exactly the same access as a PassKey does.

Re: Passkeys are now enabled by default for Google users

#306
post #13

As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?

Just happened to my in-law. She dropped her phone on the stairs, screen cracked, and became unresponsive. I gave her an older phone I had and swapped the sim fine. But she couldn't figure out how to log in to Google account because it was so adamant telling her to use her phone. Her laptop was logged out of her email, etc. Fortunately I have backup tokens for her from a previous incident heh. I have no idea what othe…

A few months ago Google wouldn't even accept backup tokens for me. I was on vacation, and that tripped enough fraud detectors to cause problems. I couldn't log back in till I got on my home network and changed my password.

Re: Passkeys are now enabled by default for Google users

#307
Most accounts with passwords have the fail-safe method of 'prove my identity to company, they reset'. I.e if you can't remember your bank password, there are paths for the bank to reset for you.

Anything that Google controls you have absolutely no way to get in contact to resolve issues. This is already a problem with all of their products. Locking all of your access behind a Google controlled door is just setting yourself up for a future nightmare.

Re: Passkeys are now enabled by default for Google users

#308
post #293
post #286

Earlier quoted context omitted.

Currently, none of the big players in the passkey space support exporting or importing of passkeys, because the spec for doing this securely has not been agreed upon, and nobody wants to allow plaintext export of passkeys. See a recent post in the 1Password passkey AMA about this subject: https://old.reddit.com/r/1Password/comments/16to6x7/hey_redd... Re. your point about 1Password going down: Your passwords and pass…

And what a surprise that is, the one feature necessary to ensure vendor lock in doesn't happen was at 0 priority before they rolled it out.

The whole point is vendor lock-in.

Re: Passkeys are now enabled by default for Google users

#309

Earlier quoted context omitted.

I had a fire. I lost every single thing I own, except my landlord grabbed my phone, bless him. Otherwise I would have been totally stuck as all my TOTP apps are on there. Also, never lose your phone number. I can't get back into my Google account even though I have the username, password and recovery email because I can never get the SMS code.

> never lose your phone number The forced SMS 2FA that banks and credit card companies have started implementing infuriates me for exactly this reason.

Especially when they migrate previously password-only accounts to requiring what they think your phone number might be, and especially given that it costs under $15 to borrow somebody's phone number for the day without their knowledge.
Post reply on HN