Live data from Hacker News

Passkeys are now enabled by default for Google users

blog.google

311–320 of 684 posts

Re: Passkeys are now enabled by default for Google users

#311
post #286

Earlier quoted context omitted.

Currently, none of the big players in the passkey space support exporting or importing of passkeys, because the spec for doing this securely has not been agreed upon, and nobody wants to allow plaintext export of passkeys. See a recent post in the 1Password passkey AMA about this subject: https://old.reddit.com/r/1Password/comments/16to6x7/hey_redd... Re. your point about 1Password going down: Your passwords and pass…

> nobody wants to allow plaintext export of passkeys. While noble, why? 1Password exports a plaintext file that has all of the credentials in plaintext already.

Because passkeys are supposed to be a bit more secure than plaintext passwords.

Re: Passkeys are now enabled by default for Google users

#312
post #285

1Password enabled PassKey support recently and I was "surprised" to learn that there is no way of exporting them out of 1Password. They're not included in the 1PUX format export, nor in the CSV. That means that they're literally impossible to back up. If 1Password goes down, or the company stops operating, or anything else like that, your Passkeys are just... gone. Absolutely no way to recover them.

Is version 8 reasonably mac-like? On 7 it's still a mac application that acts like a true mac application (drag/drop works properly everywhere, expansion, properly keyboard-enabled, etc) which is well nigh impossible when running inside a chrome box. Agile Bits support kept insisting it was the same as the old native app and people kept complaining about bugs until I stopped following it.

It's as Mac-like as any other Electron app. Which is to say, it does a pretty good impression of a Mac app, but the bundle is 345M, with another 244M hiding in your Library directory.

Re: Passkeys are now enabled by default for Google users

#313

Earlier quoted context omitted.

Disaster recovery. This is 100% my biggest worry with 2FA/MFA. I also think this is one of the reasons stuff like PGP never took off (don't @ me regarding perfect forward secrecy): the problem has always been managing some little, precious thing and the ramifications of what happens if it put beyond use or is used by some bad actor.

There are some Google Authenticator replacements that have an export function (eg. Authenticator+ on Android, although I'm not sure if it's still maintained). You give up a bit of [theoretical] security for a whole lot of DR insurance.

Google Authenticator now has an "Export QR code" function that allows exporting the 2FA secrets.

Re: Passkeys are now enabled by default for Google users

#314

Earlier quoted context omitted.

Now there is a technically savvy solution that is a technical tour-de-force. Very very cool. But also completely unrealistic for the average person to use.

How? The usage was very easy. You select a contact and add them as your recovery contact (by selecting contact from your contact list) The system adds the key in the background. If they don't have the app, the app asks you to tell them to install the app (viral growth?). The users didn't need to know any thing technical. But install app, and click yes/no like they do with a 2FA app.

I think the challenge is more coordinating the 8 people who will be a trusted part of your life long-term. Also they’d have to be sure to keep their fragments of the key intact through replacing devices, etc, no? Seems like just keeping a Yubikey in a safe deposit box would be simpler.

Re: Passkeys are now enabled by default for Google users

#315
post #278

Earlier quoted context omitted.

Don't worry, if you lose your passkey all you need is access to your email to receive a password reset link.

That's literally the solution to "What if I lose all the passkeys associated with my account and I've also forgotten my password?"

[deleted]

Re: Passkeys are now enabled by default for Google users

#316

Earlier quoted context omitted.

Disaster recovery. This is 100% my biggest worry with 2FA/MFA. I also think this is one of the reasons stuff like PGP never took off (don't @ me regarding perfect forward secrecy): the problem has always been managing some little, precious thing and the ramifications of what happens if it put beyond use or is used by some bad actor.

There are some Google Authenticator replacements that have an export function (eg. Authenticator+ on Android, although I'm not sure if it's still maintained). You give up a bit of [theoretical] security for a whole lot of DR insurance.

FYI the authenticator app itself has this now.

Re: Passkeys are now enabled by default for Google users

#317

Lauren Weinstein is sounding the alarm on passkeys which is flawed and that it would make a huge headache for a lot of people especilly normal folks. https://mastodon.laurenweinstein.org/@lauren/111103819626952... https://mastodon.laurenweinstein.org/@lauren/111211366080459...

Does he explain the flaw anywhere?

He says it's "easy to find" but apaprently he can't find it. https://mastodon.laurenweinstein.org/@lauren/111211489395997...

Why is "weak device password" a reason to avoid passkeys, when those users presumably have weak service passwords as well?

Re: Passkeys are now enabled by default for Google users

#318

Lauren Weinstein is sounding the alarm on passkeys which is flawed and that it would make a huge headache for a lot of people especilly normal folks. https://mastodon.laurenweinstein.org/@lauren/111103819626952... https://mastodon.laurenweinstein.org/@lauren/111211366080459...

It's not about security. It's about having a system for digital signatures that acts against the interests of the user.

Re: Passkeys are now enabled by default for Google users

#319

Earlier quoted context omitted.

Now there is a technically savvy solution that is a technical tour-de-force. Very very cool. But also completely unrealistic for the average person to use.

How? The usage was very easy. You select a contact and add them as your recovery contact (by selecting contact from your contact list) The system adds the key in the background. If they don't have the app, the app asks you to tell them to install the app (viral growth?). The users didn't need to know any thing technical. But install app, and click yes/no like they do with a 2FA app.

I don't have eight people, what then?

Re: Passkeys are now enabled by default for Google users

#320

Earlier quoted context omitted.

> nobody wants to allow plaintext export of passkeys. While noble, why? 1Password exports a plaintext file that has all of the credentials in plaintext already.

Because passkeys are supposed to be a bit more secure than plaintext passwords.

Passkeys are supposed to eliminate the need for companies to store a password so we no longer have to deal with the fallout of 40 breaches a year. In order to export passkeys it has to be in plaintext at some point, even if encrypted once again into the export file. Point is, one of the huge selling points of pushing people to use passkeys is the portability and lack of vendor lock in yet here we are with choices that are all currently vendor lock in.
Post reply on HN