Live data from Hacker News

Passkeys are now enabled by default for Google users

blog.google

331–340 of 684 posts

Re: Passkeys are now enabled by default for Google users

#331
post #262

Earlier quoted context omitted.

How can a user, right now, take control + ownership of backing up their own pass keys, without iCloud or Google? This is a privilege I currently enjoy right now, and one I am not really eager to give up.

Password managers like Dashlane and 1Password have announced support for storing and synching passkeys. As passkeys becomes more popular I expect more providers to step up as well. Ecosystem lockin is not how we make a new technology like this successful. And all players in the game understand that.

Appreciate the response. And I wish this message was front and center. The Attestation feature is what worries me, when, say, the bank turns it on for a few 'blessed' providers, or mandate a hardware implementation.

Watching https://github.com/keepassxreboot/keepassxc/issues/1870 with baited breath... :)

Re: Passkeys are now enabled by default for Google users

#332
post #13

As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?

I had a fire. I lost every single thing I own, except my landlord grabbed my phone, bless him. Otherwise I would have been totally stuck as all my TOTP apps are on there. Also, never lose your phone number. I can't get back into my Google account even though I have the username, password and recovery email because I can never get the SMS code.

The solution would be to have a separate phone and phone number used solely for authenticating. It will never leave home, and never be used except to authenticate. Still vulnerable to home fire, however.

Re: Passkeys are now enabled by default for Google users

#333

Earlier quoted context omitted.

All the Google accounts I had to use for work eventually required a phone number.

Google Workspace is different than a private account, which is what we are talking about here. With Google Workspace an admin can reset / disable your 2FA, so that part is out of your hands anyway. Finally, I don't see anything in Google Workspace that requires a phone number. Someone can correct me if I'm wrong there.

If google thinks your login is suspicious, it will look for 2FA. If you don't have a phone number tied to that account at that time, it will insist you add one.

Discord does the same.

Re: Passkeys are now enabled by default for Google users

#334
post #327
post #321

Earlier quoted context omitted.

What is the flaw?

AFAICT, the flaw is that passkeys are tied to device security. If I steal a naive person’s phone at the bar, and if I can guess that their PIN is 1234, then I can get into their Google account. The criticism is based on the idea that most non-techie folks are unlikely to use a strong PIN and are unlikely to set up strong biometrics. There’s a related criticism about malware being able to steal passkeys on PC-based sy…

What are the odds that someone with a passcode 1234 is 1/ already signed into Google on their phone or 2/ has their Google password already saved in the device password manager (since it asks you to save it every time you sign in) which is also protected by the device pin?

At least in this case the thief has to steal the physical phone instead of guessing "password123" on the google signin prompt from the comfort of their home.

Also- how many non-techy people do you know that avoid using on-device biometrics? On my end, the number is approximately 0.

Re: Passkeys are now enabled by default for Google users

#335
post #327
post #321

Earlier quoted context omitted.

What is the flaw?

AFAICT, the flaw is that passkeys are tied to device security. If I steal a naive person’s phone at the bar, and if I can guess that their PIN is 1234, then I can get into their Google account. The criticism is based on the idea that most non-techie folks are unlikely to use a strong PIN and are unlikely to set up strong biometrics. There’s a related criticism about malware being able to steal passkeys on PC-based sy…

If someone steals my phone and guesses my pin they already have access to my Google account because I'm signed in. To look at my email they just have to click on the gmail app. This "flaw" exists regrardless of password or passkeys

Re: Passkeys are now enabled by default for Google users

#336
post #327
post #321

Earlier quoted context omitted.

What is the flaw?

AFAICT, the flaw is that passkeys are tied to device security. If I steal a naive person’s phone at the bar, and if I can guess that their PIN is 1234, then I can get into their Google account. The criticism is based on the idea that most non-techie folks are unlikely to use a strong PIN and are unlikely to set up strong biometrics. There’s a related criticism about malware being able to steal passkeys on PC-based sy…

Won’t most people be logged into their Google account anyways? So if you steal their phone, and guess their PIN then you can just use the already logged in account.

What does this change?

Re: Passkeys are now enabled by default for Google users

#337
post #317

Earlier quoted context omitted.

Does he explain the flaw anywhere? He says it's "easy to find" but apaprently he can't find it. https://mastodon.laurenweinstein.org/@lauren/111211489395997... Why is "weak device password" a reason to avoid passkeys, when those users presumably have weak service passwords as well?

It seems like his argument is that putting access to valuable accounts on your phone is a bad practice, because if your phone is stolen at the club after the thief watched you enter your code, then the thief can get at your banking, brokerage, crypto, password manager, etc. But that argument doesn't address how passkeys somehow make that worse. Sure, if you don't want your valuable stuff stolen, don't put it on your…

The point is that the phone with a crappy 4 digit pin can be used to authenticate everything on every device the user owns that uses passkeys. It's a one stop shop of failure.

Re: Passkeys are now enabled by default for Google users

#338
post #274

Earlier quoted context omitted.

I had a discussion with my mother advising her to switch: she is afraid of changing ISP because her email is tied to her provider. We fixed this on mobile years ago but email is still a goddamn mess. Moral of the story: never get locked in.

You're not locked in. Want to switch? Add a passkey. Lose all your passkeys? Do the "forgot password" thing just like you've done forever.

The "forgot password" flow involves accessing your email. And accessing your email without having access to your passkey requires a device that has previously logged in to your email. And the device that has previously logged in to your email is the same device where your passkeys are stored, which is to say, the same device that is now lost or bricked, which is the reason your passkeys are lost in the first place.

And sure, you and I have multiple devices. We're in the minority. Most people just have the one. Without another way in, they're irrevocably fucked.

Re: Passkeys are now enabled by default for Google users

#339
As others have pointed out, cryptographic authentication is very hard to bootstrap if you simply loose your device.

Just last month my missus cracked the glass of her iPhone. Apple repaired it under AppleCare, which is great… except… that they didn’t tell her that the “glass repair” entails them replacing the guts of the phone and wiping it in the process.

Apple iPhone backups don’t contain cryptographic secrets like eSIMs!

She got stuck in a loop where she couldn’t activate her eSIM because that needed her email, but her email needed MS Authenticator, which she couldn’t activate without an SMS.

She had to drive to the Telco with a pile of photo ID to reissue her eSIM. Her bank account got locked in the process despite the password being correct because of some sort of phone hardware lock.

This took days to fix and multiple in-person visits to various organisations. If this had happened while overseas on holiday, she would have been screwed.

Times have changed.

Your entire digital identity is now a smart card in your phones

That Smart Card is either a SIM card or an onboard TPM chip, but in any event if you lose it, you may as well be dead as far as anyone else is concerned.

Passkeys make this much worse. At least if you still have a physical SIM you can transfer it from any phone to any other phone.

Passkeys are not cross-vendor transferable!

Run away screaming. Don’t believe the hype. Wait until the vendors get their act together and come up with a solution for transfer and recovery.

Re: Passkeys are now enabled by default for Google users

#340
>To use passkeys, you just use a fingerprint, face scan or pin to unlock your device, and they are 40% faster than passwords

>We’ve found that one of the most immediate benefits of passkeys is that they spare people the headache of remembering all those numbers and special characters in passwords.

So they aren't considering at all how easy is the autofill password feature with a password manager (that they even have built in Chrome/Android).

Post reply on HN