Live data from Hacker News

Passkeys are now enabled by default for Google users

blog.google

341–350 of 684 posts

Re: Passkeys are now enabled by default for Google users

#341
post #201

Earlier quoted context omitted.

Passkeys are a new technology and everyone - including users, service providers, and organizations - will take time to learn and adapt. In this interim period the recommended approach is to provide passkeys as an alternative to whatever is already offered. This is the approach that Google and many other service providers are taking. That said, you are bringing up the right questions on the general topic of account re…

How can a user, right now, take control + ownership of backing up their own pass keys, without iCloud or Google? This is a privilege I currently enjoy right now, and one I am not really eager to give up.

I use passkeys everywhere I find them. I do not take control or ownership of backing up - instead I have alternative 2fa or hardware key authentication with all those accounts.

For every account I have a hardware key for, there are 3 hardware keys associated with that account - 2 on-site, 1 off-site.

Re: Passkeys are now enabled by default for Google users

#342
post #333

Earlier quoted context omitted.

Google Workspace is different than a private account, which is what we are talking about here. With Google Workspace an admin can reset / disable your 2FA, so that part is out of your hands anyway. Finally, I don't see anything in Google Workspace that requires a phone number. Someone can correct me if I'm wrong there.

If google thinks your login is suspicious, it will look for 2FA. If you don't have a phone number tied to that account at that time, it will insist you add one. Discord does the same.

That is not true. There is no requirement for a phone number.

Re: Passkeys are now enabled by default for Google users

#343

Probably a stupid question but why can't photos of my face be used to defeat this?

The biometrics aren't authenticating you. They only unlock your phone, which stores the private key used to authenticate you.

Also a photo of your face wouldn't be sufficient for FaceID.

Re: Passkeys are now enabled by default for Google users

#344
post #327

Earlier quoted context omitted.

AFAICT, the flaw is that passkeys are tied to device security. If I steal a naive person’s phone at the bar, and if I can guess that their PIN is 1234, then I can get into their Google account. The criticism is based on the idea that most non-techie folks are unlikely to use a strong PIN and are unlikely to set up strong biometrics. There’s a related criticism about malware being able to steal passkeys on PC-based sy…

What are the odds that someone with a passcode 1234 is 1/ already signed into Google on their phone or 2/ has their Google password already saved in the device password manager (since it asks you to save it every time you sign in) which is also protected by the device pin? At least in this case the thief has to steal the physical phone instead of guessing "password123" on the google signin prompt from the comfort of…

Don’t try to argue that on-device biometrics are a foolproof solution to this. Even at it’s best you can unlock a device from a sleeping (or drunk or naive) user which just brings us back to the same issue: already being logged in to a passkey service.

Re: Passkeys are now enabled by default for Google users

#345

As others have pointed out, cryptographic authentication is very hard to bootstrap if you simply loose your device. Just last month my missus cracked the glass of her iPhone. Apple repaired it under AppleCare, which is great… except … that they didn’t tell her that the “glass repair” entails them replacing the guts of the phone and wiping it in the process. Apple iPhone backups don’t contain cryptographic secrets lik…

For that reason I don't want passkey. Password and regular 2fa/totp are fine... when setting 2fa I put it on my phone and my computer and another password vault on rpi... granted, everything still in same location but still somewhat better. I'm not really sold on esim neither - regular sims let you pop and swap them easily... why complicate it?

Re: Passkeys are now enabled by default for Google users

#346
post #112
post #11

Earlier quoted context omitted.

Yes. That plus the way apple implemented it. In my case i was already on passkeys and google decided to just... forget them all on my other computers. I can't use them to get in anymore. Why? Who the heck knows. This whole passkey shit is going to be a nightmare for UX.

In general, the levels of security that people will increasingly need going forward, and the increasing requirement by companies to use that level of security, will be a usability pain for many people and a nightmare for at least a subset.

Is there any evidence that Google needs to mess with authentication flows? My mental model of the median Google account holder is that they have a bunch of photos/emails/docs/etc that are extremely valuable to them and their family, but of little value to criminals. With a dynamic like that, the security only has to be so high to deter random hackers and making it too difficult or confusing will ruin a lot of valid accounts and do much more harm than the criminals would have.

There are reasons to be skeptical of Google's motives here given their history of wanting to create user lock-in in various ways, and caring more about shiny new tech than general user experience.

Re: Passkeys are now enabled by default for Google users

#347
post #293

Earlier quoted context omitted.

And what a surprise that is, the one feature necessary to ensure vendor lock in doesn't happen was at 0 priority before they rolled it out.

The whole point is vendor lock-in.

How does that work if you can register multiple different keys using different devices from different vendors on an account?

Edit: I took the last sentence out, it was childish on my part.

Re: Passkeys are now enabled by default for Google users

#348
post #278

Earlier quoted context omitted.

Don't worry, if you lose your passkey all you need is access to your email to receive a password reset link.

That's literally the solution to "What if I lose all the passkeys associated with my account and I've also forgotten my password?"

The major problem with passkeys is that first they were poorly designed so there's no portability or ability to enroll an offline (or worse, physically unavailable, like stored in a safe) authenticator, then there's this kludge to work around the limitation.

It was obvious from day 0 (to anyone except for Apple and Microsoft) that people do have multiple devices and not all of them are from a single vendor. My only explanation is that they deliberately decided to ignore this aspect, because it wasn't in corporate interests.

They made it significantly easier to lose all the passkeys, because they made it very hard to add multiple passkeys (you literally have to walk/run/drive/fly and grab every different device you have, get it online and register - or get properly locked in with a single vendor and pray they work for you, forever).

Carrying a Yubikey does not work (you can lose it). iCloud/Windows Hello does not work (you can be on a non-Apple/Microsoft device). 1Password is better but still does not really work (you can lose access to your account). They're all SPOFs, and avoiding SPOF was deliberately made hard (you can't easily enroll a "backup" Yubikey that you don't have at hand, and if you have it at hand it's not a backup anymore).

Heck, "official" demo at passkeys.io doesn't even bother to showcase how multiple passkeys are going to be a thing at all, which is an obvious red flag.

That is, not to mention that a growing number of vendors contributed to the crappiness by limiting what kind of authenticators and which platforms one can use (BestBuy, PayPal and so on), contributing to decreased security and increased headaches.

Re: Passkeys are now enabled by default for Google users

#349

Earlier quoted context omitted.

How can a user, right now, take control + ownership of backing up their own pass keys, without iCloud or Google? This is a privilege I currently enjoy right now, and one I am not really eager to give up.

I use passkeys everywhere I find them. I do not take control or ownership of backing up - instead I have alternative 2fa or hardware key authentication with all those accounts. For every account I have a hardware key for, there are 3 hardware keys associated with that account - 2 on-site, 1 off-site.

Which hardware keys are you using? And have you found any difficulty in adding multiple keys to a web site?

Re: Passkeys are now enabled by default for Google users

#350
post #338

Earlier quoted context omitted.

You're not locked in. Want to switch? Add a passkey. Lose all your passkeys? Do the "forgot password" thing just like you've done forever.

The "forgot password" flow involves accessing your email. And accessing your email without having access to your passkey requires a device that has previously logged in to your email. And the device that has previously logged in to your email is the same device where your passkeys are stored, which is to say, the same device that is now lost or bricked, which is the reason your passkeys are lost in the first place. A…

You only use your passkey when logging in to your email account if you use a web-based client exclusivley.
Post reply on HN