As others have pointed out, cryptographic authentication is very hard to bootstrap if you simply loose your device. Just last month my missus cracked the glass of her iPhone. Apple repaired it under AppleCare, which is great… except … that they didn’t tell her that the “glass repair” entails them replacing the guts of the phone and wiping it in the process. Apple iPhone backups don’t contain cryptographic secrets lik…
Passkeys are now enabled by default for Google users
351–360 of 684 posts
Re: Passkeys are now enabled by default for Google users
#352As others have pointed out, cryptographic authentication is very hard to bootstrap if you simply loose your device. Just last month my missus cracked the glass of her iPhone. Apple repaired it under AppleCare, which is great… except … that they didn’t tell her that the “glass repair” entails them replacing the guts of the phone and wiping it in the process. Apple iPhone backups don’t contain cryptographic secrets lik…
In any case, you should have multiple methods. It could be passkeys on multiple devices. It could be TOTP, plus recovery codes in a safe. Passkeys are just one more method.
For the longest time, the gold standard for authenticating people has been tamperproof hardware with keys that cannot be copied. Except iPhones actually have credible biometrics on top of that. Much better than Yubikeys, for example. Of course you always need to have at least one backup device or other method in case your primary device is lost. Now that this is finally making it's way to the “normal people”, it's suddenly a “run away screaming” scenario? Come on.
Re: Passkeys are now enabled by default for Google users
#353Earlier quoted context omitted.
> never lose your phone number The forced SMS 2FA that banks and credit card companies have started implementing infuriates me for exactly this reason.
Especially when they migrate previously password-only accounts to requiring what they think your phone number might be, and especially given that it costs under $15 to borrow somebody's phone number for the day without their knowledge.
Re: Passkeys are now enabled by default for Google users
#354Earlier quoted context omitted.
I had a fire. I lost every single thing I own, except my landlord grabbed my phone, bless him. Otherwise I would have been totally stuck as all my TOTP apps are on there. Also, never lose your phone number. I can't get back into my Google account even though I have the username, password and recovery email because I can never get the SMS code.
The solution would be to have a separate phone and phone number used solely for authenticating. It will never leave home, and never be used except to authenticate. Still vulnerable to home fire, however.
Re: Passkeys are now enabled by default for Google users
#355>To use passkeys, you just use a fingerprint, face scan or pin to unlock your device, and they are 40% faster than passwords >We’ve found that one of the most immediate benefits of passkeys is that they spare people the headache of remembering all those numbers and special characters in passwords. So they aren't considering at all how easy is the autofill password feature with a password manager (that they even have…
Passwords are a nightmare for both users and service providers for a variety of reasons. And password autofill is a bandaid at best.
If I had a quarter for the number of times I've personally used a password manager to auto generate a password which was then either reject by the website due to absurd password complexity requirements, or had the password seemingly accepted but in reality silently truncated behind the scenes....
I know you're commenting on a Google blog post, but FWIW Apple acknowledges password managers/autofill in the "Deploy passkeys at work" talk from WWDC 2023:
"Let’s look at a side-by-side comparison of the experience of creating a new password versus creating a new passkey. As you can see, creating a passkey is significantly faster and easier than creating a password. Just Face ID and you’re done. Now that we’ve looked at creation, let’s compare the experience of signing back in. With a password, the user has to remember and type in the password. With a passkey, they just Face ID and they’re done. A password manager can help improve the experience, but even the best password manager can’t compete with the user experience of passkeys. You are used to having to make tradeoffs between better security and a better user experience. Passkeys achieve something rare: great security and a great user experience."
Source: https://developer.apple.com/videos/play/wwdc2023/10263/?time...
Re: Passkeys are now enabled by default for Google users
#356As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?
Passkeys are a new technology and everyone - including users, service providers, and organizations - will take time to learn and adapt. In this interim period the recommended approach is to provide passkeys as an alternative to whatever is already offered. This is the approach that Google and many other service providers are taking. That said, you are bringing up the right questions on the general topic of account re…
They strongly want to lock you in to their own authentication platforms (iCloud Keychain, Windows Hello, 1Password*), that's why they don't want to address this.
It's impossible they're not aware about those issues. Anyone with a brain and some technical expertise would come up with those questions in an evening or two, and Passkeys were worked on for months. To best of my awareness, there is no official acknowledgement (support replies "no, you can't do this" doesn't count, that's just restating facts, not acknowledging an issue).
*) Ok, 1Password says they're all about user freedoms and that it's up to user to decide where they store their passkeys - but that's what they say, not what they do. What they do is indistinguishable from Apple and Microsoft.
Re: Passkeys are now enabled by default for Google users
#357Re: Passkeys are now enabled by default for Google users
#358Earlier quoted context omitted.
iCloud is unfortunately impossible to adequately secure for that use case. If you shoulder-surf somebody's phone unlock PIN and grab their phone, you have everything you need to take over their iCloud account, including their passkeys and the capability of locking out all of the victim's other trusted Apple devices and changing their iCloud password. This was very surprising for me to witness first hand – fortunately…
It is a fair observation. And I can see why users tend to be alarmed about this. Although in my experience users tend to significantly underestimate the real risks of online attacks relative to these more visceral threats. Let met ask you: has that discovery made you stop using your iPhone, or storing passwords or other critical data in your iCloud? If the answer is "No", then you're strictly better off moving to pas…
Yes, it has (the latter). I was a big fan of (non-synchronized) on-device passkeys, but this has significantly changed the threat model for me.
I use a third-party password manager exclusively now, and I'll probably be using its synchronized Passkey implementation too if it turns out to be any good.
As soon as Apple starts offering a different set of security trade-offs (e.g. make usage of the recovery key mandatory when resetting my iCloud password, or at least implement a timed lockout), I'd gladly start using iCloud Passkeys and maybe also its password manager.
Re: Passkeys are now enabled by default for Google users
#359Earlier quoted context omitted.
If google thinks your login is suspicious, it will look for 2FA. If you don't have a phone number tied to that account at that time, it will insist you add one. Discord does the same.
That is not true. There is no requirement for a phone number.
I'm not the only one to have encountered this
Re: Passkeys are now enabled by default for Google users
#360Earlier quoted context omitted.
Passkeys represent the cumulative wisdom and experience (and compromises!) of the whole industry on how to keep users safe online. Appreciate your opinions that these efforts are doomed. It is safe to say, "We'll surely find out!"
"The Industry" also has interests like making password sharing impossible, uniquely tracking users and _doesn't care_ if users get locked out. The industry does not put users first. It puts it's own risk reduction first.