Oh I'm seething. Screw google, so god damn much. They've been accidentally enabling it for nearly a month if not more. And the UX has been infinitely confusing. I've been using 2fa for a decade (not an exaggeration, an understatement). I've been using u2f since the first month it was available and FUCK Google for this blog post. A month ago I logged in and tried to check on my security tokens. Their UI was silently u…
Your comment would be more impactful if it explained clearly what the problem is. What does it mean to upconvert a security token? In fact, what’s a security token? (I ask mainly so that I can watch out for whatever bit you. On the face of it, the blog post seems pretty anodyne. The screenshot shows that it’s optional, not forced, since there’s a "not now" button.) EDIT: oh, they auto converted your security keys to…
Passkeys are now enabled by default for Google users
361–370 of 684 posts
Re: Passkeys are now enabled by default for Google users
#362Earlier quoted context omitted.
How can a user, right now, take control + ownership of backing up their own pass keys, without iCloud or Google? This is a privilege I currently enjoy right now, and one I am not really eager to give up.
I use passkeys everywhere I find them. I do not take control or ownership of backing up - instead I have alternative 2fa or hardware key authentication with all those accounts. For every account I have a hardware key for, there are 3 hardware keys associated with that account - 2 on-site, 1 off-site.
I suppose every time one makes an account one can register the two on-site keys, and then rotate one of your on-site key to off-site and take the off-site key home with you, and then finally register it.
Maybe I should get a third key...
Re: Passkeys are now enabled by default for Google users
#363Can you store a passkey on a YubiKey? Or just buy a $100 android phone just for passkey backup to keep at home?
2. Most services let you add more than one passkey. Using 1Password, or using iCloud Keychain or similar, you can sync passkeys between devices. Even with iCloud Keychain, if you have only one device, you're given a recovery code that can bootstrap the entire system from zero if your only device is stolen.
Re: Passkeys are now enabled by default for Google users
#364As others have pointed out, cryptographic authentication is very hard to bootstrap if you simply loose your device. Just last month my missus cracked the glass of her iPhone. Apple repaired it under AppleCare, which is great… except … that they didn’t tell her that the “glass repair” entails them replacing the guts of the phone and wiping it in the process. Apple iPhone backups don’t contain cryptographic secrets lik…
I believe all of the issues you've described, but you can usually add multiple passkeys to each service. There is nothing stopping you from adding your iPhone and a cheap android phone and having redundancy, or using 1Password and storing your passkey in there.
iPhone backups do store backups of the media stored in iCloud Keychain, if you have another apple device or if you have the recovery key, you can get back in. You just need the device passcode or recovery key and you can re-bootstrap everything. eSIMs are unique because they're carrier things and those things have and always will be a pain and tied to stores and phone calls.
Re: Passkeys are now enabled by default for Google users
#365Earlier quoted context omitted.
How? The usage was very easy. You select a contact and add them as your recovery contact (by selecting contact from your contact list) The system adds the key in the background. If they don't have the app, the app asks you to tell them to install the app (viral growth?). The users didn't need to know any thing technical. But install app, and click yes/no like they do with a 2FA app.
I don't have eight people, what then?
You have to have at least 3 peers, though (IIRC, 2/3 is the minimum split possible that would provide fault tolerance).
Re: Passkeys are now enabled by default for Google users
#366As others have pointed out, cryptographic authentication is very hard to bootstrap if you simply loose your device. Just last month my missus cracked the glass of her iPhone. Apple repaired it under AppleCare, which is great… except … that they didn’t tell her that the “glass repair” entails them replacing the guts of the phone and wiping it in the process. Apple iPhone backups don’t contain cryptographic secrets lik…
Re: Passkeys are now enabled by default for Google users
#367Earlier quoted context omitted.
AFAICT, the flaw is that passkeys are tied to device security. If I steal a naive person’s phone at the bar, and if I can guess that their PIN is 1234, then I can get into their Google account. The criticism is based on the idea that most non-techie folks are unlikely to use a strong PIN and are unlikely to set up strong biometrics. There’s a related criticism about malware being able to steal passkeys on PC-based sy…
What are the odds that someone with a passcode 1234 is 1/ already signed into Google on their phone or 2/ has their Google password already saved in the device password manager (since it asks you to save it every time you sign in) which is also protected by the device pin? At least in this case the thief has to steal the physical phone instead of guessing "password123" on the google signin prompt from the comfort of…
...very high? I don't understand how this is unlikely, pretty much every phone owner with a google account is signed into that account on their phone.
Re: Passkeys are now enabled by default for Google users
#368Re: Passkeys are now enabled by default for Google users
#369Earlier quoted context omitted.
I use passkeys everywhere I find them. I do not take control or ownership of backing up - instead I have alternative 2fa or hardware key authentication with all those accounts. For every account I have a hardware key for, there are 3 hardware keys associated with that account - 2 on-site, 1 off-site.
Which hardware keys are you using? And have you found any difficulty in adding multiple keys to a web site?
By count of sites, most sites don't appear to take security that seriously so anything more than a password is off the cards, but the big ones - the ones that actually matter; email, cloud, etc. should all be able to be secured.
Re: Passkeys are now enabled by default for Google users
#370Earlier quoted context omitted.
Is version 8 reasonably mac-like? On 7 it's still a mac application that acts like a true mac application (drag/drop works properly everywhere, expansion, properly keyboard-enabled, etc) which is well nigh impossible when running inside a chrome box. Agile Bits support kept insisting it was the same as the old native app and people kept complaining about bugs until I stopped following it.
It’s so rare that I use anything other than the 1Password Chrome extension that I couldn’t really tell you! The main app seems.. fine? But like I say, I hardly use it, so I probably wouldn’t notice details like you mention. Do you have a different workflow where you use the main app a lot?
With 1password 7 whe safari plug in is more conveniently integrated than the chrome one which is pretty clunkly by comparison, though this is true of other chrome plug ins too. But that's not a big deal as I rarely use chrome anyway, just for google docs which don't need 1password.