Live data from Hacker News

Passkeys are now enabled by default for Google users

blog.google

361–370 of 684 posts

Re: Passkeys are now enabled by default for Google users

#361
post #214

Oh I'm seething. Screw google, so god damn much. They've been accidentally enabling it for nearly a month if not more. And the UX has been infinitely confusing. I've been using 2fa for a decade (not an exaggeration, an understatement). I've been using u2f since the first month it was available and FUCK Google for this blog post. A month ago I logged in and tried to check on my security tokens. Their UI was silently u…

Your comment would be more impactful if it explained clearly what the problem is. What does it mean to upconvert a security token? In fact, what’s a security token? (I ask mainly so that I can watch out for whatever bit you. On the face of it, the blog post seems pretty anodyne. The screenshot shows that it’s optional, not forced, since there’s a "not now" button.) EDIT: oh, they auto converted your security keys to…

"Not forced" would mean the dialog has a "Nope", "Not" or "Nuh uh" button instead of "Not now" and permanently goes away when clicked, never to return.

Re: Passkeys are now enabled by default for Google users

#362

Earlier quoted context omitted.

How can a user, right now, take control + ownership of backing up their own pass keys, without iCloud or Google? This is a privilege I currently enjoy right now, and one I am not really eager to give up.

I use passkeys everywhere I find them. I do not take control or ownership of backing up - instead I have alternative 2fa or hardware key authentication with all those accounts. For every account I have a hardware key for, there are 3 hardware keys associated with that account - 2 on-site, 1 off-site.

How do you register your off-site hardware key. Did you have to go retrieve it each time you wanted to make an account?

I suppose every time one makes an account one can register the two on-site keys, and then rotate one of your on-site key to off-site and take the off-site key home with you, and then finally register it.

Maybe I should get a third key...

Re: Passkeys are now enabled by default for Google users

#363

Can you store a passkey on a YubiKey? Or just buy a $100 android phone just for passkey backup to keep at home?

1. Yes! Using resident keys, yubikeys can store a number of them. Not an infinite number. It's 25 resident keys.

2. Most services let you add more than one passkey. Using 1Password, or using iCloud Keychain or similar, you can sync passkeys between devices. Even with iCloud Keychain, if you have only one device, you're given a recovery code that can bootstrap the entire system from zero if your only device is stolen.

Re: Passkeys are now enabled by default for Google users

#364

As others have pointed out, cryptographic authentication is very hard to bootstrap if you simply loose your device. Just last month my missus cracked the glass of her iPhone. Apple repaired it under AppleCare, which is great… except … that they didn’t tell her that the “glass repair” entails them replacing the guts of the phone and wiping it in the process. Apple iPhone backups don’t contain cryptographic secrets lik…

> Run away screaming. Don’t believe the hype. Wait until the vendors get their act together and come up with a solution for transfer and recovery.

I believe all of the issues you've described, but you can usually add multiple passkeys to each service. There is nothing stopping you from adding your iPhone and a cheap android phone and having redundancy, or using 1Password and storing your passkey in there.

iPhone backups do store backups of the media stored in iCloud Keychain, if you have another apple device or if you have the recovery key, you can get back in. You just need the device passcode or recovery key and you can re-bootstrap everything. eSIMs are unique because they're carrier things and those things have and always will be a pain and tied to stores and phone calls.

Re: Passkeys are now enabled by default for Google users

#365

Earlier quoted context omitted.

How? The usage was very easy. You select a contact and add them as your recovery contact (by selecting contact from your contact list) The system adds the key in the background. If they don't have the app, the app asks you to tell them to install the app (viral growth?). The users didn't need to know any thing technical. But install app, and click yes/no like they do with a 2FA app.

I don't have eight people, what then?

You use different numbers, for example 3/5 or 2/3.

You have to have at least 3 peers, though (IIRC, 2/3 is the minimum split possible that would provide fault tolerance).

Re: Passkeys are now enabled by default for Google users

#366

As others have pointed out, cryptographic authentication is very hard to bootstrap if you simply loose your device. Just last month my missus cracked the glass of her iPhone. Apple repaired it under AppleCare, which is great… except … that they didn’t tell her that the “glass repair” entails them replacing the guts of the phone and wiping it in the process. Apple iPhone backups don’t contain cryptographic secrets lik…

that is why its important for 3rd party tools like bitwarden and 1password to support passkeys..

Re: Passkeys are now enabled by default for Google users

#367
post #327

Earlier quoted context omitted.

AFAICT, the flaw is that passkeys are tied to device security. If I steal a naive person’s phone at the bar, and if I can guess that their PIN is 1234, then I can get into their Google account. The criticism is based on the idea that most non-techie folks are unlikely to use a strong PIN and are unlikely to set up strong biometrics. There’s a related criticism about malware being able to steal passkeys on PC-based sy…

What are the odds that someone with a passcode 1234 is 1/ already signed into Google on their phone or 2/ has their Google password already saved in the device password manager (since it asks you to save it every time you sign in) which is also protected by the device pin? At least in this case the thief has to steal the physical phone instead of guessing "password123" on the google signin prompt from the comfort of…

> What are the odds that someone with a passcode 1234 is 1/ already signed into Google on their phone

...very high? I don't understand how this is unlikely, pretty much every phone owner with a google account is signed into that account on their phone.

Re: Passkeys are now enabled by default for Google users

#368
I wont add on to the technical aspect of the discussion, but this whole article is "its easier and its faster and its less expensive for you!!", a data-harvesting tactic having been done for years. Please think, people. I get the security aspect, but this technology gives up an astronomic amount of personal freedom - even if vendor lock-in is somehow eliminated - and biometric data.

Re: Passkeys are now enabled by default for Google users

#369

Earlier quoted context omitted.

I use passkeys everywhere I find them. I do not take control or ownership of backing up - instead I have alternative 2fa or hardware key authentication with all those accounts. For every account I have a hardware key for, there are 3 hardware keys associated with that account - 2 on-site, 1 off-site.

Which hardware keys are you using? And have you found any difficulty in adding multiple keys to a web site?

Yubikey keys - zero difficulty adding multiple - if a site doesn't allow multiple I wouldn't lock my account down to a single point of failure. All the big players seem to offer it, and I can not recall any that didn't. Google in the "advanced protection" days forced you to have more than 2 keys for this reason.

By count of sites, most sites don't appear to take security that seriously so anything more than a password is off the cards, but the big ones - the ones that actually matter; email, cloud, etc. should all be able to be secured.

Re: Passkeys are now enabled by default for Google users

#370
post #285

Earlier quoted context omitted.

Is version 8 reasonably mac-like? On 7 it's still a mac application that acts like a true mac application (drag/drop works properly everywhere, expansion, properly keyboard-enabled, etc) which is well nigh impossible when running inside a chrome box. Agile Bits support kept insisting it was the same as the old native app and people kept complaining about bugs until I stopped following it.

It’s so rare that I use anything other than the 1Password Chrome extension that I couldn’t really tell you! The main app seems.. fine? But like I say, I hardly use it, so I probably wouldn’t notice details like you mention. Do you have a different workflow where you use the main app a lot?

I keep a lot (including images) in the main app as an ecrypted shared resource for IDs and various other secure info. If I suddenly need my insurance card I can quickly grab it out of the app rather than rummage through the (unencrypted) icloud or dropbox filesystem on ios. And I can cut/past text out of the images. I also use it for logging into apps, dragging credentials into remote machines over ssh etc.

With 1password 7 whe safari plug in is more conveniently integrated than the chrome one which is pretty clunkly by comparison, though this is true of other chrome plug ins too. But that's not a big deal as I rarely use chrome anyway, just for google docs which don't need 1password.

Post reply on HN