Live data from Hacker News

Passkeys are now enabled by default for Google users

blog.google

371–380 of 684 posts

Re: Passkeys are now enabled by default for Google users

#371

As others have pointed out, cryptographic authentication is very hard to bootstrap if you simply loose your device. Just last month my missus cracked the glass of her iPhone. Apple repaired it under AppleCare, which is great… except … that they didn’t tell her that the “glass repair” entails them replacing the guts of the phone and wiping it in the process. Apple iPhone backups don’t contain cryptographic secrets lik…

what you are describing is why I use a virtual phone for all services.

you can do it on your own with twilio, then create a phone number and have a program forward you stuff to your real phone.

the twilio phone is hard to lose as it has an api and you can toss it when you want to start over.

except now, you need an entire phone virtualized as your proxy instead of just a twilio phone number.

they keep raising the barrier

Re: Passkeys are now enabled by default for Google users

#372

I wont add on to the technical aspect of the discussion, but this whole article is "its easier and its faster and its less expensive for you!!", a data-harvesting tactic having been done for years. Please think, people. I get the security aspect, but this technology gives up an astronomic amount of personal freedom - even if vendor lock-in is somehow eliminated - and biometric data.

You don't know what you're talking about.

Biometric data is only stored on your device. Logging into an app or website with a passkey just uses bog standard asymmetric crypto (public/private keypair). Also a lot of thought was put into the WebAuthn standard (an open standard) to make sure it can't be used as a tracking vector.

Re: Passkeys are now enabled by default for Google users

#373

Earlier quoted context omitted.

I use passkeys everywhere I find them. I do not take control or ownership of backing up - instead I have alternative 2fa or hardware key authentication with all those accounts. For every account I have a hardware key for, there are 3 hardware keys associated with that account - 2 on-site, 1 off-site.

How do you register your off-site hardware key. Did you have to go retrieve it each time you wanted to make an account? I suppose every time one makes an account one can register the two on-site keys, and then rotate one of your on-site key to off-site and take the off-site key home with you, and then finally register it. Maybe I should get a third key...

I think you answered your own question! The three key is optimum for ease of rotating (or so you can carry one on person) - but if your house burns down with your phone in it - you will lose anything set up since your last offsite rotation.

Sounds paranoid / crazy - but I have 0 anxiety about being locked out of an account that matters.

Re: Passkeys are now enabled by default for Google users

#374

1Password enabled PassKey support recently and I was "surprised" to learn that there is no way of exporting them out of 1Password. They're not included in the 1PUX format export, nor in the CSV. That means that they're literally impossible to back up. If 1Password goes down, or the company stops operating, or anything else like that, your Passkeys are just... gone. Absolutely no way to recover them.

Can't you enroll a Yubikey and keep it in a safe?

Re: Passkeys are now enabled by default for Google users

#375
post #359

Earlier quoted context omitted.

That is not true. There is no requirement for a phone number.

https://www.reddit.com/r/GMail/comments/zegzh6/to_help_keep_... I'm not the only one to have encountered this

Again, that's not a requirement for a phone number.

That's asking a user to verify themselves with a provided number.

Likely because the user doesn't have anything else set up for 2FA.

Re: Passkeys are now enabled by default for Google users

#376
post #301

Lauren Weinstein is sounding the alarm on passkeys which is flawed and that it would make a huge headache for a lot of people especilly normal folks. https://mastodon.laurenweinstein.org/@lauren/111103819626952... https://mastodon.laurenweinstein.org/@lauren/111211366080459...

Yup! I've had similar complaints for years now. Modulo the whole privacy/vendor lockin issue, passkeys are not a terrible alternative to people without 2FA reusing the same basic password on every single website. However, when you actually rely on it to secure things , it quickly becomes a massive nightmare - made even worse by it being treated as equivalent to password+2FA.

> made even worse by it being treated as equivalent to password+2FA.

passkeys are significantly more secure than the most widely-used/most popular forms of 2FA, because the most popular forms of 2FA are TOTP and SMS, and both are subject to phishing attacks. A passkey alone is much more secure than the vast majority of password + 2FA combinations.

The only thing stronger than a passkey standing alone is a Security Key, but Security Keys come with a lot of usability downsides that can easily bite the average user, including:

- inconvenience: you have to remember to carry it around with you everywhere (and not lose it!)

- recoverability: you're completely screwed if you lose it and don't have extras that you already previously added to your accounts. (this also means that you need to buy at least two security keys to have a decent recovery story.)

- rotation (have to log in to every single service, one by one, to re-add new key if you change keys)

And if you really want the extra security that a Security Key provides, you can use a Security Key as a passkey.

Re: Passkeys are now enabled by default for Google users

#377
post #359

Earlier quoted context omitted.

https://www.reddit.com/r/GMail/comments/zegzh6/to_help_keep_... I'm not the only one to have encountered this

Again, that's not a requirement for a phone number. That's asking a user to verify themselves with a provided number . Likely because the user doesn't have anything else set up for 2FA.

This is not true. It will ask for a provided number if you've already provided one, but if you've never provided one, it'll ask for any number and treat that as the provided number for future reference.

Re: Passkeys are now enabled by default for Google users

#378

Earlier quoted context omitted.

Maybe they could have used more marketable terms like "1-time password", or "barely a password", or "mini-password" (to denote minimal expected usage of your password), etc.?

I would prefer something like “secure id”. It reflects that the mechanism is a way to securely store some identity related information. It is not a mechanism to establish that identity. The value proposition is still obvious: You need to establish your identity once, and then you can securely save it and share it across devices and avoid having to reestablish your identity every time. It also removes the “password” c…

Yep, 100% this! I vote for "secure id" for all the reasons cited.

Re: Passkeys are now enabled by default for Google users

#379
post #360

Earlier quoted context omitted.

"The Industry" also has interests like making password sharing impossible, uniquely tracking users and _doesn't care_ if users get locked out. The industry does not put users first. It puts it's own risk reduction first.

Did you know that Apple allows sharing passkeys via Airdrop?

Doesn't that give access to everything you've signed in using that passkey? Rather than e.g. Sharing the password for the family Netflix account.

Re: Passkeys are now enabled by default for Google users

#380
post #201

Earlier quoted context omitted.

Passkeys are a new technology and everyone - including users, service providers, and organizations - will take time to learn and adapt. In this interim period the recommended approach is to provide passkeys as an alternative to whatever is already offered. This is the approach that Google and many other service providers are taking. That said, you are bringing up the right questions on the general topic of account re…

All those issues were obvious from the day zero, and raised multiple times by many people. They're deliberately ignored by the stakeholders. They strongly want to lock you in to their own authentication platforms (iCloud Keychain, Windows Hello, 1Password*), that's why they don't want to address this. It's impossible they're not aware about those issues. Anyone with a brain and some technical expertise would come up…

You can recover access to your iCloud Keychain even if you've lost 100% of your devices.

See the section titled "Recovery security" in this article:

https://support.apple.com/en-us/102195

Relevant excerpt for those too lazy to click through:

"However, it's also important that passkeys be recoverable even in the event that all associated devices are lost. Passkeys can be recovered through iCloud keychain escrow, which is also protected against brute-force attacks, even by Apple."

Post reply on HN