Earlier quoted context omitted.
"The Industry" also has interests like making password sharing impossible, uniquely tracking users and _doesn't care_ if users get locked out. The industry does not put users first. It puts it's own risk reduction first.
Did you know that Apple allows sharing passkeys via Airdrop?
Passkeys are now enabled by default for Google users
401–410 of 684 posts
Re: Passkeys are now enabled by default for Google users
#402So what happens when I die and my spouse or next of kin has to deal with this stuff? As the executor of my father's estate, he kept a physical password book that was instrumental in making it easy for me to settle his affairs.
Re: Passkeys are now enabled by default for Google users
#403Earlier quoted context omitted.
Does he explain the flaw anywhere? He says it's "easy to find" but apaprently he can't find it. https://mastodon.laurenweinstein.org/@lauren/111211489395997... Why is "weak device password" a reason to avoid passkeys, when those users presumably have weak service passwords as well?
It seems like his argument is that putting access to valuable accounts on your phone is a bad practice, because if your phone is stolen at the club after the thief watched you enter your code, then the thief can get at your banking, brokerage, crypto, password manager, etc. But that argument doesn't address how passkeys somehow make that worse. Sure, if you don't want your valuable stuff stolen, don't put it on your…
Re: Passkeys are now enabled by default for Google users
#404As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?
Passkeys are a new technology and everyone - including users, service providers, and organizations - will take time to learn and adapt. In this interim period the recommended approach is to provide passkeys as an alternative to whatever is already offered. This is the approach that Google and many other service providers are taking. That said, you are bringing up the right questions on the general topic of account re…
Talk about victim blaming. Google and other companies introduce policies that make total identity lockout both easier and more problematic. Instead of investing in customer service to deal with this issue, the customer needs to "have a plan". What a crazy coincidence that this policy increases Google's profitability by decreasing support.
Re: Passkeys are now enabled by default for Google users
#405Earlier quoted context omitted.
> This is not true. What is not true? > if you've never provided one I started this thread off with don't provide a number. Again, set up a alternate 2FA with them and you won't have to deal with a phone number at all. > and treat that as the provided number for future reference Even if they did add it in, you could remove it later.
> What is not true? The claim that google will never insist you set up 2FA by providing them a phone number if their ML algorithms decide your log in is suspicious. Based on my own experiences with a little used google account and finding the messages of other users who have encountered the same error. What is your basis for claiming that my position is untrue?
1) that's not what I said.
2) that flow you describe isn't asking you to set up SMS 2FA. It is asking you to verify an account with SMS. Likely because there is no other way for them to verify your account.
> Based on my own experiences with a little used google account and finding the messages of other users who have encountered the same error.
The number of people who've reported that error is super small. Even the link you provided is 10 months old. This must be related to an edge case of not having another 2FA set up.
> What is your basis for claiming that my position is untrue?
You said that it insists you add a number. I don't believe that is true. The example you provided does not show that is true.
Re: Passkeys are now enabled by default for Google users
#406Earlier quoted context omitted.
To add, it is pretty poor there is no FAQ linked to from that post to answer basic non-technical questions as to how this is intended to be used. I assume as a technical person, the answer is I should have a backup device with a friend and/or store my passkeys somehow on my Apple or Microsoft or password manager account as well. But it needs more explanation in detail from Google!
You can try this: https://support.google.com/accounts/answer/13548313?hl=en , this help center page is linked to from various parts of the product experience for regular users to get a better idea about passkeys if they are interseted.
Re: Passkeys are now enabled by default for Google users
#407Earlier quoted context omitted.
Nobody should be using a remembered password anymore. Most people are likely using the phone for both the password and the MFA code.
> Nobody should be using a remembered password anymore. Nobody is a strong number, why? I don't want to use biometrics for logging in to my SSH terminal. I dislike having to use my phone for authentication methods. I go many places without my phone. Even tempted to gon on holiday without it. Maybe I'm just one of the few who actually enjoys turning it off when coding, developing or whatever.
Re: Passkeys are now enabled by default for Google users
#408Earlier quoted context omitted.
This is accurate, but by putting your passkey backup with that external entity, you are putting all your keys in that basket. Passwords have an obvious, backup option with zero dependencies on third-parties: A printed list in a fire safe. I would not advise users go heavily with any passkey provider that does not provide a physical backup of a similar form that can be secured through non-technical means, and that can…
The problem with that is people don't have fire safes. Or homes in some cases (e.g. many unhoused people have smartphones now). Also people need to travel and do recovery without having to fly home to their safe. The idea that printing a backup is easy and an option for many people is often not the case.
I go out on a limb and say one smartphone usually - that is at heightened risk of getting stolen. With passwords, the person would probably just pick something they can remember in case the phone gets stolen. With passkeys, what should they do?
Re: Passkeys are now enabled by default for Google users
#409Earlier quoted context omitted.
Honestly, if they'd just give me the option to write it down (or take a picture or whatever) and manually restore it by typing it in if I need to, that would just about solve the issue
The point is that the private key resides on a tamperproof piece of hardware. Malware, viruses, or shoulder surfers cannot copy the key. The solution is to set up multiple pieces of secure hardware, not writing down the keys to the castle on a piece of paper.
Re: Passkeys are now enabled by default for Google users
#410Earlier quoted context omitted.
There are workarounds, but that doesn't mean that passkeys is a half-baked technology. The real, simple solution would be a way to write down the passkey, similar to an SSH private key.
A main idea of passkeys is that the private keys are bound to hardware and cannot be copied. Using the private key is subject to biometric authentication. This eliminates a whole category of issues where the private key could get stolen. So no, writing down the SSH private key is not the solution. The solution is to trust multiple private keys, each stored within tamperproof hardware. This is also why, as a service p…
With a bank, if I lose paperwork, they will have a process in place for me to prove my identity. BigTech will shrug if my phone-locked passkey becomes inaccessible.