Live data from Hacker News

Passkeys are now enabled by default for Google users

blog.google

411–420 of 684 posts

Re: Passkeys are now enabled by default for Google users

#411
post #364

As others have pointed out, cryptographic authentication is very hard to bootstrap if you simply loose your device. Just last month my missus cracked the glass of her iPhone. Apple repaired it under AppleCare, which is great… except … that they didn’t tell her that the “glass repair” entails them replacing the guts of the phone and wiping it in the process. Apple iPhone backups don’t contain cryptographic secrets lik…

> Run away screaming. Don’t believe the hype. Wait until the vendors get their act together and come up with a solution for transfer and recovery. I believe all of the issues you've described, but you can usually add multiple passkeys to each service. There is nothing stopping you from adding your iPhone and a cheap android phone and having redundancy, or using 1Password and storing your passkey in there. iPhone back…

> I believe all of the issues you've described, but you can usually add multiple passkeys to each service.

How does this work? Do I have to visit the website of each service from my secondary device for it to get the alternate passkey?

Re: Passkeys are now enabled by default for Google users

#412
post #44

Earlier quoted context omitted.

Ah right, account recovery. The one that tells me the only way to sign in to my old Google account is to use a phone that no longer exists.

What’s the standard then? Should it be possible to recover your account without possessing any evidence whatsoever that you are the person you say you are?

Given your response you should read up on the reality of Google Account recovery, because the usual horror story is not that you have "no evidence whatsoever" but more like "I have all the evidence in the world including recovery codes, TOTP backups and a valid password and somehow I'm still locked out".

Re: Passkeys are now enabled by default for Google users

#413
post #201
post #13

As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?

Passkeys are a new technology and everyone - including users, service providers, and organizations - will take time to learn and adapt. In this interim period the recommended approach is to provide passkeys as an alternative to whatever is already offered. This is the approach that Google and many other service providers are taking. That said, you are bringing up the right questions on the general topic of account re…

You should disclose your employer more consistently.

Re: Passkeys are now enabled by default for Google users

#414
post #327
post #321

Earlier quoted context omitted.

What is the flaw?

AFAICT, the flaw is that passkeys are tied to device security. If I steal a naive person’s phone at the bar, and if I can guess that their PIN is 1234, then I can get into their Google account. The criticism is based on the idea that most non-techie folks are unlikely to use a strong PIN and are unlikely to set up strong biometrics. There’s a related criticism about malware being able to steal passkeys on PC-based sy…

Most people have _extremely_ weak device security. 0000, 1234, DDMM of their birthdate, etc, you probably cover the majority of people.

And none of that helps you when someone robs you of your phone and says tell them your unlock code or they’ll stab you. Now they’ve got all your passkeys too.

Re: Passkeys are now enabled by default for Google users

#415

1Password enabled PassKey support recently and I was "surprised" to learn that there is no way of exporting them out of 1Password. They're not included in the 1PUX format export, nor in the CSV. That means that they're literally impossible to back up. If 1Password goes down, or the company stops operating, or anything else like that, your Passkeys are just... gone. Absolutely no way to recover them.

1Password's Passkey support feels very aggressively growth-hacky to me. They intercept calls to `window.credentials` and if you want to use 1Password along side other verifiers like Yubikey, you need to go into your settings and disable their passkeys offering entirely. It's similar to how they also intercept (and globally disable!) Google One Tap prompts in order to show their own OAuth prompt. I only use their Chro…

I'm kind of mad at 1Password - but this isn't correct. When the 1Password prompt some up, you can click the little "USB key" icon which ostensibly is for hardware keys, but all it does is pass control back to the OS, at which point your iCloud prompt, or whatever provider you are using, can be used.

Re: Passkeys are now enabled by default for Google users

#416

>To use passkeys, you just use a fingerprint, face scan or pin to unlock your device, and they are 40% faster than passwords >We’ve found that one of the most immediate benefits of passkeys is that they spare people the headache of remembering all those numbers and special characters in passwords. So they aren't considering at all how easy is the autofill password feature with a password manager (that they even have…

>So they aren't considering at all how easy is the autofill password feature with a password manager Passwords are a nightmare for both users and service providers for a variety of reasons. And password autofill is a bandaid at best . If I had a quarter for the number of times I've personally used a password manager to auto generate a password which was then either reject by the website due to absurd password complex…

In practice the actually concerning use case is not creating a key or using it, but safeguarding it and recovering it.

Re: Passkeys are now enabled by default for Google users

#417

No one has managed yet to explain to me how you recover access to an account using these passkeys if you somehow lose access to all your devices. Note that i said "all your devices" so the cloud backup you dream of will also be inaccessible because I can't authenticate to that either. And I know about backups... what about your average user who is likely to own a single phone and no other device? They lose access to…

Now extend that; it's not you trying to recover access, it's your relatives or heirs trying to do so, because you are incapacitated or dead.

Legacy contact

https://support.apple.com/en-gb/HT212360

Account recovery contact

https://support.apple.com/en-gb/HT212513

Re: Passkeys are now enabled by default for Google users

#418

>To use passkeys, you just use a fingerprint, face scan or pin to unlock your device, and they are 40% faster than passwords >We’ve found that one of the most immediate benefits of passkeys is that they spare people the headache of remembering all those numbers and special characters in passwords. So they aren't considering at all how easy is the autofill password feature with a password manager (that they even have…

>So they aren't considering at all how easy is the autofill password feature with a password manager Passwords are a nightmare for both users and service providers for a variety of reasons. And password autofill is a bandaid at best . If I had a quarter for the number of times I've personally used a password manager to auto generate a password which was then either reject by the website due to absurd password complex…

You're comparing a crappy password filter with an optimally implemented passkey thing, though. If the world's up for improving over status quo by rewriting all login prompts, the comparable options would be making password managers/autofill/autogenerated passwords work well everywhere (which'd be just some light tweaks here and there), or making passkeys work well everywhere (which is an entire new thing, and people would still need to deal with passwords because there's no way that they're disappearing in less than a couple decades).

Passkeys might (or might not) have other benefits, but ease of use is entirely a question of cherry-picking.

Re: Passkeys are now enabled by default for Google users

#419

Earlier quoted context omitted.

The point is that the private key resides on a tamperproof piece of hardware. Malware, viruses, or shoulder surfers cannot copy the key. The solution is to set up multiple pieces of secure hardware, not writing down the keys to the castle on a piece of paper.

Great so now people need to be rich enough to own multiple phones? Really. The solution can’t be “buy multiple devices” when the average person can barely afford to maintain one working device.

Your computer can also be a passkey. I currently use both my laptop and my computer as a passkey, and a USB drive. So I have 3 backups to my Google account.

It is true that you do need to be rich enough to own a phone and ~100 USD of something else (laptop or USB), which does put redundancy out of the reach of a large portion of the world. But then they can just use regular 2fa at the expense of not being phishing-proof.

Re: Passkeys are now enabled by default for Google users

#420
post #243

Earlier quoted context omitted.

Other businesses have humans on staff which will verify your identity documents. Google simply chooses not to do this, because it is expensive, and their "users" are not their customers.

That is not without risk either: Many more people have a copy of my passport than have access to my Yubikey or recovery phone number.

Yes, remotely accepting a copy of an identity document from the other end of a wire is not a good authentication method. That's because they're not intended for remote digital authentication. Photo IDs are intended to be validated in-person, using the original document, and the photo visually compared to the person holding it.
Post reply on HN