Live data from Hacker News

Passkeys are now enabled by default for Google users

blog.google

421–430 of 684 posts

Re: Passkeys are now enabled by default for Google users

#421
post #327

Earlier quoted context omitted.

AFAICT, the flaw is that passkeys are tied to device security. If I steal a naive person’s phone at the bar, and if I can guess that their PIN is 1234, then I can get into their Google account. The criticism is based on the idea that most non-techie folks are unlikely to use a strong PIN and are unlikely to set up strong biometrics. There’s a related criticism about malware being able to steal passkeys on PC-based sy…

Most people have _extremely_ weak device security. 0000, 1234, DDMM of their birthdate, etc, you probably cover the majority of people. And none of that helps you when someone robs you of your phone and says tell them your unlock code or they’ll stab you. Now they’ve got all your passkeys too.

They also have your phone so they have text messages, email access, Google auth access, etc.

So yes it is true that your phone and it's pin/biometrics are ultimately the most important thing for security. But passkey on your phone is no worse than the previous state.

Re: Passkeys are now enabled by default for Google users

#422

Earlier quoted context omitted.

What are the odds that someone with a passcode 1234 is 1/ already signed into Google on their phone or 2/ has their Google password already saved in the device password manager (since it asks you to save it every time you sign in) which is also protected by the device pin? At least in this case the thief has to steal the physical phone instead of guessing "password123" on the google signin prompt from the comfort of…

> What are the odds that someone with a passcode 1234 is 1/ already signed into Google on their phone ...very high? I don't understand how this is unlikely, pretty much every phone owner with a google account is signed into that account on their phone.

Exactly. So they already have access to your email, passwords, and text messages regardless of the passkey

Re: Passkeys are now enabled by default for Google users

#423

Earlier quoted context omitted.

It seems like his argument is that putting access to valuable accounts on your phone is a bad practice, because if your phone is stolen at the club after the thief watched you enter your code, then the thief can get at your banking, brokerage, crypto, password manager, etc. But that argument doesn't address how passkeys somehow make that worse. Sure, if you don't want your valuable stuff stolen, don't put it on your…

The point is that the phone with a crappy 4 digit pin can be used to authenticate everything on every device the user owns that uses passkeys. It's a one stop shop of failure.

Phones are already that way. They have text messages and email which is enough to log into almost any service.

Re: Passkeys are now enabled by default for Google users

#424

As others have pointed out, cryptographic authentication is very hard to bootstrap if you simply loose your device. Just last month my missus cracked the glass of her iPhone. Apple repaired it under AppleCare, which is great… except … that they didn’t tell her that the “glass repair” entails them replacing the guts of the phone and wiping it in the process. Apple iPhone backups don’t contain cryptographic secrets lik…

[deleted]

Re: Passkeys are now enabled by default for Google users

#425
post #364

Earlier quoted context omitted.

> Run away screaming. Don’t believe the hype. Wait until the vendors get their act together and come up with a solution for transfer and recovery. I believe all of the issues you've described, but you can usually add multiple passkeys to each service. There is nothing stopping you from adding your iPhone and a cheap android phone and having redundancy, or using 1Password and storing your passkey in there. iPhone back…

There are workarounds, but that doesn't mean that passkeys is a half-baked technology. The real, simple solution would be a way to write down the passkey, similar to an SSH private key.

> The real, simple solution would be a way to write down the passkey, similar to an SSH private key.

Except shorter for convenience. Something you could even memorize.

Re: Passkeys are now enabled by default for Google users

#426
post #273

Earlier quoted context omitted.

Passkeys represent the cumulative wisdom and experience (and compromises!) of the whole industry on how to keep users safe online. Appreciate your opinions that these efforts are doomed. It is safe to say, "We'll surely find out!"

> Passkeys represent the cumulative wisdom and experience (and compromises!) of the whole industry on how to keep users safe online. That is true _if_ you do not highly weigh all the concerns that have been brought up in this thread today. I do not trust Google to help if things go wrong so why would I ever consider such a system wise? Frankly, you seem to be ignoring concerns if they contradict your belief that this…

Did you see they worked for Google? Or did you guess correctly?[1]

[1] https://news.ycombinator.com/item?id=37833206

Re: Passkeys are now enabled by default for Google users

#427
post #222

This may cause me to "up"grade to 1Password 8, which I have been dreading.

Be aware what you're getting into: https://news.ycombinator.com/item?id=37836783

Beware of spreading FUD. Password managers like 1Password sync the data locally. If they are offline, for whatever reason, you can still access the passwords locally. You can easily test this by disabling networking on your device and accessing your data in the 1Password apps.

Re: Passkeys are now enabled by default for Google users

#428
post #314

Earlier quoted context omitted.

How? The usage was very easy. You select a contact and add them as your recovery contact (by selecting contact from your contact list) The system adds the key in the background. If they don't have the app, the app asks you to tell them to install the app (viral growth?). The users didn't need to know any thing technical. But install app, and click yes/no like they do with a 2FA app.

I think the challenge is more coordinating the 8 people who will be a trusted part of your life long-term. Also they’d have to be sure to keep their fragments of the key intact through replacing devices, etc, no? Seems like just keeping a Yubikey in a safe deposit box would be simpler.

if they replaced their device, their new device would still preserve your key, just like you replacing your device keeps your key.

Re: Passkeys are now enabled by default for Google users

#429

Earlier quoted context omitted.

How can a user, right now, take control + ownership of backing up their own pass keys, without iCloud or Google? This is a privilege I currently enjoy right now, and one I am not really eager to give up.

I use 1Password [0] for syncing passkeys, and it works quite well. I would imagine other password managers are building similar features. [0]: https://support.1password.com/save-use-passkeys/

1Password does not give control and ownership.[1]

[1] https://news.ycombinator.com/item?id=37836783

Re: Passkeys are now enabled by default for Google users

#430
post #262

Earlier quoted context omitted.

How can a user, right now, take control + ownership of backing up their own pass keys, without iCloud or Google? This is a privilege I currently enjoy right now, and one I am not really eager to give up.

Password managers like Dashlane and 1Password have announced support for storing and synching passkeys. As passkeys becomes more popular I expect more providers to step up as well. Ecosystem lockin is not how we make a new technology like this successful. And all players in the game understand that.

1Password does not give control and ownership.[1]

[1] https://news.ycombinator.com/item?id=37836783

Post reply on HN