Live data from Hacker News

Passkeys are now enabled by default for Google users

blog.google

451–460 of 684 posts

Re: Passkeys are now enabled by default for Google users

#451
post #327

Earlier quoted context omitted.

AFAICT, the flaw is that passkeys are tied to device security. If I steal a naive person’s phone at the bar, and if I can guess that their PIN is 1234, then I can get into their Google account. The criticism is based on the idea that most non-techie folks are unlikely to use a strong PIN and are unlikely to set up strong biometrics. There’s a related criticism about malware being able to steal passkeys on PC-based sy…

Won’t most people be logged into their Google account anyways? So if you steal their phone, and guess their PIN then you can just use the already logged in account. What does this change?

Certain account changing actions cannot be completed without the password. But if you have the phone (session, sms, passkey), you can reset the password and it's off to the races.

Re: Passkeys are now enabled by default for Google users

#452

As others have pointed out, cryptographic authentication is very hard to bootstrap if you simply loose your device. Just last month my missus cracked the glass of her iPhone. Apple repaired it under AppleCare, which is great… except … that they didn’t tell her that the “glass repair” entails them replacing the guts of the phone and wiping it in the process. Apple iPhone backups don’t contain cryptographic secrets lik…

Honestly, if they'd just give me the option to write it down (or take a picture or whatever) and manually restore it by typing it in if I need to, that would just about solve the issue

Google has backup codes for this purpose.

Re: Passkeys are now enabled by default for Google users

#453

Earlier quoted context omitted.

"You might get locked out of your account" is the updated version of the old "Your hard drive will crash." It isn't a matter of if, it's just a matter of when. Backups and a thorough disaster recovery plan is absolutely mandatory for anyone who cares about their data. Some company is going to mess something up due to no fault of your own. It is inevitable. Unfortunately, there aren't good disaster recovery options fo…

My thought on this is to involve notaries. As in you can get a notorised account. And if something goes wrong you can get a notary in the loop and by law the providers have to fix what ever has gone wrong or they are liable for actual and statutory damages.

100% agreed. It's the analog reason notaries even exist.

Re: Passkeys are now enabled by default for Google users

#454
post #13

As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?

> What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?

Easy: you will never log in to google again. Since google has zero reachable support, that's the end of your account.

This works better with something like a credit union where as a last resort just can just walk in there in person with IDs and restore access.

But with these internet giant companies which take pride in not having any reachable support ever? Nope, nope and no.

Re: Passkeys are now enabled by default for Google users

#455

Earlier quoted context omitted.

The point is that the private key resides on a tamperproof piece of hardware. Malware, viruses, or shoulder surfers cannot copy the key. The solution is to set up multiple pieces of secure hardware, not writing down the keys to the castle on a piece of paper.

Great so now people need to be rich enough to own multiple phones? Really. The solution can’t be “buy multiple devices” when the average person can barely afford to maintain one working device.

[dead]

Re: Passkeys are now enabled by default for Google users

#456
post #423

Earlier quoted context omitted.

The point is that the phone with a crappy 4 digit pin can be used to authenticate everything on every device the user owns that uses passkeys. It's a one stop shop of failure.

Phones are already that way. They have text messages and email which is enough to log into almost any service.

Yes, that's also bad. They're both bad. Passkeys are worse.

Re: Passkeys are now enabled by default for Google users

#457

Earlier quoted context omitted.

Honestly, if they'd just give me the option to write it down (or take a picture or whatever) and manually restore it by typing it in if I need to, that would just about solve the issue

The point is that the private key resides on a tamperproof piece of hardware. Malware, viruses, or shoulder surfers cannot copy the key. The solution is to set up multiple pieces of secure hardware, not writing down the keys to the castle on a piece of paper.

I'm much more concerned about my access being tied to physical hardware than I am about "malware".

Re: Passkeys are now enabled by default for Google users

#458
post #432

As others have pointed out, cryptographic authentication is very hard to bootstrap if you simply loose your device. Just last month my missus cracked the glass of her iPhone. Apple repaired it under AppleCare, which is great… except … that they didn’t tell her that the “glass repair” entails them replacing the guts of the phone and wiping it in the process. Apple iPhone backups don’t contain cryptographic secrets lik…

> Run away screaming. Don’t believe the hype. Wait until the vendors get their act together and come up with a solution for transfer and recovery. Very much this. Having authentication tied to hardware you don't control is a near-certain denial of service in the future. People love to hate on passwords but the reality is that for many circumstances (threat models) they are the best compromise. You can make them more…

Just like the rest of it, they’re going to try to lock down the open web, general-purpose computing, etc.

They are going to be the gatekeepers if you and the web services let them. Oh yeah — also they’ll run all the web, email and other services anyway. Trap you in their metaverse and AI most likely, since that’s where your coworkers and friends will be you’ll have to be there too.

Resist by opting out :)

Re: Passkeys are now enabled by default for Google users

#459
post #306

Earlier quoted context omitted.

Just happened to my in-law. She dropped her phone on the stairs, screen cracked, and became unresponsive. I gave her an older phone I had and swapped the sim fine. But she couldn't figure out how to log in to Google account because it was so adamant telling her to use her phone. Her laptop was logged out of her email, etc. Fortunately I have backup tokens for her from a previous incident heh. I have no idea what othe…

A few months ago Google wouldn't even accept backup tokens for me. I was on vacation, and that tripped enough fraud detectors to cause problems. I couldn't log back in till I got on my home network and changed my password.

Back in the old days with no 2FA and only username/password access geolocation lockouts happened every time I went travelling. You could regain access by getting a code from a recovery email, but that often got locked out as well!

Eventually I set up my own VPN server so that the services still thought I was using my home IP.

Post reply on HN