Live data from Hacker News

Passkeys are now enabled by default for Google users

blog.google

491–500 of 684 posts

Re: Passkeys are now enabled by default for Google users

#491
post #417

Earlier quoted context omitted.

Now extend that; it's not you trying to recover access, it's your relatives or heirs trying to do so, because you are incapacitated or dead.

Legacy contact https://support.apple.com/en-gb/HT212360 Account recovery contact https://support.apple.com/en-gb/HT212513

Can't add those after the fact.

Re: Passkeys are now enabled by default for Google users

#492
post #347

Earlier quoted context omitted.

How does that work if you can register multiple different keys using different devices from different vendors on an account? Edit: I took the last sentence out, it was childish on my part.

What are the vendor options though? (I think) its Google, Apple, Microsoft, Yubico and 1password? None of which support exporting the keys as per other comments in this thread. Also (i think) none of them are open source?

1password publishes their implementation: https://github.com/1Password/passkey-rs

Re: Passkeys are now enabled by default for Google users

#493
post #419

Earlier quoted context omitted.

Great so now people need to be rich enough to own multiple phones? Really. The solution can’t be “buy multiple devices” when the average person can barely afford to maintain one working device.

Your computer can also be a passkey. I currently use both my laptop and my computer as a passkey, and a USB drive. So I have 3 backups to my Google account. It is true that you do need to be rich enough to own a phone and ~100 USD of something else (laptop or USB), which does put redundancy out of the reach of a large portion of the world. But then they can just use regular 2fa at the expense of not being phishing-pr…

Yes, but in order to add new items to each piece of hardware you have to be physically co-located with all the pieces of hardware you want to use as your backups. Which means they cannot be geographically distributed (or if they are that there is a period of time in which you aren't fully backed up). Which means you're either in a place where you can loose all your keys (e. g. a house fire or a flood) or your in a place where you can loose all the devices that have a key.

Re: Passkeys are now enabled by default for Google users

#494
post #432

As others have pointed out, cryptographic authentication is very hard to bootstrap if you simply loose your device. Just last month my missus cracked the glass of her iPhone. Apple repaired it under AppleCare, which is great… except … that they didn’t tell her that the “glass repair” entails them replacing the guts of the phone and wiping it in the process. Apple iPhone backups don’t contain cryptographic secrets lik…

> Run away screaming. Don’t believe the hype. Wait until the vendors get their act together and come up with a solution for transfer and recovery. Very much this. Having authentication tied to hardware you don't control is a near-certain denial of service in the future. People love to hate on passwords but the reality is that for many circumstances (threat models) they are the best compromise. You can make them more…

> Very much this. Having authentication tied to hardware you don't control is a near-certain denial of service in the future.

Then you can tie it to hardware you do control, or to software.

Obligatory "Passkeys misconceptions" article: https://www.stavros.io/posts/clearing-up-some-passkeys-misco...

Re: Passkeys are now enabled by default for Google users

#495

Earlier quoted context omitted.

A main idea of passkeys is that the private keys are bound to hardware and cannot be copied. Using the private key is subject to biometric authentication. This eliminates a whole category of issues where the private key could get stolen. So no, writing down the SSH private key is not the solution. The solution is to trust multiple private keys, each stored within tamperproof hardware. This is also why, as a service p…

> This is also why, as a service provider, I'd like to see some device attestation. I want to know that the keys being used here are not written on a fucking piece of paper. This is precisely why user should run away. Service provider is moving liability to end user and washing their hand away, while user gets screwed if anything happens during vacation.

End user also gets screwed when they are phished for their paper key. And I'm not sure about liability, unless you consider the requirement to check haveibeenpwned once a week for a breach to be no one's responsibility.

Re: Passkeys are now enabled by default for Google users

#496
post #458
post #432

Earlier quoted context omitted.

> Run away screaming. Don’t believe the hype. Wait until the vendors get their act together and come up with a solution for transfer and recovery. Very much this. Having authentication tied to hardware you don't control is a near-certain denial of service in the future. People love to hate on passwords but the reality is that for many circumstances (threat models) they are the best compromise. You can make them more…

Just like the rest of it, they’re going to try to lock down the open web, general-purpose computing, etc. They are going to be the gatekeepers if you and the web services let them. Oh yeah — also they’ll run all the web, email and other services anyway. Trap you in their metaverse and AI most likely, since that’s where your coworkers and friends will be you’ll have to be there too. Resist by opting out :)

I think it’s time for a government solution, but nowadays it’d be done to be benefit big tech and the surveillance state.

Re: Passkeys are now enabled by default for Google users

#497

Earlier quoted context omitted.

Honestly, if they'd just give me the option to write it down (or take a picture or whatever) and manually restore it by typing it in if I need to, that would just about solve the issue

I like this idea of authenticating yourself by typing things in.

But how can i be sure it’s really you? How can i track you that way?

Re: Passkeys are now enabled by default for Google users

#498
post #201

Earlier quoted context omitted.

Passkeys are a new technology and everyone - including users, service providers, and organizations - will take time to learn and adapt. In this interim period the recommended approach is to provide passkeys as an alternative to whatever is already offered. This is the approach that Google and many other service providers are taking. That said, you are bringing up the right questions on the general topic of account re…

How can a user, right now, take control + ownership of backing up their own pass keys, without iCloud or Google? This is a privilege I currently enjoy right now, and one I am not really eager to give up.

I've got security keys on Yubikeys, Android devices, and Windows devices. Only one of these are Google.

Re: Passkeys are now enabled by default for Google users

#499

As others have pointed out, cryptographic authentication is very hard to bootstrap if you simply loose your device. Just last month my missus cracked the glass of her iPhone. Apple repaired it under AppleCare, which is great… except … that they didn’t tell her that the “glass repair” entails them replacing the guts of the phone and wiping it in the process. Apple iPhone backups don’t contain cryptographic secrets lik…

To save people from reading the article before running away screaming:

> But while they’re a big step forward, we know that new technologies take time to catch on — so passwords may be around for a little while. That's why people will still be given the option to use a password to sign in and may opt-out of passkeys by turning off “Skip password when possible.”

So, soon passwords will be added to “Killed by Google,” along with my account. (I keep zero devices logged in.)

It’s well past time to migrate off my few remaining use cases. I wonder if my employer will be able to reset my corporate account passkeys when the inevitable happens.

Re: Passkeys are now enabled by default for Google users

#500

As others have pointed out, cryptographic authentication is very hard to bootstrap if you simply loose your device. Just last month my missus cracked the glass of her iPhone. Apple repaired it under AppleCare, which is great… except … that they didn’t tell her that the “glass repair” entails them replacing the guts of the phone and wiping it in the process. Apple iPhone backups don’t contain cryptographic secrets lik…

As an aside, I bought a hardware TOTP token that I could have access to if i got locked out Bitwarden/Authy: https://www.amazon.com/gp/product/B07RQPJNZH

It would be awesome to have an "emergency" server where I could type in the URL, decrypt it with my passphrase and OTP, and get access to everything I need temporarily so I can re-bootstrap all my stuff. Of course, this doesn't solve the problem of SMS 2fa being used for everything, but it's a good first step.

I am in favor of crossplatform solutions like YubiKey. Apple and Google passkeys are lame.

Post reply on HN