Live data from Hacker News

Passkeys are now enabled by default for Google users

blog.google

531–540 of 684 posts

Re: Passkeys are now enabled by default for Google users

#531

I might regret this but I have an (almost finished) draft of a paper on Passkeys, it is available, with comments enabled (which will be turned off if vandalism becomes a problem) at: https://docs.google.com/document/d/1eBjQDWkbqXJSL4GRrAdTUcAx... TL;DR: ============ Major insights in this paper: Passkeys level up security, and while Passkeys make some tradeoffs concerning security vs. usability, they do not introduce…

> one common strategy is via displaying a QR code

The problem with Passkeys is not that it's not possible, but that the standard is lacking any guidelines for things like this. There is no interoperability in general, it's accidental at best. And this is concerning.

Same goes for a lot of aspects that are attributed to Passkeys as "this can be solved this way", but in no way documented (in a way promoted by any major vendor), let alone standardized, let alone be required by some standard to be "Passkey-compliant".

In short, I think this can be summarized as "Passkeys lack proper standardized best practices document, encouraged by renown parties".

It is wrong to hand-wave at some specific implementation and say that because that implementation is okay, the whole standard is fine.

----

Also, you may consider adding another concern, "authenticator must be physically present to be registered". This limits ability to add new devices (which was not an issue with other systems, such as TLS client certificates).

In simple terms, one cannot add a Yubikey that lies in a safe in a secure vault under a mountain, they must have it at hand, when they're online.

This Passkeys/Webauthn limitation leads to people having significantly greater difficulty adding backup options, contributing to higher chances of getting locked out (temporarily or permanently) that it could've been, would Passkeys be designed differently.

----

Both things don't explicitly introduce any new weaknesses, compared to passwords. But the problem with Passkeys is that they're here to stay for a long while. So a push towards "you must fix this before it's too late" petitioning collective FAANG (who are the only entities that were able to push asymmetric crypto to web, no grassroots movement was able to do this - many attempts were made and all had died in oblivion) is extremely important.

Re: Passkeys are now enabled by default for Google users

#532

As others have pointed out, cryptographic authentication is very hard to bootstrap if you simply loose your device. Just last month my missus cracked the glass of her iPhone. Apple repaired it under AppleCare, which is great… except … that they didn’t tell her that the “glass repair” entails them replacing the guts of the phone and wiping it in the process. Apple iPhone backups don’t contain cryptographic secrets lik…

Completely agree. Currently I can perform a full bootstrap using information stored in my brain (with my partner's brain as backup). Any new "solution to passwords" that doesn't allow that means an instant NO from me. I don't care how much more theoretically secure it is.

Re: Passkeys are now enabled by default for Google users

#533
post #496
post #458

Earlier quoted context omitted.

Just like the rest of it, they’re going to try to lock down the open web, general-purpose computing, etc. They are going to be the gatekeepers if you and the web services let them. Oh yeah — also they’ll run all the web, email and other services anyway. Trap you in their metaverse and AI most likely, since that’s where your coworkers and friends will be you’ll have to be there too. Resist by opting out :)

I think it’s time for a government solution, but nowadays it’d be done to be benefit big tech and the surveillance state.

How about an open source one?

https://intercoin.org/overview.pdf

Re: Passkeys are now enabled by default for Google users

#534
post #201

Earlier quoted context omitted.

Passkeys are a new technology and everyone - including users, service providers, and organizations - will take time to learn and adapt. In this interim period the recommended approach is to provide passkeys as an alternative to whatever is already offered. This is the approach that Google and many other service providers are taking. That said, you are bringing up the right questions on the general topic of account re…

You should disclose your employer more consistently.

I work on Google's authentication team. I have mentioned this elsewhere in the thread.

Re: Passkeys are now enabled by default for Google users

#535
post #489

Earlier quoted context omitted.

This is just bad and uninformed advice. Adding a passkey to an account is like adding a yubikey to an account (experience wise). You can (typically) add multiple keys to your account. It's also not all or nothing. You can (in every service I've setup) still have a password and an even a TOTP.

There is no way adding multiple keys to your account is more work than a password manager. Just use a password manager and retain full control over your secrets.

Yeah I don’t really see the upside of these over just sticking with bitwarden.

Re: Passkeys are now enabled by default for Google users

#536

As others have pointed out, cryptographic authentication is very hard to bootstrap if you simply loose your device. Just last month my missus cracked the glass of her iPhone. Apple repaired it under AppleCare, which is great… except … that they didn’t tell her that the “glass repair” entails them replacing the guts of the phone and wiping it in the process. Apple iPhone backups don’t contain cryptographic secrets lik…

Passkeys follow the 3-2-1 backup rule, just like any other digital data. The main difference being that you don't need to backup the passkey itself, just have multiple passkeys.

  Have 3 passkeys
  2 of them on-person at any time (e.g. one on your phone TPM, one on a Yubikey)
  1 of them off-site (e.g. keep a backup Yubikey at home in a fireproof safe, or use a 1Password passkey, depending on your threat model)
Whenever you sign up for a new vendor/service, register all three passkeys with your account.

Re: Passkeys are now enabled by default for Google users

#537
post #262

Earlier quoted context omitted.

Password managers like Dashlane and 1Password have announced support for storing and synching passkeys. As passkeys becomes more popular I expect more providers to step up as well. Ecosystem lockin is not how we make a new technology like this successful. And all players in the game understand that.

Appreciate the response. And I wish this message was front and center. The Attestation feature is what worries me, when, say, the bank turns it on for a few 'blessed' providers, or mandate a hardware implementation. Watching https://github.com/keepassxreboot/keepassxc/issues/1870 with baited breath... :)

Your concern around attestation (mis)use is spot on. I'd say the industry is yet to arrive at an acceptable consensus or compromise on that question.

Re: Passkeys are now enabled by default for Google users

#538
post #201

Earlier quoted context omitted.

Passkeys are a new technology and everyone - including users, service providers, and organizations - will take time to learn and adapt. In this interim period the recommended approach is to provide passkeys as an alternative to whatever is already offered. This is the approach that Google and many other service providers are taking. That said, you are bringing up the right questions on the general topic of account re…

All those issues were obvious from the day zero, and raised multiple times by many people. They're deliberately ignored by the stakeholders. They strongly want to lock you in to their own authentication platforms (iCloud Keychain, Windows Hello, 1Password*), that's why they don't want to address this. It's impossible they're not aware about those issues. Anyone with a brain and some technical expertise would come up…

On account recovery, the user is strictly no worse off with passkeys relative to passwords and arguably actually better off in many cases. This is not what I'd call deliberately ignoring concerns.

Re: Passkeys are now enabled by default for Google users

#539

As others have pointed out, cryptographic authentication is very hard to bootstrap if you simply loose your device. Just last month my missus cracked the glass of her iPhone. Apple repaired it under AppleCare, which is great… except … that they didn’t tell her that the “glass repair” entails them replacing the guts of the phone and wiping it in the process. Apple iPhone backups don’t contain cryptographic secrets lik…

Passkeys follow the 3-2-1 backup rule, just like any other digital data. The main difference being that you don't need to backup the passkey itself, just have multiple passkeys. Have 3 passkeys 2 of them on-person at any time (e.g. one on your phone TPM, one on a Yubikey) 1 of them off-site (e.g. keep a backup Yubikey at home in a fireproof safe, or use a 1Password passkey, depending on your threat model) Whenever yo…

... or just store a password in your password manager.

I thought passkeys were supposed to be convenient to use.

Re: Passkeys are now enabled by default for Google users

#540

As others have pointed out, cryptographic authentication is very hard to bootstrap if you simply loose your device. Just last month my missus cracked the glass of her iPhone. Apple repaired it under AppleCare, which is great… except … that they didn’t tell her that the “glass repair” entails them replacing the guts of the phone and wiping it in the process. Apple iPhone backups don’t contain cryptographic secrets lik…

Passkeys follow the 3-2-1 backup rule, just like any other digital data. The main difference being that you don't need to backup the passkey itself, just have multiple passkeys. Have 3 passkeys 2 of them on-person at any time (e.g. one on your phone TPM, one on a Yubikey) 1 of them off-site (e.g. keep a backup Yubikey at home in a fireproof safe, or use a 1Password passkey, depending on your threat model) Whenever yo…

I do follow this. Unfortunately, it leaves out one glaring flaw: you can’t register a Passkey you don’t physically have.

I use four: an Apple Passkey, a YubiKey I keep on me, a YubiKey at home, and a YubiKey in the bank. When I sign up for a service, I need to register all four of them. Not only is this generally a bit of a pain in the ass, but it also means I have to remember to go fetch the one in the bank vault periodically and update the credentials.

If I could save a stub locally that would let me register with a key not in my physical presence, that would go a long way to making this more usable. Even better would be the ability to register a bundle of them all in one go without having to do it four separate times.

As it stands right now, it’s hard to recommend to users who don’t understand or care enough to take all of these steps. Which to be clear is entirely reasonable on their part. It’s an unacceptable amount of work and mental accounting for it to be something the average person can do without high risk of losing their entire digital identity.

Post reply on HN