Live data from Hacker News

Passkeys are now enabled by default for Google users

blog.google

551–560 of 684 posts

Re: Passkeys are now enabled by default for Google users

#551

Earlier quoted context omitted.

That article is about as misleading as it's possible to be while still being technically right. The "attestation" feature of passkeys exists solely to let websites refuse to let you use passkeys tied to hardware you do control, or to software. The way this article only mentions it in passing and tries to downplay it reminds me of the joke of https://what-if.xkcd.com/49/ - a very long article listing a bunch of upside…

I guess we'll have to wait and see whether websites will force people to use specific authenticators. I don't think they will.

We can already see this to some degree. On my Android device, Chrome will only let me create a synchronized passkey in a Google account UNLESS attachment is explicitly set to "cross-plattform" - even though not specifying the option is supposed to allow all types.

You can try this out on webauthn.io and changing the attachment setting.

Re: Passkeys are now enabled by default for Google users

#552

Earlier quoted context omitted.

How does this address OP's concern? If you have a single device (e.g. an iPhone) and you store all your passkeys on it, then losing it means you lost all passkeys. Your post describes exactly that: - "I can’t recover the keys if I lose the hardware" - "That is a risk you’ll need to take if you’re using hardware authenticators" Fantasizing that with this proposed simplification of the authentication process people wil…

I haven't heard anyone claim that passkeys are simpler than passwords, as that would be trivially false. The claim is that they're more secure while still remaining fairly usable. Passkeys are WebAuthn credentials that are synced between devices, so they aren't hardware keys, they're software keys.

> more secure

"more secure" is a completely meaningless statement, I wish this usage would die already (in general).

You need to talk about security in the face of a very specific threat, then you can say solution A is better than solution B against threat T1, worse for T2 and about a wash for T3 and so on.

Security is not a linear scale from 0-100 where you can say "more secure". There are many different criteria and any given solution will be better in some, worse in others. You must do a threat model for your specific use case to say if something is better or worse for those specific threats, and keep in mind other people will have very different threat models for the same solution.

Re: Passkeys are now enabled by default for Google users

#553

Earlier quoted context omitted.

Why does this article claim that attestation is unlikely? We know Google loves the idea - see Web Environment Integrity (WEI). Also, what's stopping us from falling into the passkey version of the world we got with OpenID, where many services force you to log in with your BigTech account?

> Why does this article claim that attestation is unlikely? Facebook is still going to want me on their websites even if I’m running Firefox. Most websites people visit will not do any chrome WEI attestation. Likely exceptions are sites which handle any legal, financial, or health-related data. Not credit cards. I doubt most Google properties will use WEI. They still want to slurp up all my juicy Firefox usage data a…

I'm willing to bet otherwise (w.r.t. your first statement). They probably consider the sliver of such users expendable. They probably also (rightly) assume that a significant percentage of that sliver will continue using their service (e.g. via sanctioned Chrome on sanctioned hardware) if push comes to shove.

Or at least they will at some point in the near future.

Re: Passkeys are now enabled by default for Google users

#554

While I believe this is a step in the right direction. I have read too many horror stories of people who were locked out of their Google and iCloud accounts with no real possibility of getting back in. I don’t think I am alone in thinking I am on borrowed time. Someday, probably due to my own fault I will be locked out of Google and my digital life will be over. If a private company can offer a similar login method l…

Disaster recovery. This is 100% my biggest worry with 2FA/MFA. I also think this is one of the reasons stuff like PGP never took off (don't @ me regarding perfect forward secrecy): the problem has always been managing some little, precious thing and the ramifications of what happens if it put beyond use or is used by some bad actor.

1Password makes it pretty easy- both the OTPs and the backup codes can be synced to your account on the web and on all your devices.

Re: Passkeys are now enabled by default for Google users

#555

As others have pointed out, cryptographic authentication is very hard to bootstrap if you simply loose your device. Just last month my missus cracked the glass of her iPhone. Apple repaired it under AppleCare, which is great… except … that they didn’t tell her that the “glass repair” entails them replacing the guts of the phone and wiping it in the process. Apple iPhone backups don’t contain cryptographic secrets lik…

> Passkeys are not cross-vendor transferable!

They are when using a third party password manager like 1password or dashlane. At least in they are device agnostic. Haven‘t yet tried to export a passkey to another manager.

Re: Passkeys are now enabled by default for Google users

#556

As others have pointed out, cryptographic authentication is very hard to bootstrap if you simply loose your device. Just last month my missus cracked the glass of her iPhone. Apple repaired it under AppleCare, which is great… except … that they didn’t tell her that the “glass repair” entails them replacing the guts of the phone and wiping it in the process. Apple iPhone backups don’t contain cryptographic secrets lik…

My understanding is that Passkeys are transferrable, unlike earlier efforts. See for example this iOS help page: https://support.apple.com/guide/iphone/passkeys-passwords-de... Unless you store the passkey in a hardware Fido key like a Yubikey. Then the way to transfer it is to physically carry the key and plug it to another device.

OP specifically mentions "cross-vendor" transferable. Which, to my understanding, is currently true.

Re: Passkeys are now enabled by default for Google users

#557
post #518

Earlier quoted context omitted.

Thieves can steal a car using tech magic. That is also true about access to accounts. That contradicts your comment. Biometrics, if stolen, can be used to access any of accounts if one obtains knowledge about how to use it for hacking. Your comment violates HN guidelines, but as guideline says I assume good faith therefore I have provided details about how you're incorrect on that one.

A passkey does not contain and is not derived from biometric data, so one cannot login to an account using biometric data alone. If one wanted to use biometric data to access a Google Account secured with a passkey, one would: 1. Need to find a device with that passkey on it (or an account like iCloud Keychain or 1Password that contains the synced passkey). Biometric data could be used to unlock the iPhone, in theory…

It does not have to be a thug who makes your picture.

Titanic has crashed. Microsoft has been hacked. There are no solutions that do not contain bugs. There are no drivers for sensors that cannot be hacked.

Sure hacking a device is difficult, sure. Maybe nearly impossible, but I doubt it. All software has bugs. Some even backdoors. Some data are centralized and kept on big tech cloud storage which is a honey pot for hackers. Once hacker has biometrics data on your phone captured, it could be used. Not only to obtain your passkeys, but outside of your phone.

A simple google search confirms that. There was a biometric data breach. Sure this might not be the best result, but I spend 2 seconds searching for it. Quite generic article, but I think it is sufficient.

https://www.secureworld.io/industry-news/biometric-data-brea...

Quotes

"Facial recognition and fingerprint information cannot be changed. Once they are stolen, it can't be undone."

"Putting all the data found in the leak together, criminals of all kinds could use this information for varied illegal and dangerous activities."

Keychain, iCloud, 1Password... These are just details.

Re: Passkeys are now enabled by default for Google users

#558
post #266

Earlier quoted context omitted.

How can a user, right now, take control + ownership of backing up their own pass keys, without iCloud or Google? This is a privilege I currently enjoy right now, and one I am not really eager to give up.

It depends on your web browser. Just see what happens here https://webauthn.io/ Firefox on Desktop tells me to "touch my security key". Not sure how that works. Firefox Android gives me a few hardware options to store my passkey to. Chrome Desktop asks me to enable Bluetooth. Chrome Android asks which Google Account to use.

Just tried that with Firefox on Android and while it works, I can't find any evidence of a stored passkey on my device, let alone a way to export it.

Re: Passkeys are now enabled by default for Google users

#559

Earlier quoted context omitted.

> What is the account recovery process if I’m locked out and don’t have my phone, say it’s lost or broken and I can’t verify my identity? > You can always fall back to legacy authentication options such as passwords and traditional 2-step-verification. In a case where you can no longer remember your password, you can also go through Google’s Account recovery flow. We encourage you to add your email and phone number t…

Then what's the point of it all if a hacker can still get into my account using the traditional methods? This seems to be just opening up another avenue of attack.

You can read more about the security properties of passkeys on your Google account on this post from earlier this year when support was originally announced: https://security.googleblog.com/2023/05/so-long-passwords-th...

Re: Passkeys are now enabled by default for Google users

#560
post #418

Earlier quoted context omitted.

>So they aren't considering at all how easy is the autofill password feature with a password manager Passwords are a nightmare for both users and service providers for a variety of reasons. And password autofill is a bandaid at best . If I had a quarter for the number of times I've personally used a password manager to auto generate a password which was then either reject by the website due to absurd password complex…

You're comparing a crappy password filter with an optimally implemented passkey thing, though. If the world's up for improving over status quo by rewriting all login prompts, the comparable options would be making password managers/autofill/autogenerated passwords work well everywhere (which'd be just some light tweaks here and there), or making passkeys work well everywhere (which is an entire new thing, and people…

I’m not cherry-picking, I’m comparing the actual real-world experience of using password autofill vs. using a passkey.

The significantly better passkey sign-in UX that I’m talking about exists on all major platforms. And the UX is handled by browser and operating system APIs, so it’s not really something the app or website can mess up.

Also, any solution that still involves password-based login prompts would be worse than passkeys because passwords are still shared secrets, and password hashes would remain juicy targets for attackers in server breaches.

Post reply on HN