Live data from Hacker News

Passkeys are now enabled by default for Google users

blog.google

591–600 of 684 posts

Re: Passkeys are now enabled by default for Google users

#591

As others have pointed out, cryptographic authentication is very hard to bootstrap if you simply loose your device. Just last month my missus cracked the glass of her iPhone. Apple repaired it under AppleCare, which is great… except … that they didn’t tell her that the “glass repair” entails them replacing the guts of the phone and wiping it in the process. Apple iPhone backups don’t contain cryptographic secrets lik…

Completely agree. Currently I can perform a full bootstrap using information stored in my brain (with my partner's brain as backup). Any new "solution to passwords" that doesn't allow that means an instant NO from me. I don't care how much more theoretically secure it is.

It isn't more secure if you use a secure password with the standard way of auth today. Especially not theoretically what relates to cryptography.

Some common attack vectors like phishing would be more secure since you more or less automatically generate different credentials for different services, just as you get different access tokens from your oauth service. Token theft is an issue too, but only ever partially compromises you for a limited time.

Re: Passkeys are now enabled by default for Google users

#592
There's one elephant in the room I'm not hearing enough about, namely the legal precedent (at least in the U.S.) that you can legally be compelled to provide a biometric identifier (fingerprint, face scan, etc.), but cannot be compelled to provide a password, as that would be "compelled speech" and violate the first amendment.

I disable all kinds of biometrics from my devices when traveling for this reason specifically. Passwords in my password manager aren't the whole password. There's another component in my head that I won't (and, more importantly, cannot be compelled to) disclose.

Re: Passkeys are now enabled by default for Google users

#593
post #81

Always remember that passwords are protected by Fifth Amendment and similiar laws in other countries, but there is no law prohibiting officer to put your phone in front of your face to unlock it.

So do you have one password memorized or hundreds?

One, the one to my password manager, where the rest of my passwords are stored--but without the additional part I add after I paste the password that is stored in my head.

Re: Passkeys are now enabled by default for Google users

#594
post #69

Earlier quoted context omitted.

So why not just have a password that then unlocks the passkey? I already have a password manager.

Sure, PINs can be long and alphanumeric on most phones these days.

How is that different from a password? PIN stands for Personal Identification Number. Words change meaning all the time, of course, but in this case there’s no reason to call it a PIN when there’s already another word for it.

Re: Passkeys are now enabled by default for Google users

#595

Earlier quoted context omitted.

The initial poster described that process - you bring government IDs in person to an office. If you want to avoid that, just set up multiple devices.

Or use a password. Seriously, you have to do better here. I guess we will see recovery options by a master password and then the mechanism would be the question again.

I don't get it, why is a password superior? The argument of "what if you lose access to multiple devices" seems just as valid as the argument of "what if you forget your password". Recovery is the same either way - you need to establish identity somehow, using any number of other mechanisms (such as showing up somewhere with government issued ID).

Re: Passkeys are now enabled by default for Google users

#596
post #432

Earlier quoted context omitted.

> Run away screaming. Don’t believe the hype. Wait until the vendors get their act together and come up with a solution for transfer and recovery. Very much this. Having authentication tied to hardware you don't control is a near-certain denial of service in the future. People love to hate on passwords but the reality is that for many circumstances (threat models) they are the best compromise. You can make them more…

> People love to hate on passwords but the reality is that for many circumstances (threat models) they are the best compromise. You can make them more than strong enough (take 32+ bytes out of /dev/random and encode however you like, nobody will ever brute force that in this universe) and various passwords managers solve the problem of re-use (never reuse a password). > And it comes with the benefit that you control…

I tried a few different android apps a few years ago and since then I'm a happy user of Keepass2Android.

Re: Passkeys are now enabled by default for Google users

#597
post #486

Earlier quoted context omitted.

I recently watched a movie called the circle with Emma Watson where they want to tie the account with a corporation as a means of Id to register to vote. Imagine leaving identity to a corporate who simply shrugs off all but legal threats. It's terrifying and I reckon we are in our way there

I strongly recommend the book. It’s considerably better and gets into the dystopia better.

Yeah, off-topic but I definitely agree. The book is an easy read and good. I didn't know there was a movie; I should watch it.

Re: Passkeys are now enabled by default for Google users

#598
post #538

Earlier quoted context omitted.

All those issues were obvious from the day zero, and raised multiple times by many people. They're deliberately ignored by the stakeholders. They strongly want to lock you in to their own authentication platforms (iCloud Keychain, Windows Hello, 1Password*), that's why they don't want to address this. It's impossible they're not aware about those issues. Anyone with a brain and some technical expertise would come up…

On account recovery, the user is strictly no worse off with passkeys relative to passwords and arguably actually better off in many cases. This is not what I'd call deliberately ignoring concerns.

Yes, but if you had to resort to recovery you’re already past Passkeys or passwords. Recovery is not exactly in either’s spec, it’s a separate matter. Saying “but recovery is the same” is pointless - sure it is, by definition, because it’s out of scope.

Passkeys make it more likely that you’ll have to resort to account recovery, because it’s explicitly easier to lose passkey access than a password access (assuming that all platforms that implement passkeys implement password management as well, and that every password manager allows “export” by showing password to a naked eye).

One can write a copy of their password in a notebook and use it from anything with a keyboard and network connection. This mechanism is built in.

Passkeys are explicitly worse in this regard, as they don’t address export at all. Some implementations may be at par, but the overall spec is strictly worse, as it fails to address number of obvious issues.

Re: Passkeys are now enabled by default for Google users

#599

Earlier quoted context omitted.

> Why does this article claim that attestation is unlikely? Facebook is still going to want me on their websites even if I’m running Firefox. Most websites people visit will not do any chrome WEI attestation. Likely exceptions are sites which handle any legal, financial, or health-related data. Not credit cards. I doubt most Google properties will use WEI. They still want to slurp up all my juicy Firefox usage data a…

I'm willing to bet otherwise (w.r.t. your first statement). They probably consider the sliver of such users expendable. They probably also (rightly) assume that a significant percentage of that sliver will continue using their service (e.g. via sanctioned Chrome on sanctioned hardware) if push comes to shove. Or at least they will at some point in the near future.

Facebook went out of their way to make an onion address available for the application (https://en.m.wikipedia.org/wiki/Facebook_onion_address). They consider nobody to be “expendable” when it comes to their desire to profile individuals. Forcing their users into a specific browser will do nothing for them when what they want is for people to make requests against their servers.

Re: Passkeys are now enabled by default for Google users

#600

As others have pointed out, cryptographic authentication is very hard to bootstrap if you simply loose your device. Just last month my missus cracked the glass of her iPhone. Apple repaired it under AppleCare, which is great… except … that they didn’t tell her that the “glass repair” entails them replacing the guts of the phone and wiping it in the process. Apple iPhone backups don’t contain cryptographic secrets lik…

Honestly, if they'd just give me the option to write it down (or take a picture or whatever) and manually restore it by typing it in if I need to, that would just about solve the issue

Funny story, if you’re using TOTP (the time-varying code thing like in Google Authenticator), you can save a picture of the QR code and reuse it later and it will still work.
Post reply on HN