Live data from Hacker News

Passkeys are now enabled by default for Google users

blog.google

601–610 of 684 posts

Re: Passkeys are now enabled by default for Google users

#601
post #518

Earlier quoted context omitted.

A passkey does not contain and is not derived from biometric data, so one cannot login to an account using biometric data alone. If one wanted to use biometric data to access a Google Account secured with a passkey, one would: 1. Need to find a device with that passkey on it (or an account like iCloud Keychain or 1Password that contains the synced passkey). Biometric data could be used to unlock the iPhone, in theory…

It does not have to be a thug who makes your picture. Titanic has crashed. Microsoft has been hacked. There are no solutions that do not contain bugs. There are no drivers for sensors that cannot be hacked. Sure hacking a device is difficult, sure. Maybe nearly impossible, but I doubt it. All software has bugs. Some even backdoors. Some data are centralized and kept on big tech cloud storage which is a honey pot for…

Yes, I understand that biometric data can be acquired… The biometric data does not alone get you into an account with a passkey.

You still need the device/account that the passkey is stored on.

Re: Passkeys are now enabled by default for Google users

#602
post #594

Earlier quoted context omitted.

Sure, PINs can be long and alphanumeric on most phones these days.

How is that different from a password? PIN stands for Personal Identification Number. Words change meaning all the time, of course, but in this case there’s no reason to call it a PIN when there’s already another word for it.

The important difference is that it is stored on the local device, not the remote server.

Since the things stored on the remote server have been called “passwords” for decades, it seems helpful to call the local thing a “PIN” to help more easily distinguish it.

IMO it’s not more silly than calling a hand-held computer a “phone.”

Re: Passkeys are now enabled by default for Google users

#603

As others have pointed out, cryptographic authentication is very hard to bootstrap if you simply loose your device. Just last month my missus cracked the glass of her iPhone. Apple repaired it under AppleCare, which is great… except … that they didn’t tell her that the “glass repair” entails them replacing the guts of the phone and wiping it in the process. Apple iPhone backups don’t contain cryptographic secrets lik…

That's the reason i have 2 devices with my accounts and auth app. One is for daily use and another one is a backup phone in case something happens to the first one

Re: Passkeys are now enabled by default for Google users

#604

As others have pointed out, cryptographic authentication is very hard to bootstrap if you simply loose your device. Just last month my missus cracked the glass of her iPhone. Apple repaired it under AppleCare, which is great… except … that they didn’t tell her that the “glass repair” entails them replacing the guts of the phone and wiping it in the process. Apple iPhone backups don’t contain cryptographic secrets lik…

TBH I don't trust google on security one bit after one of my namesakes attached her phone to my google account a few months ago without any warning or prompting by google to me.

Re: Passkeys are now enabled by default for Google users

#605

Lauren Weinstein is sounding the alarm on passkeys which is flawed and that it would make a huge headache for a lot of people especilly normal folks. https://mastodon.laurenweinstein.org/@lauren/111103819626952... https://mastodon.laurenweinstein.org/@lauren/111211366080459...

“Weak device authentication”? I though all phones had fingerprint scanners or face scanning nowadays?

Re: Passkeys are now enabled by default for Google users

#606

Earlier quoted context omitted.

For that reason I don't want passkey. Password and regular 2fa/totp are fine... when setting 2fa I put it on my phone and my computer and another password vault on rpi... granted, everything still in same location but still somewhat better. I'm not really sold on esim neither - regular sims let you pop and swap them easily... why complicate it?

>Password and regular 2fa/totp are fine This might feel true, but it's factually not true. Both passwords and TOTP can be phished. In addition, passwords can be weak, reused, and password hashes can (and are frequently) stolen and cracked in server breaches. Passkeys are guaranteed to be strong, unique (can't be reused), strongly phishing-resistant, and there's nothing worth stealing from servers (just public keys).…

If someone is ignorant and (Re)uses weak password then it's own fault. Yes, phishing can happen but it's more convoluted (and again - lack of attention). Being conscious about it brings the benefit of not relying on single point of failure...

Re: Passkeys are now enabled by default for Google users

#607
post #592

There's one elephant in the room I'm not hearing enough about, namely the legal precedent (at least in the U.S.) that you can legally be compelled to provide a biometric identifier (fingerprint, face scan, etc.), but cannot be compelled to provide a password, as that would be "compelled speech" and violate the first amendment. I disable all kinds of biometrics from my devices when traveling for this reason specifical…

Interesting point. Seems like a point where the law lacks behind technological progress. Though, in any case, most people aren’t aware of the detailed laws and when pressured enough by enough authority - perhaps not quite lawfully - they will give in. So, this seems to me a rather niche case where both sides know and follow the law, which is usually not the case.

Re: Passkeys are now enabled by default for Google users

#608
post #173

Earlier quoted context omitted.

I reset it using my SMS 2FA phone. I can't lose that number because in my country I'm legally entitled to it.

Could you please specify which country you are referring to where individuals are legally entitled to keep their phone number? Thank you!

In Poland I can keep my number and recover the SIM, but I guess it's EU-wide.

Re: Passkeys are now enabled by default for Google users

#609

Earlier quoted context omitted.

Threat #1: Credential theft from server breaches Threat #2: User creates a weak credential Threat #3: User reuses a credential (uses same credential across multiple services) Threat #4: Phishing Attackers use huge password dumps compiled from multiple server breaches, and then try them against other services. Relying on a combination of the fruits of their labor from all four threats, attackers successfully compromis…

You are correct about all of that. But personally, as a technically able user, my risk of randomly losing access to my Google (or MS, Apple, Meta, etc) account is far greater than from all those threats combined. If we had a trustworthy and accountable authority operating this stuff then it would be great. But we don't, we have a bunch of companies who are neither of those things. It's like mandating that everyone mu…

You can use whatever passkey/password manager you want to though. You don’t need to use Google or Apple’s password/passkey manager apps if you don’t want to. Passkeys are WebAuthn credentials, which is an open standard, and it’s being supported by an increasing number of password manager apps.

Re: Passkeys are now enabled by default for Google users

#610

Earlier quoted context omitted.

Or use a password. Seriously, you have to do better here. I guess we will see recovery options by a master password and then the mechanism would be the question again.

I don't get it, why is a password superior? The argument of "what if you lose access to multiple devices" seems just as valid as the argument of "what if you forget your password". Recovery is the same either way - you need to establish identity somehow, using any number of other mechanisms (such as showing up somewhere with government issued ID).

I can make a personal backup of a password. A fragile piece of hardware can fail me for a variety of reasons outside my control(lost or suddenly breaks).

I have had a (Google) phone suddenly die in my hands without any prompting. With a password I was able to transition to a new device without incident. If my passkey was locked to that device, I might have found myself locked out of my digital identity.

Post reply on HN