Live data from Hacker News

Passkeys are now enabled by default for Google users

blog.google

611–620 of 684 posts

Re: Passkeys are now enabled by default for Google users

#611
post #549

Earlier quoted context omitted.

Passwords are also not entirely secret, as they're shared by definition. Passkeys use public-private key crypto, which is more secure in every way.

Password should be stored as salted hash, so they are not really shared.

Salted and hashed passwords must be shared but not (hopefully not) stored.

Re: Passkeys are now enabled by default for Google users

#612

Earlier quoted context omitted.

How does this address OP's concern? If you have a single device (e.g. an iPhone) and you store all your passkeys on it, then losing it means you lost all passkeys. Your post describes exactly that: - "I can’t recover the keys if I lose the hardware" - "That is a risk you’ll need to take if you’re using hardware authenticators" Fantasizing that with this proposed simplification of the authentication process people wil…

I haven't heard anyone claim that passkeys are simpler than passwords, as that would be trivially false. The claim is that they're more secure while still remaining fairly usable. Passkeys are WebAuthn credentials that are synced between devices, so they aren't hardware keys, they're software keys.

Here is Google discussing how passkeys are easier and simpler to use than passwords: https://security.googleblog.com/2023/05/making-authenticatio...

Here is 1Password discussing how passkeys are simpler to use than passwords: https://1password.com/product/passkeys

Here is Ars Technica declaring that passkeys are easier to use than passwords: https://arstechnica.com/information-technology/2023/05/passw...

Etc etc. If this is the first time you are seeing businesses and media refer to passkeys as being simpler to use than passwords you haven't been paying attention.

Re: Passkeys are now enabled by default for Google users

#613
post #589

Earlier quoted context omitted.

Totp is phishable. Passkeys aren't phishable. At the point where the user can access the private keys phishing is once again a concern. If I can't access my pk, I cannot be phished. As soon as you allow me to copy my key (instead of creating many, which should be acceptable) I can be phished again.

Passkeys are stealable no? If I have you phone...

You still need my password or fingerprint to usea passkey, and can't transfer it from my device to yours.

Re: Passkeys are now enabled by default for Google users

#614

Earlier quoted context omitted.

I haven't heard anyone claim that passkeys are simpler than passwords, as that would be trivially false. The claim is that they're more secure while still remaining fairly usable. Passkeys are WebAuthn credentials that are synced between devices, so they aren't hardware keys, they're software keys.

Here is Google discussing how passkeys are easier and simpler to use than passwords: https://security.googleblog.com/2023/05/making-authenticatio... Here is 1Password discussing how passkeys are simpler to use than passwords: https://1password.com/product/passkeys Here is Ars Technica declaring that passkeys are easier to use than passwords: https://arstechnica.com/information-technology/2023/05/passw... Etc etc. If…

Oh huh, I stand corrected. I thought passwords were easy, but, thinking about it, I've had lots of trouble trying to figure out which password I've used for each site.

I can definitely believe passkeys are easier, in light of that.

Re: Passkeys are now enabled by default for Google users

#615
post #589

Earlier quoted context omitted.

Passkeys are stealable no? If I have you phone...

You still need my password or fingerprint to use a passkey, and can't transfer it from my device to yours.

Doesn't sound a whole lot different from TOTP to me.

Re: Passkeys are now enabled by default for Google users

#616
post #358
post #275

Earlier quoted context omitted.

It is a fair observation. And I can see why users tend to be alarmed about this. Although in my experience users tend to significantly underestimate the real risks of online attacks relative to these more visceral threats. Let met ask you: has that discovery made you stop using your iPhone, or storing passwords or other critical data in your iCloud? If the answer is "No", then you're strictly better off moving to pas…

> Let met ask you: has that discovery made you stop using your iPhone, or storing passwords or other critical data in your iCloud? Yes, it has (the latter). I was a big fan of (non-synchronized) on-device passkeys, but this has significantly changed the threat model for me. I use a third-party password manager exclusively now, and I'll probably be using its synchronized Passkey implementation too if it turns out to b…

I think you can set a longer iPhone password instead of a pin. Harder to surf.

Re: Passkeys are now enabled by default for Google users

#617

Earlier quoted context omitted.

Nevertheless, nothing forces my banking app to accept a second PassKey other than the one linked to FaceID. When I buy a new phone, I need to re-bootstrap auth from zero. There’s no way to store two.

Is the app the only way you interface with your bank? It doesn't have a website? All of the things I've used passkeys on support both web and mobile auth, which necessitates two keys.

You'd be surprised! There are plenty of new banks in Asia which only have mobile apps. You can't access your account using a web browser at all. They don't even give you a passbook, all banking activity from signup are done via the mobile app.

Re: Passkeys are now enabled by default for Google users

#618

Earlier quoted context omitted.

You are correct about all of that. But personally, as a technically able user, my risk of randomly losing access to my Google (or MS, Apple, Meta, etc) account is far greater than from all those threats combined. If we had a trustworthy and accountable authority operating this stuff then it would be great. But we don't, we have a bunch of companies who are neither of those things. It's like mandating that everyone mu…

You can use whatever passkey/password manager you want to though. You don’t need to use Google or Apple’s password/passkey manager apps if you don’t want to. Passkeys are WebAuthn credentials, which is an open standard, and it’s being supported by an increasing number of password manager apps.

In theory. Let's see how that pans out over the next couple of years, I think imposing platform lock-in in is going to be impossible for them to resist.

Re: Passkeys are now enabled by default for Google users

#619

Earlier quoted context omitted.

What are the odds that someone with a passcode 1234 is 1/ already signed into Google on their phone or 2/ has their Google password already saved in the device password manager (since it asks you to save it every time you sign in) which is also protected by the device pin? At least in this case the thief has to steal the physical phone instead of guessing "password123" on the google signin prompt from the comfort of…

Don’t try to argue that on-device biometrics are a foolproof solution to this. Even at it’s best you can unlock a device from a sleeping (or drunk or naive) user which just brings us back to the same issue: already being logged in to a passkey service.

From the parent I responded to, emphasis mine:

> The criticism is based on the idea that most non-techie folks are unlikely to use a strong PIN _and are unlikely to set up strong biometrics._

On-device biometrics are typically _also_ used to unlock the device password manager, so my other remarks still apply. I bet a sizeable portion of the HN crowd also uses biometrics to unlock their well-configured password managers on their phone.

At least, that's what I personally do. Entering my very strong vault password every [lock duration] on a touch keyboard is already irritating enough; I'd rather just look at my phone to unlock my passwords when I need to use autofill.

Re: Passkeys are now enabled by default for Google users

#620

Lauren Weinstein is sounding the alarm on passkeys which is flawed and that it would make a huge headache for a lot of people especilly normal folks. https://mastodon.laurenweinstein.org/@lauren/111103819626952... https://mastodon.laurenweinstein.org/@lauren/111211366080459...

This debate is frustrating because it lacks data — it's full of opinions about which risk is worse than which other.

To compare the risks and benefits, we need to know how often people actually re-use passwords, use 2FA, rely solely on their phone screen lock for access to all their accounts, use biometrics, need account recovery, and so on. That data is the only way to settle the debate (and would allow each person can settle it for themselves, perhaps differently based on their circumstances).

Google has most of this data. They should publish it to back up their claims.

Post reply on HN