Live data from Hacker News

Passkeys are now enabled by default for Google users

blog.google

621–630 of 684 posts

Re: Passkeys are now enabled by default for Google users

#621
post #44

Earlier quoted context omitted.

Ah right, account recovery. The one that tells me the only way to sign in to my old Google account is to use a phone that no longer exists.

or to fax/email/send in government identity documents.

No, have a Google account that is locked forever without recourse. Even though I have email forwarding setup in that account to my main one.

Re: Passkeys are now enabled by default for Google users

#622
post #358

Earlier quoted context omitted.

> Let met ask you: has that discovery made you stop using your iPhone, or storing passwords or other critical data in your iCloud? Yes, it has (the latter). I was a big fan of (non-synchronized) on-device passkeys, but this has significantly changed the threat model for me. I use a third-party password manager exclusively now, and I'll probably be using its synchronized Passkey implementation too if it turns out to b…

I think you can set a longer iPhone password instead of a pin. Harder to surf.

Sure, but that's really inconvenient in the 99.9% of cases where I just want to unlock my phone, not recover my iCloud account password.

Re: Passkeys are now enabled by default for Google users

#623
post #502

Earlier quoted context omitted.

I'm from Brazil, where as is known many robberies and assaults happen on the street, and ever since the whole process of putting essential life services into smartphones started, many people are adopting a scheme of having 2 smartphones (if not 3 or 4 for other reasons! ) : 1) The House smartphone → it is where you install everything truly vital, like the main bank app (started mainly because of this), 2FA apps like…

"... This phone NEVER NEVER leaves the house, except ONCE if the bank app requires on location authentication of the phone for the bank app to function ..." Can you elaborate ? What does this "on location" process look like ? What do they ask you to do ?

I'm guessing it means you have to walk inside the bank branch, and show ID and your phone with the installed bank app to an employee who somehow authorizes the phone to use the app?

Re: Passkeys are now enabled by default for Google users

#624

Earlier quoted context omitted.

I don't get it, why is a password superior? The argument of "what if you lose access to multiple devices" seems just as valid as the argument of "what if you forget your password". Recovery is the same either way - you need to establish identity somehow, using any number of other mechanisms (such as showing up somewhere with government issued ID).

I can make a personal backup of a password. A fragile piece of hardware can fail me for a variety of reasons outside my control(lost or suddenly breaks). I have had a (Google) phone suddenly die in my hands without any prompting. With a password I was able to transition to a new device without incident. If my passkey was locked to that device, I might have found myself locked out of my digital identity.

> A fragile piece of hardware can fail me for a variety of reasons outside my control(lost or suddenly breaks).

But you can use multiple devices... How is "a password written down and stored somewhere" better than a separate device used for backup purposes? Hell, get three devices, go nuts.

Re: Passkeys are now enabled by default for Google users

#625

Earlier quoted context omitted.

How does this address OP's concern? If you have a single device (e.g. an iPhone) and you store all your passkeys on it, then losing it means you lost all passkeys. Your post describes exactly that: - "I can’t recover the keys if I lose the hardware" - "That is a risk you’ll need to take if you’re using hardware authenticators" Fantasizing that with this proposed simplification of the authentication process people wil…

I haven't heard anyone claim that passkeys are simpler than passwords, as that would be trivially false. The claim is that they're more secure while still remaining fairly usable. Passkeys are WebAuthn credentials that are synced between devices, so they aren't hardware keys, they're software keys.

> I haven't heard anyone claim that passkeys are simpler than passwords, as that would be trivially false.

I have frequently heard and read claims that passkeys are easier to use than passwords. The claim always seemed incorrect to me for so many reasons. What passkeys do is make things more complicated, but move where the complication is.

Re: Passkeys are now enabled by default for Google users

#627

Earlier quoted context omitted.

There are workarounds, but that doesn't mean that passkeys is a half-baked technology. The real, simple solution would be a way to write down the passkey, similar to an SSH private key.

A main idea of passkeys is that the private keys are bound to hardware and cannot be copied. Using the private key is subject to biometric authentication. This eliminates a whole category of issues where the private key could get stolen. So no, writing down the SSH private key is not the solution. The solution is to trust multiple private keys, each stored within tamperproof hardware. This is also why, as a service p…

> The solution is to trust multiple private keys, each stored within tamperproof hardware.

But as a user, this is not a realistic solution. If I have to keep multiple pieces of hardware enrolled, that means that I have to keep all the multiple pieces of hardware at hand when I create an account somewhere, and go through multiple enrollment cycles.

That means that I have to keep all the various pieces of hardware in the same physical location and relatively easy to access, which removes a great deal of the safety of redundancy.

It's just not realistically workable for me.

> I want to know that the keys being used here are not written on a fucking piece of paper.

Why do you care?

Re: Passkeys are now enabled by default for Google users

#628

As others have pointed out, cryptographic authentication is very hard to bootstrap if you simply loose your device. Just last month my missus cracked the glass of her iPhone. Apple repaired it under AppleCare, which is great… except … that they didn’t tell her that the “glass repair” entails them replacing the guts of the phone and wiping it in the process. Apple iPhone backups don’t contain cryptographic secrets lik…

Passkeys follow the 3-2-1 backup rule, just like any other digital data. The main difference being that you don't need to backup the passkey itself, just have multiple passkeys. Have 3 passkeys 2 of them on-person at any time (e.g. one on your phone TPM, one on a Yubikey) 1 of them off-site (e.g. keep a backup Yubikey at home in a fireproof safe, or use a 1Password passkey, depending on your threat model) Whenever yo…

> Whenever you sign up for a new vendor/service, register all three passkeys with your account.

That's exactly the part that makes this solution unworkable.

Re: Passkeys are now enabled by default for Google users

#629

Earlier quoted context omitted.

Passkeys follow the 3-2-1 backup rule, just like any other digital data. The main difference being that you don't need to backup the passkey itself, just have multiple passkeys. Have 3 passkeys 2 of them on-person at any time (e.g. one on your phone TPM, one on a Yubikey) 1 of them off-site (e.g. keep a backup Yubikey at home in a fireproof safe, or use a 1Password passkey, depending on your threat model) Whenever yo…

I do follow this. Unfortunately, it leaves out one glaring flaw: you can’t register a Passkey you don’t physically have. I use four: an Apple Passkey, a YubiKey I keep on me, a YubiKey at home, and a YubiKey in the bank. When I sign up for a service, I need to register all four of them. Not only is this generally a bit of a pain in the ass, but it also means I have to remember to go fetch the one in the bank vault pe…

> "glaring flaw: you can’t register a Passkey you don’t physically have."

I have Yubikeys and find this frustrating.

Is there not a technical solution that should've happened by now, or is it not as simple as I'm imagining: can't hardware passkeys have a way to export whatever it is that's needed for services to register them (public key/s?) such that if you have 4 keys you can export 4 files to your PC and and time you create an online account just provide all four files at the same time to be registered?

I guess maybe it's not as simple as being a public key that can be registered without the key being around, some sort of active challenge/response needed as part of registration? Or is my imagined solution above completely workable and just overlooked so far?

Re: Passkeys are now enabled by default for Google users

#630

Lauren Weinstein is sounding the alarm on passkeys which is flawed and that it would make a huge headache for a lot of people especilly normal folks. https://mastodon.laurenweinstein.org/@lauren/111103819626952... https://mastodon.laurenweinstein.org/@lauren/111211366080459...

“Weak device authentication”? I though all phones had fingerprint scanners or face scanning nowadays?

[deleted]
Post reply on HN