Earlier quoted context omitted.
Won’t most people be logged into their Google account anyways? So if you steal their phone, and guess their PIN then you can just use the already logged in account. What does this change?
Certain account changing actions cannot be completed without the password. But if you have the phone (session, sms, passkey), you can reset the password and it's off to the races.
Passkeys are now enabled by default for Google users
661–670 of 684 posts
Re: Passkeys are now enabled by default for Google users
#662As others have pointed out, cryptographic authentication is very hard to bootstrap if you simply loose your device. Just last month my missus cracked the glass of her iPhone. Apple repaired it under AppleCare, which is great… except … that they didn’t tell her that the “glass repair” entails them replacing the guts of the phone and wiping it in the process. Apple iPhone backups don’t contain cryptographic secrets lik…
Re: Passkeys are now enabled by default for Google users
#663Earlier quoted context omitted.
I'm from Brazil, where as is known many robberies and assaults happen on the street, and ever since the whole process of putting essential life services into smartphones started, many people are adopting a scheme of having 2 smartphones (if not 3 or 4 for other reasons! ) : 1) The House smartphone → it is where you install everything truly vital, like the main bank app (started mainly because of this), 2FA apps like…
"... This phone NEVER NEVER leaves the house, except ONCE if the bank app requires on location authentication of the phone for the bank app to function ..." Can you elaborate ? What does this "on location" process look like ? What do they ask you to do ?
Re: Passkeys are now enabled by default for Google users
#664Earlier quoted context omitted.
I'm from Brazil, where as is known many robberies and assaults happen on the street, and ever since the whole process of putting essential life services into smartphones started, many people are adopting a scheme of having 2 smartphones (if not 3 or 4 for other reasons! ) : 1) The House smartphone → it is where you install everything truly vital, like the main bank app (started mainly because of this), 2FA apps like…
Even that doesn't seem like enough to me. You need not just multiple devices, but multiple distant locations. A fire, flood, car accident, or theft can result in the total loss of multiple devices unless one is sufficiently far away and also secure. Then there's keeping that remote device up to date. This is beyond the patience, finance, and understanding of virtually everyone.
A disaster scenario in practice means you are screwed either way here, tons of physical documents can be lost or destroyed too, but that is a calamity that by definition is exceedingly rare.
Most are worried about common thiefs, a scenario of robbery or assault that can happen anytime anywhere and frequently, repeatedly. The overall threat here is far larger that the rare scenario.
Now, to the complexity. Usually the thief smartphone is some old phone still around, might not even be working, and no one puts anything in there, it is literally a throw-away device. It has no complexity or hassle, and usually is free. The house smartphone, people usually repurpose some old smartphone or buy a cheap android. I still have an iphone 6 for this purpose, and if the app is up to date, it usually is safe enough. People will not be using the phone for anything else, it will not leave the house, so exposition is severely reduced.
Re: Passkeys are now enabled by default for Google users
#665As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?
Passkeys are a new technology and everyone - including users, service providers, and organizations - will take time to learn and adapt. In this interim period the recommended approach is to provide passkeys as an alternative to whatever is already offered. This is the approach that Google and many other service providers are taking. That said, you are bringing up the right questions on the general topic of account re…
Re: Passkeys are now enabled by default for Google users
#666Earlier quoted context omitted.
What difference does it make? You still have all the same disadvantages.
There's a huge gap in price between a phone and a yubikey.
Re: Passkeys are now enabled by default for Google users
#667As others have pointed out, cryptographic authentication is very hard to bootstrap if you simply loose your device. Just last month my missus cracked the glass of her iPhone. Apple repaired it under AppleCare, which is great… except … that they didn’t tell her that the “glass repair” entails them replacing the guts of the phone and wiping it in the process. Apple iPhone backups don’t contain cryptographic secrets lik…
> Run away screaming. Don’t believe the hype. Wait until the vendors get their act together and come up with a solution for transfer and recovery. Very much this. Having authentication tied to hardware you don't control is a near-certain denial of service in the future. People love to hate on passwords but the reality is that for many circumstances (threat models) they are the best compromise. You can make them more…
You can use passkeys with a yubikey, right?
Re: Passkeys are now enabled by default for Google users
#668Earlier quoted context omitted.
My understanding is that Passkeys are transferrable, unlike earlier efforts. See for example this iOS help page: https://support.apple.com/guide/iphone/passkeys-passwords-de... Unless you store the passkey in a hardware Fido key like a Yubikey. Then the way to transfer it is to physically carry the key and plug it to another device.
OP specifically mentions "cross-vendor" transferable. Which, to my understanding, is currently true.
Re: Passkeys are now enabled by default for Google users
#669Earlier quoted context omitted.
I recently watched a movie called the circle with Emma Watson where they want to tie the account with a corporation as a means of Id to register to vote. Imagine leaving identity to a corporate who simply shrugs off all but legal threats. It's terrifying and I reckon we are in our way there
I strongly recommend the book. It’s considerably better and gets into the dystopia better.
Re: Passkeys are now enabled by default for Google users
#670Earlier quoted context omitted.
There's a huge gap in price between a phone and a yubikey.
You also lose an element of security - if someone steals your phone, they still need your fingerprint/face/PIN/whatever to access all your accounts, and you might even be able to lock or wipe the phone remotely.