Live data from Hacker News

Passkeys are now enabled by default for Google users

blog.google

661–670 of 684 posts

Re: Passkeys are now enabled by default for Google users

#661
post #451

Earlier quoted context omitted.

Won’t most people be logged into their Google account anyways? So if you steal their phone, and guess their PIN then you can just use the already logged in account. What does this change?

Certain account changing actions cannot be completed without the password. But if you have the phone (session, sms, passkey), you can reset the password and it's off to the races.

If the person uses a password manager, same result. You have the phone unlocked, you have everything.

Re: Passkeys are now enabled by default for Google users

#662

As others have pointed out, cryptographic authentication is very hard to bootstrap if you simply loose your device. Just last month my missus cracked the glass of her iPhone. Apple repaired it under AppleCare, which is great… except … that they didn’t tell her that the “glass repair” entails them replacing the guts of the phone and wiping it in the process. Apple iPhone backups don’t contain cryptographic secrets lik…

[deleted]

Re: Passkeys are now enabled by default for Google users

#663
post #502

Earlier quoted context omitted.

I'm from Brazil, where as is known many robberies and assaults happen on the street, and ever since the whole process of putting essential life services into smartphones started, many people are adopting a scheme of having 2 smartphones (if not 3 or 4 for other reasons! ) : 1) The House smartphone → it is where you install everything truly vital, like the main bank app (started mainly because of this), 2FA apps like…

"... This phone NEVER NEVER leaves the house, except ONCE if the bank app requires on location authentication of the phone for the bank app to function ..." Can you elaborate ? What does this "on location" process look like ? What do they ask you to do ?

Pardon for the delay. I'm surprised , i did not know this was not usual in other places. The biggest bank here is Bank of Brazil (state bank), and it has a lot of local physical sites in all over the country, with multiple units in bigger cities. A client ALWAYS has a main physical unit associated with their account, according to the address, and the person is required to physically go there to do many actions. There is a 2nd floor or rear area where there is a few bureaucrats or even the local manager, and the client has to appoint a meeting with them (usually by entering and waiting in a line at the moment, no internet pre-arranged way) to do stuff like big financial transactions, close or open the account, buy dollars or euros, seek advice about and start to use financial services of the bank like insurances retiremensts, etc. The front area of the 1st floor is where the money machines are located, where people usually get physical cash, pay bills, etc. The person has to use both a fingerprint and a password to authorize the operations, and of course there is cameras both in and out of the bank registering everything, and usually morning to afternoon there is a local security staff of 1 or a few (depending on the unit size). Now with the context, finally to the on location authentication mechanism: The client can download the bank app, and login, but to actually DO anything in the app, the client first has to physically go to her-his main physical unit with the smartphone to be used, and go to a money machine. There, she-he has to login in the machine using both the fingerprint and password, and do the operation of authorizing the smartphone to be associated with the account, confirm by SMS on the smartphone, and voilá. ONLY NOW can the bank app properly be used. That is why i called it 'on location authentication', the client has to go personally with the smartphone itself to a physical unit in order to authenticate the phone , so that the bank app can be used. The fin-tech banks by contrast are 100% freestyle in every way, having no physical units and not demanding any sort of protocol to do equivalent actions, and that is loved by many, but there also the issue of less security, even much less security i dare to say, which was proved by a history of many crimes and frauds happening now that used them as instruments. Many people were victims of fraudsters that created bank accounts in their names exactly in these fin-tech banks, and did shenigans like taking 5 digit loans, buying physical goods, etc.

Re: Passkeys are now enabled by default for Google users

#664

Earlier quoted context omitted.

I'm from Brazil, where as is known many robberies and assaults happen on the street, and ever since the whole process of putting essential life services into smartphones started, many people are adopting a scheme of having 2 smartphones (if not 3 or 4 for other reasons! ) : 1) The House smartphone → it is where you install everything truly vital, like the main bank app (started mainly because of this), 2FA apps like…

Even that doesn't seem like enough to me. You need not just multiple devices, but multiple distant locations. A fire, flood, car accident, or theft can result in the total loss of multiple devices unless one is sufficiently far away and also secure. Then there's keeping that remote device up to date. This is beyond the patience, finance, and understanding of virtually everyone.

Total security does not exist, as the saying goes. These are several counter-measures that emerged in the social sphere of common people, to increase security a few levels and hopefully avoid the worst scenarios at least. I don't think almost anyone has all 4 smartphone categories i listed, but if you ask around, most would recognize the measures you are talking about.

A disaster scenario in practice means you are screwed either way here, tons of physical documents can be lost or destroyed too, but that is a calamity that by definition is exceedingly rare.

Most are worried about common thiefs, a scenario of robbery or assault that can happen anytime anywhere and frequently, repeatedly. The overall threat here is far larger that the rare scenario.

Now, to the complexity. Usually the thief smartphone is some old phone still around, might not even be working, and no one puts anything in there, it is literally a throw-away device. It has no complexity or hassle, and usually is free. The house smartphone, people usually repurpose some old smartphone or buy a cheap android. I still have an iphone 6 for this purpose, and if the app is up to date, it usually is safe enough. People will not be using the phone for anything else, it will not leave the house, so exposition is severely reduced.

Re: Passkeys are now enabled by default for Google users

#665
post #201
post #13

As a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?

Passkeys are a new technology and everyone - including users, service providers, and organizations - will take time to learn and adapt. In this interim period the recommended approach is to provide passkeys as an alternative to whatever is already offered. This is the approach that Google and many other service providers are taking. That said, you are bringing up the right questions on the general topic of account re…

But you can set family members/significant others/etc as possible recovery mechanisms! This seems like a really workable solution that I don’t see people discussing in this thread?

Re: Passkeys are now enabled by default for Google users

#666

Earlier quoted context omitted.

What difference does it make? You still have all the same disadvantages.

There's a huge gap in price between a phone and a yubikey.

You also lose an element of security - if someone steals your phone, they still need your fingerprint/face/PIN/whatever to access all your accounts, and you might even be able to lock or wipe the phone remotely.

Re: Passkeys are now enabled by default for Google users

#667
post #432

As others have pointed out, cryptographic authentication is very hard to bootstrap if you simply loose your device. Just last month my missus cracked the glass of her iPhone. Apple repaired it under AppleCare, which is great… except … that they didn’t tell her that the “glass repair” entails them replacing the guts of the phone and wiping it in the process. Apple iPhone backups don’t contain cryptographic secrets lik…

> Run away screaming. Don’t believe the hype. Wait until the vendors get their act together and come up with a solution for transfer and recovery. Very much this. Having authentication tied to hardware you don't control is a near-certain denial of service in the future. People love to hate on passwords but the reality is that for many circumstances (threat models) they are the best compromise. You can make them more…

>Having authentication tied to hardware you don't control is a near-certain denial of service in the future.

You can use passkeys with a yubikey, right?

Re: Passkeys are now enabled by default for Google users

#668
post #556

Earlier quoted context omitted.

My understanding is that Passkeys are transferrable, unlike earlier efforts. See for example this iOS help page: https://support.apple.com/guide/iphone/passkeys-passwords-de... Unless you store the passkey in a hardware Fido key like a Yubikey. Then the way to transfer it is to physically carry the key and plug it to another device.

OP specifically mentions "cross-vendor" transferable. Which, to my understanding, is currently true.

You can set up a Yubikey on a mac and use it on a Windows machine. It’s cross-vendor transferrable.

Re: Passkeys are now enabled by default for Google users

#669
post #486

Earlier quoted context omitted.

I recently watched a movie called the circle with Emma Watson where they want to tie the account with a corporation as a means of Id to register to vote. Imagine leaving identity to a corporate who simply shrugs off all but legal threats. It's terrifying and I reckon we are in our way there

I strongly recommend the book. It’s considerably better and gets into the dystopia better.

Thank you for the recommendation. It's now on my list.

Re: Passkeys are now enabled by default for Google users

#670

Earlier quoted context omitted.

There's a huge gap in price between a phone and a yubikey.

You also lose an element of security - if someone steals your phone, they still need your fingerprint/face/PIN/whatever to access all your accounts, and you might even be able to lock or wipe the phone remotely.

Yubikeys can have PIN and biometric protection.
Post reply on HN