Interesting. I'm still struggling to see how this is better than just using a yubi/solo-key
Bringing passkeys to Android and Chrome
11–20 of 264 posts
Re: Bringing passkeys to Android and Chrome
#12Interesting. I'm still struggling to see how this is better than just using a yubi/solo-key
Since I already use a phone capable of doing the same thing, let my phone be my main authenticator, and then I can use a Yubikey as a backup.
It's not like one is necessarily better than the other, except that you already carry a phone and they're capable of being a hardware device that works with Webauthn. No need to carry a second device or, pay for one, for that matter. Since at least with Apple's solution it'll sync over iCloud Keychain.
If you're happy with Yubikey's, nothing changes. But for the average person, this makes Webauthn an option without having to buy any hardware or carry something you are more likely to lose because you don't understand the intricate details of how the thing works. I wouldn't expect my parents to understand how a Yubikey works well enough to know it should be used as a pair, for backup purposes, but that is a barrier to entry for them that they don't need to worry about now.
Re: Bringing passkeys to Android and Chrome
#13And what happens if your Google account that these keys are tied to is locked/revoked for a nebulous ToS violation?
Re: Bringing passkeys to Android and Chrome
#14Interesting. I'm still struggling to see how this is better than just using a yubi/solo-key
Yubikeys are great but they're super niche. Among Android users alone there might be a billion people who will never buy one.
Re: Bringing passkeys to Android and Chrome
#15Another product that they will use their dominant position to force down our throat!
I'm struggling to see your complaint being a valid one. This is basically webauthn, so use a Yubikey or similar device if you wish.
Re: Bringing passkeys to Android and Chrome
#16And what happens if your Google account that these keys are tied to is locked/revoked for a nebulous ToS violation?
Re: Bringing passkeys to Android and Chrome
#17Interesting. I'm still struggling to see how this is better than just using a yubi/solo-key
Thus, unlike a FIDO2 key, you don't have to visit every online service to tell it about the new redundant keys you add.
The rest of the security article linked by madjam002 goes into detail how Google implements their version of that backup. It's a bit like Keybase in the sense that your other devices act as keys to unlock the backup for new devices.
Re: Bringing passkeys to Android and Chrome
#18And what happens if your Google account that these keys are tied to is locked/revoked for a nebulous ToS violation?
From TFA (the security blog): "The main ingredient of a passkey is a cryptographic private key. In most cases, this private key lives only on the user's own devices, such as laptops or mobile phones."
Of course, one doesn’t need to utilize this, but you’re SOL without a recovery mechanism of last resort (unless individual sites and services have their own recovery processes to re-provision a user who no longer has access to their cryptographic credentials).
Re: Bringing passkeys to Android and Chrome
#19And what happens if your Google account that these keys are tied to is locked/revoked for a nebulous ToS violation?
From TFA (the security blog): "The main ingredient of a passkey is a cryptographic private key. In most cases, this private key lives only on the user's own devices, such as laptops or mobile phones."
Re: Bringing passkeys to Android and Chrome
#20And what happens if your Google account that these keys are tied to is locked/revoked for a nebulous ToS violation?
From TFA (the security blog): "The main ingredient of a passkey is a cryptographic private key. In most cases, this private key lives only on the user's own devices, such as laptops or mobile phones."
"Only on the user's device", right.