Live data from Hacker News

Bringing passkeys to Android and Chrome

android-developers.googleblog.com

121–130 of 264 posts

Re: Bringing passkeys to Android and Chrome

#121

Earlier quoted context omitted.

> That’s part of the design though. That’s what completely eliminates the ability to do phishing-attacks. If the actual domain name is used to generate the key that would also completely eliminates the ability to do phishing-attacks. Paypal.com and PaypaI.com would generate two completely different keys.

It would mean that somewhere there is a common root, which if extracted, can derive all keys for all sites. Why introduce such a risk when there’s no reason to do that?

If I can get access to your device to exfiltrate the private key that generates the domain specific keys, why wouldn't I also have access to the the randomly generated site keys? Your device needs access to the keys to use them.

In both cases your device has a private key that it needs to secure. In my scenario we remove the third party cloud service.

Re: Bringing passkeys to Android and Chrome

#122

Earlier quoted context omitted.

> That’s part of the design though. That’s what completely eliminates the ability to do phishing-attacks. If the actual domain name is used to generate the key that would also completely eliminates the ability to do phishing-attacks. Paypal.com and PaypaI.com would generate two completely different keys.

It would mean that somewhere there is a common root, which if extracted, can derive all keys for all sites. Why introduce such a risk when there’s no reason to do that?

Because then as a user you'd still have the ability to backup that key yourself and aren't at the mercy of $cloud_service_of_your_choice.

Re: Bringing passkeys to Android and Chrome

#123

Earlier quoted context omitted.

> but I can at least visualize Apple having the scale to do that. > Google on the other hand has a horrendous reputation for Neither are true nor false but definitely exaggerations. All you're doing is displaying personal biases by providing them with benefit-of-the-doubts. They too have a reputation for locking people out, and are well known for turning data over, but one that HN in gernal prefers to ignore.

> Neither are true nor false but definitely exaggerations. Google does not kill services. That does not happen. Google definitely does not deplatform people killing all their accounts and all their access. That also does not happen.

Missing /s

Re: Bringing passkeys to Android and Chrome

#125
post #27

Passkeys sound like another way for companies like Google and Apple to lock you into their walled garden. Having each walled garden randomly generating a key for every single domain instead of using the actual domain name as part of the key is a great way to lock regular people into their respective ecosystems.

Seems like you wouldn't want to share passkeys for the same reasons you don't normally want to share passwords?

Instead, each website that accepts passkeys should allow you to register multiple devices and probably print out backup codes as well (for the especially important accounts).

If there's no reason to migrate anything then lock-in is irrelevant. Just add more login methods so that when you lose some, you have others.

Re: Bringing passkeys to Android and Chrome

#126

Earlier quoted context omitted.

It's not particularly surprising. Apple has a much better reputation at customer service than Google does – they have actual stores you can walk into. Now I'm not sure whether they can help you unlock your Apple ID if you prove to them that you're the owner of the account, but I can at least visualize Apple having the scale to do that. Google on the other hand has a horrendous reputation for locking out people out of…

At the risk of being pedantic, no. Apple Stores aren’t able or empowered to provide Apple ID support beyond what the public website based recovery workflows provide. I am sure someone will note that someone at an Apple Store has helped them reset an Apple ID password. What I mean is that Apple Store employees have neither procedure nor access to override Apple’s account system. You have to call support for assistance…

Eh. Pedantically; the Apple Store will at least try to help you, even if they’re not empowered to fix it they will guide you through the process until there is a resolution.

It’s not as “you’re on your own” as some products I’ve owned.

Re: Bringing passkeys to Android and Chrome

#128
post #127

Dumb question: what keeps me from spoofing the fingerprint[1] and obtaining all the passcodes at once? [1] https://phys.org/news/2005-12-biometric-expert-easy-spoof-fi...

Note you can't just get the keys even if you have a fingerprint. You would need to maintain continuous access to the device while it is still signed in as the user. It would be pretty easy to the "find my device", if the user didn't already notice you were handling it

Re: Bringing passkeys to Android and Chrome

#129
post #16

And what happens if your Google account that these keys are tied to is locked/revoked for a nebulous ToS violation?

From TFA (the security blog): "The main ingredient of a passkey is a cryptographic private key. In most cases, this private key lives only on the user's own devices, such as laptops or mobile phones."

"on your device" doesn't mean that you can actually access the key though. It might be stored in the secure enclave/TPM or otherwise unavailable if the phone has a locked bootloader.

Re: Bringing passkeys to Android and Chrome

#130

Earlier quoted context omitted.

The second most popular top level comment chain is: > Unless I can back it up and import it into a new device from a competitor, then there is no way I am going to use this unless forced. I do not trust one company anymore. Which is the same sentiment as this thread. The first comment was just talking about the open standard of Apple's implementation and weakness of 2FA loss/recovery. https://news.ycombinator.com/ite…

> I do not trust one company anymore. Especially when that company is Google.

[deleted]
Post reply on HN