Live data from Hacker News

Bringing passkeys to Android and Chrome

android-developers.googleblog.com

131–140 of 264 posts

Re: Bringing passkeys to Android and Chrome

#132
post #27

Passkeys sound like another way for companies like Google and Apple to lock you into their walled garden. Having each walled garden randomly generating a key for every single domain instead of using the actual domain name as part of the key is a great way to lock regular people into their respective ecosystems.

Seems like you wouldn't want to share passkeys for the same reasons you don't normally want to share passwords? Instead, each website that accepts passkeys should allow you to register multiple devices and probably print out backup codes as well (for the especially important accounts). If there's no reason to migrate anything then lock-in is irrelevant. Just add more login methods so that when you lose some, you have…

I have over 500 online accounts. Imagine if all of them used a login method where I had to have backup devices registered, instead of just me backing up the credentials (like I do today with a password manager).

With backup devices, whenever I upgrade or replace a device, I need to go to each of the 500+ online accounts and register the new device. This is much more work than a quick login to each site via my password manager (which can happen on-demand, only as I need to use the services).

Re: Bringing passkeys to Android and Chrome

#133

Earlier quoted context omitted.

Apple, on the other hand, has terrible problems with working with others that google does not. Apple will happily tell you that if you want grandma to have a whatever color text bubble, you should buy her an iPhone, to name a recent example, rather than adopt the standard everyone else is using. I bought a Macbook last holiday season and couldn't even set it up until my wife set up her iPhone on my account to activat…

> I bought a Macbook last holiday season and couldn't even set it up until my wife set up her iPhone on my account... I have no idea what you mean by this. You do not need, and have never needed, to own an iPhone to use an Apple computer. > I bought my wife a iWatch last week and briefly thought of getting myself one but you can't use it without an iPhone... This, on the other hand, makes a little more sense. The App…

What about all those ads for the cell iWatches that boast leaving the phone behind?

Re: Bringing passkeys to Android and Chrome

#134

Earlier quoted context omitted.

> but I can at least visualize Apple having the scale to do that. > Google on the other hand has a horrendous reputation for Neither are true nor false but definitely exaggerations. All you're doing is displaying personal biases by providing them with benefit-of-the-doubts. They too have a reputation for locking people out, and are well known for turning data over, but one that HN in gernal prefers to ignore.

> Neither are true nor false but definitely exaggerations. Google does not kill services. That does not happen. Google definitely does not deplatform people killing all their accounts and all their access. That also does not happen.

Apple absolutely did not abandon the Xserve platform after promising a professional and modern Unix experience. Google is definitely the only one with a penchant for mercy-killing unsuccessful products.

Re: Bringing passkeys to Android and Chrome

#135
post #133

Earlier quoted context omitted.

> I bought a Macbook last holiday season and couldn't even set it up until my wife set up her iPhone on my account... I have no idea what you mean by this. You do not need, and have never needed, to own an iPhone to use an Apple computer. > I bought my wife a iWatch last week and briefly thought of getting myself one but you can't use it without an iPhone... This, on the other hand, makes a little more sense. The App…

What about all those ads for the cell iWatches that boast leaving the phone behind?

The Apple Watch is designed to be tethered to the phone, even if just for configuration.

If you want to go on a hike while leaving your (distracting) phone behind, you can. Just don't expect 911 unless you have the GPS+cellular version.

Re: Bringing passkeys to Android and Chrome

#136
post #133

Earlier quoted context omitted.

> I bought a Macbook last holiday season and couldn't even set it up until my wife set up her iPhone on my account... I have no idea what you mean by this. You do not need, and have never needed, to own an iPhone to use an Apple computer. > I bought my wife a iWatch last week and briefly thought of getting myself one but you can't use it without an iPhone... This, on the other hand, makes a little more sense. The App…

What about all those ads for the cell iWatches that boast leaving the phone behind?

You need to have an iPhone in order to leave it behind.

Re: Bringing passkeys to Android and Chrome

#137
post #92

Earlier quoted context omitted.

because simple, easy-to-use ID lowers the barrier for demanding ID in more places and attacking anonymity. the easier we make it to demand id, the more people will demand it. wanna use a fake name/not divulge your identity? doing something politically sensitive where you may need some protection? just like your privacy? tough shit show your id or GTFO.

Shouldn't we instead solve the problem that you might "need some protection" because you're doing something political - instead of relying on security-through-obscurity which honestly doesn't even really work anymore, IDs or no IDs. There's so many other ways for governments to track people of interest these days.

i disagree with the assumption that it's a solvable problem. people remain fallible and the correct solution is to mitigate our downside by minimizing state power. not disagreeing with the idea that we also need to work on lots of other ways to reduce its power and ability to track people btw.

Re: Bringing passkeys to Android and Chrome

#138
post #133

Earlier quoted context omitted.

> I bought a Macbook last holiday season and couldn't even set it up until my wife set up her iPhone on my account... I have no idea what you mean by this. You do not need, and have never needed, to own an iPhone to use an Apple computer. > I bought my wife a iWatch last week and briefly thought of getting myself one but you can't use it without an iPhone... This, on the other hand, makes a little more sense. The App…

What about all those ads for the cell iWatches that boast leaving the phone behind?

The cellular version of the Apple Watch can perform a limited set of tasks -- like making phone calls, sending/receiving text messages, and playing music -- without a phone present. It still requires a phone for full functionality, and for setup.

Re: Bringing passkeys to Android and Chrome

#139
post #126

Earlier quoted context omitted.

At the risk of being pedantic, no. Apple Stores aren’t able or empowered to provide Apple ID support beyond what the public website based recovery workflows provide. I am sure someone will note that someone at an Apple Store has helped them reset an Apple ID password. What I mean is that Apple Store employees have neither procedure nor access to override Apple’s account system. You have to call support for assistance…

Eh. Pedantically; the Apple Store will at least try to help you, even if they’re not empowered to fix it they will guide you through the process until there is a resolution. It’s not as “you’re on your own” as some products I’ve owned.

This is key. That the Apple Store can't directly help you doesn't mean they won't direct you to the proper person (and possibly stay with you if possible & desired)

Re: Bringing passkeys to Android and Chrome

#140
post #70
post #40

Earlier quoted context omitted.

The entire third party auth push has turned into what may be one of the largest incumbent power grabs I have ever seen. Stuff like Google Amp or even App Store walled gardens pale in comparison. What drives me nuts is how little discussion of this I've seen. People don't even seem aware of the implications of it. It's being pushed hard as a boon to security, which it is in some cases, but at a cost that nobody is eve…

Compare this with status quo for users like my parents. They constantly forget their passwords and quail at screwing up the 2nd factor all the time. If they could just use their fingerprint/faceID to login (after initial registration on the device) they would be super happy. Rest of us should be happy there will be less exploits where people give up the keys to their kingdom by clicking on a random email.

Exactly what Google thinks: https://youtu.be/N7N4EC20-cM?t=15m36s

If you scroll back, they mention you have to protect everyone to be effective, i.e. high value target friends and family.

Post reply on HN