And what happens if your Google account that these keys are tied to is locked/revoked for a nebulous ToS violation?
Bringing passkeys to Android and Chrome
131–140 of 264 posts
Re: Bringing passkeys to Android and Chrome
#132Passkeys sound like another way for companies like Google and Apple to lock you into their walled garden. Having each walled garden randomly generating a key for every single domain instead of using the actual domain name as part of the key is a great way to lock regular people into their respective ecosystems.
Seems like you wouldn't want to share passkeys for the same reasons you don't normally want to share passwords? Instead, each website that accepts passkeys should allow you to register multiple devices and probably print out backup codes as well (for the especially important accounts). If there's no reason to migrate anything then lock-in is irrelevant. Just add more login methods so that when you lose some, you have…
With backup devices, whenever I upgrade or replace a device, I need to go to each of the 500+ online accounts and register the new device. This is much more work than a quick login to each site via my password manager (which can happen on-demand, only as I need to use the services).
Re: Bringing passkeys to Android and Chrome
#133Earlier quoted context omitted.
Apple, on the other hand, has terrible problems with working with others that google does not. Apple will happily tell you that if you want grandma to have a whatever color text bubble, you should buy her an iPhone, to name a recent example, rather than adopt the standard everyone else is using. I bought a Macbook last holiday season and couldn't even set it up until my wife set up her iPhone on my account to activat…
> I bought a Macbook last holiday season and couldn't even set it up until my wife set up her iPhone on my account... I have no idea what you mean by this. You do not need, and have never needed, to own an iPhone to use an Apple computer. > I bought my wife a iWatch last week and briefly thought of getting myself one but you can't use it without an iPhone... This, on the other hand, makes a little more sense. The App…
Re: Bringing passkeys to Android and Chrome
#134Earlier quoted context omitted.
> but I can at least visualize Apple having the scale to do that. > Google on the other hand has a horrendous reputation for Neither are true nor false but definitely exaggerations. All you're doing is displaying personal biases by providing them with benefit-of-the-doubts. They too have a reputation for locking people out, and are well known for turning data over, but one that HN in gernal prefers to ignore.
> Neither are true nor false but definitely exaggerations. Google does not kill services. That does not happen. Google definitely does not deplatform people killing all their accounts and all their access. That also does not happen.
Re: Bringing passkeys to Android and Chrome
#135Earlier quoted context omitted.
> I bought a Macbook last holiday season and couldn't even set it up until my wife set up her iPhone on my account... I have no idea what you mean by this. You do not need, and have never needed, to own an iPhone to use an Apple computer. > I bought my wife a iWatch last week and briefly thought of getting myself one but you can't use it without an iPhone... This, on the other hand, makes a little more sense. The App…
What about all those ads for the cell iWatches that boast leaving the phone behind?
If you want to go on a hike while leaving your (distracting) phone behind, you can. Just don't expect 911 unless you have the GPS+cellular version.
Re: Bringing passkeys to Android and Chrome
#136Earlier quoted context omitted.
> I bought a Macbook last holiday season and couldn't even set it up until my wife set up her iPhone on my account... I have no idea what you mean by this. You do not need, and have never needed, to own an iPhone to use an Apple computer. > I bought my wife a iWatch last week and briefly thought of getting myself one but you can't use it without an iPhone... This, on the other hand, makes a little more sense. The App…
What about all those ads for the cell iWatches that boast leaving the phone behind?
Re: Bringing passkeys to Android and Chrome
#137Earlier quoted context omitted.
because simple, easy-to-use ID lowers the barrier for demanding ID in more places and attacking anonymity. the easier we make it to demand id, the more people will demand it. wanna use a fake name/not divulge your identity? doing something politically sensitive where you may need some protection? just like your privacy? tough shit show your id or GTFO.
Shouldn't we instead solve the problem that you might "need some protection" because you're doing something political - instead of relying on security-through-obscurity which honestly doesn't even really work anymore, IDs or no IDs. There's so many other ways for governments to track people of interest these days.
Re: Bringing passkeys to Android and Chrome
#138Earlier quoted context omitted.
> I bought a Macbook last holiday season and couldn't even set it up until my wife set up her iPhone on my account... I have no idea what you mean by this. You do not need, and have never needed, to own an iPhone to use an Apple computer. > I bought my wife a iWatch last week and briefly thought of getting myself one but you can't use it without an iPhone... This, on the other hand, makes a little more sense. The App…
What about all those ads for the cell iWatches that boast leaving the phone behind?
Re: Bringing passkeys to Android and Chrome
#139Earlier quoted context omitted.
At the risk of being pedantic, no. Apple Stores aren’t able or empowered to provide Apple ID support beyond what the public website based recovery workflows provide. I am sure someone will note that someone at an Apple Store has helped them reset an Apple ID password. What I mean is that Apple Store employees have neither procedure nor access to override Apple’s account system. You have to call support for assistance…
Eh. Pedantically; the Apple Store will at least try to help you, even if they’re not empowered to fix it they will guide you through the process until there is a resolution. It’s not as “you’re on your own” as some products I’ve owned.
Re: Bringing passkeys to Android and Chrome
#140Earlier quoted context omitted.
The entire third party auth push has turned into what may be one of the largest incumbent power grabs I have ever seen. Stuff like Google Amp or even App Store walled gardens pale in comparison. What drives me nuts is how little discussion of this I've seen. People don't even seem aware of the implications of it. It's being pushed hard as a boon to security, which it is in some cases, but at a cost that nobody is eve…
Compare this with status quo for users like my parents. They constantly forget their passwords and quail at screwing up the 2nd factor all the time. If they could just use their fingerprint/faceID to login (after initial registration on the device) they would be super happy. Rest of us should be happy there will be less exploits where people give up the keys to their kingdom by clicking on a random email.
If you scroll back, they mention you have to protect everyone to be effective, i.e. high value target friends and family.