Live data from Hacker News

Bringing passkeys to Android and Chrome

android-developers.googleblog.com

181–190 of 264 posts

Re: Bringing passkeys to Android and Chrome

#181

The thread here seems like a dumpster fire to me. Everyone here is worrying about lock-in to an open standard, so I want to clarify things. WebAuthn is an open standard. It's a way for you to prove to a website that you have a specific private key. There's no lock-in, because the key is portable (unless you don't want it to be). There's no privacy issue, because the key is unique per website. There's no security issu…

> If you don't like Google or Apple, use your favorite password manager.

Unless the service you are trying to use requires that you use a particular model of authenticator, which the service provider can enforce via attestation.

Re: Bringing passkeys to Android and Chrome

#183

The thread here seems like a dumpster fire to me. Everyone here is worrying about lock-in to an open standard, so I want to clarify things. WebAuthn is an open standard. It's a way for you to prove to a website that you have a specific private key. There's no lock-in, because the key is portable (unless you don't want it to be). There's no privacy issue, because the key is unique per website. There's no security issu…

> If you don't like Google or Apple, use your favorite password manager. Unless the service you are trying to use requires that you use a particular model of authenticator, which the service provider can enforce via attestation.

They can do this with SSO provided by third parties now.

Re: Bringing passkeys to Android and Chrome

#184

Earlier quoted context omitted.

> If you don't like Google or Apple, use your favorite password manager. Unless the service you are trying to use requires that you use a particular model of authenticator, which the service provider can enforce via attestation.

They can do this with SSO provided by third parties now.

Sure, but passkeys are meant to replace passwords, not SSO (although I won't complain if they do replace SSO).

Most services probably would not restrict you to just one model of authenticator, but it wouldn't surprise me at all to see a service require that the authenticator be backed by a secure element, in which case you could use a security key, a passkey, a TPM, et cetera, but not a password manager. I'd still take that over passwords, but I don't think everyone would.

Re: Bringing passkeys to Android and Chrome

#185

Earlier quoted context omitted.

It's not particularly surprising. Apple has a much better reputation at customer service than Google does – they have actual stores you can walk into. Now I'm not sure whether they can help you unlock your Apple ID if you prove to them that you're the owner of the account, but I can at least visualize Apple having the scale to do that. Google on the other hand has a horrendous reputation for locking out people out of…

Apple, on the other hand, has terrible problems with working with others that google does not. Apple will happily tell you that if you want grandma to have a whatever color text bubble, you should buy her an iPhone, to name a recent example, rather than adopt the standard everyone else is using. I bought a Macbook last holiday season and couldn't even set it up until my wife set up her iPhone on my account to activat…

My TV offered free Apple TV+. In order to sign in, I had to get a code sent to a laptop sitting far away. I assume they expected me to be carrying an iPhone, as no non-Apple device could provide the OTP. Using an Apple service is simply not worth the hassle.

Re: Bringing passkeys to Android and Chrome

#186
post #89

Earlier quoted context omitted.

Is it nanny-ish just because it makes it simpler for end users? Fairly certain most users are not interested in managing their own key sharing infrastructure. It's built on the same technology as FIDO keys, so if you want to take control of it yourself, just use a hardware key.

Exactly. Now, why are they doing it for free? Why take on a huge responsibility for no money, what do they get out of it?

If people use this instead of passwords, they get less compromised accounts on their services that they have to deal with.

Re: Bringing passkeys to Android and Chrome

#188
post #31

Interesting. I'm still struggling to see how this is better than just using a yubi/solo-key

At the very minimum, one undeniable technical advantage Passkeys have -- that they share with their foundation, WebAuthn -- is that Passkeys are unphishable.

That’s not a technical advantage over Yubikeys/SoloKeys, since they also use WebAuthn and are also unphishable.

Re: Bringing passkeys to Android and Chrome

#189
post #147
post #58

Earlier quoted context omitted.

Sure, but here's the deal with this. Even with Yubikeys it has always been recommended (as long as I've been involved in these types of discussions anyway) that you should have two of them. If you lose one you have one safely secured that can get you into any service you need to. This is my general stance on it as well, and one that I think I would still strongly recommend even in this new Passkeys era. That would co…

> If you lose one you have one safely secured that can get you into any service you need to. Even that is not good enough, by a longshot. This is so much worse than even regular passwords. It works for corporatiosn. Lost your key? Go to IT and generate a new one. It does not work for individuals.

If you don’t trust yourself to have backup keys, you use the Google or Apple ecosystem. As long as you can get back into your Google or iCloud account, you can get back into every other passkey-protected website. You can also use third-party “cloud” password managers if you prefer.

WebAuthn lets you dial the convenience/security tradeoff exactly however you prefer. I’ll be using hardware tokens, but I’ll be telling non-technical people to use their existing smartphones.

Re: Bringing passkeys to Android and Chrome

#190
post #31

Interesting. I'm still struggling to see how this is better than just using a yubi/solo-key

At the very minimum, one undeniable technical advantage Passkeys have -- that they share with their foundation, WebAuthn -- is that Passkeys are unphishable.

Don't all fido2 yubikeys support webauthn? They have the advantage that they can't be cloned/sync/etc. Might be an inconvenience for some but for me that's an advantage.
Post reply on HN