Live data from Hacker News

Bringing passkeys to Android and Chrome

android-developers.googleblog.com

261–264 of 264 posts

Re: Bringing passkeys to Android and Chrome

#261

Earlier quoted context omitted.

> There's no privacy issue There is a real privacy issue if online services will now force you to store your "passwords" on a device - whether it be in your phone or a password manager.

The passkeys are stored in a Trusted Platform Module, and as far as I know, it is basically impregnable, even with access to the physical device.

That's irrelevant as the real issue is that if anyone gets access to your device, they can then get access to all your online accounts.

Re: Bringing passkeys to Android and Chrome

#262
post #209

Earlier quoted context omitted.

When I got my M1 MBP there was no way, that I could find, to set up the computer and login the first time without using an iPhone. I don't remember the exact phrasing it gave me, but the only way I could get the system set up was my wife logging out of her iPhone, and logging into it as me. I don't know if this is newer than your experience, or there was some trick to get past it, but I couldn't find one.

I have a M1 and M2 (Pro and Air, and non-M Pro and Air) and have never done this, and never seen it. I do not even have an Apple ID logged into any Mac laptop I have ever owned. You do not need an account or an iPhone, this makes no sense to me. Was this purchased new from a retail store?

Purchased new directly from Apple.

Re: Bringing passkeys to Android and Chrome

#263

Earlier quoted context omitted.

The passkeys are stored in a Trusted Platform Module, and as far as I know, it is basically impregnable, even with access to the physical device.

That's irrelevant as the real issue is that if anyone gets access to your device, they can then get access to all your online accounts.

Well, no, that is not right. Passkeys most definitely not available to someone who steals your phone.
Post reply on HN