Live data from Hacker News

Passkeys: The beginning of the end of the password

blog.google

301–310 of 1001 posts

Re: Passkeys: The beginning of the end of the password

#301
post #5

How is this more secure? They say "with a fingerprint, a face scan or a screen lock PIN", but basically all phones let you fall back to PINs if you dont want to do face or fingerprints. Pins are flat out not secure - typically just 4 digits. Yeah its probably better than 80% of people having "password123", but it seems strictly worse than a password + password manager? Or at least just having proper 2FA.

>with a fingerprint, a face scan or a screen lock PIN I agree - not secure. And just a daily reminder that biometrics are usernames , they are not passwords. You can change a password, a lock, a key, you cannot change biometrics, and thus they should not be used for guarding sensitive info. The only use-case for biometrics is deanonymization, sold to you under the auspices of security, primarily used for corporate su…

> you cannot change biometrics

Bodies are not invulnerable to damage. You can absolutely change your "biometrics", you just probably wouldn't _want_ to.

Re: Passkeys: The beginning of the end of the password

#302
post #294

The paragraph in the section, "What are passkeys?" tells me that they: are new, are easier, let me use biometrics, and are resistant to attacks. But, it doesn't tell me what passkeys actually are. Compare passkeys to traditional authentication factors. What's a password? A secret word or phrase that only you know. What are biometrics? Parts of your body that can help uniquely identify you, like your fingerprint or re…

Thank you. I've been trying to figure out what they hell they are and have been unsuccessful. I thought it was just me.

This goes into more detail: https://developers.google.com/identity/passkeys

As far as I can tell: it's a system of private keys stored on devices, in order to transmit a key you also need to unlock a device (e.g. phone) with some other method like a PIN or fingerprint/face scan. Combine those two things and it means a would-be hacker would need both the physical device as well as the local authentication for that device (PIN or biometrics).

Re: Passkeys: The beginning of the end of the password

#303
post #79

Those passkeys are either insecure or unreliable. Let me explain: Those passkeys are asymmetric cryptographic keypairs where the private key is securely stored on a device, unlockable (for use, not reading) only by convincing your devices security processor to do so by pin/fingerprint/pattern. Which in itself can be secure, given you do trust that magic security processor (which you shouldn't, see yesterday's news fo…

As an administrator, I hear you, but we have to adapt. Passwords are awful. On the whole, the effort and energy spent training people on passwords, battling phishing, dealing with password managers, cleaning up from breaches, and more… passwords can't die soon enough. FWIW, asymmetric PKI is technically mature and relatively easy to implement in most applications (without "vendor lock-in", I might add to comments upt…

I'm looking forward to such glory days. Right now, however, none of the solutions available are ones that I could live with if I had to use them for everything. For one or two very sensitive things, sure, but for everything? It's less of a pain to use long, random passwords.

Re: Passkeys: The beginning of the end of the password

#304
Users pay a subtle price for the perceived convenience of passkeys when it's time to migrate to another platform.

Before, you could just sign in to your password manager on the new platform, and get a 2FA prompt the first time you sign in to any particular site (so you're manually entering one additional factor per site). With passkeys, you have to do account recovery, so you have to manually provide two factors per site. That translates to hours of cumulative extra work.

It's an opportunity to increase platform stickiness, backed by a flimsy security excuse. Nobody using a password manager is getting their accounts hacked unless the vendor is breached or they have malware on their system. Passkeys don't help in either scenario. And the UX isn't materially better than the built-in password manager, though I guess that's a matter of opinion.

Re: Passkeys: The beginning of the end of the password

#305
post #294

The paragraph in the section, "What are passkeys?" tells me that they: are new, are easier, let me use biometrics, and are resistant to attacks. But, it doesn't tell me what passkeys actually are. Compare passkeys to traditional authentication factors. What's a password? A secret word or phrase that only you know. What are biometrics? Parts of your body that can help uniquely identify you, like your fingerprint or re…

From what I can find the word passkey is just a synonym for password. So yes, none of this makes any sense.

Re: Passkeys: The beginning of the end of the password

#307
post #294

The paragraph in the section, "What are passkeys?" tells me that they: are new, are easier, let me use biometrics, and are resistant to attacks. But, it doesn't tell me what passkeys actually are. Compare passkeys to traditional authentication factors. What's a password? A secret word or phrase that only you know. What are biometrics? Parts of your body that can help uniquely identify you, like your fingerprint or re…

I suspect that one screen comic or a 20 second video could explain it. Instead they give us a wall of text that even technical people can't understand.

Re: Passkeys: The beginning of the end of the password

#308

Earlier quoted context omitted.

Thank you. I've been trying to figure out what they hell they are and have been unsuccessful. I thought it was just me.

This goes into more detail: https://developers.google.com/identity/passkeys As far as I can tell: it's a system of private keys stored on devices, in order to transmit a key you also need to unlock a device (e.g. phone) with some other method like a PIN or fingerprint/face scan. Combine those two things and it means a would-be hacker would need both the physical device as well as the local authentication for that dev…

Can it be uses on both Android and iOS? What about desktop machines with no fingerprint sensor or faceID?

What happens if user loses the only device on which passkey was enrolled?

Re: Passkeys: The beginning of the end of the password

#309

Came to HN today figuring there would be a thread about this, after getting an email about it from Google themselves, riddled with things causing me to wonder if the message was spoofed: 1. "Dear User" -- other emails I've gotten from Google say "Hello" or "Hi " or have no salutation at all. 2. The main section begins with "Passkey support will be integrated because they’re easier to use, and safer than most other fo…

>I'm not really a huge stickler for grammar, but I've seen countless "how to spot phishing" guides specifically suggesting that we look for grammatical mistakes, as they're specifically included for purposes of improving the ratio of hooked phish to eaten phish, so it follows that messages which aren't phishing really ought to use correct grammar!

Lily Tomlin & co. could have made this[0] for Google today, instead of for AT&T ~50 years ago.

The dynamics haven't changed, just the corporations involved. And more's the pity.

[0] https://vimeo.com/355556831

Re: Passkeys: The beginning of the end of the password

#310
post #294

The paragraph in the section, "What are passkeys?" tells me that they: are new, are easier, let me use biometrics, and are resistant to attacks. But, it doesn't tell me what passkeys actually are. Compare passkeys to traditional authentication factors. What's a password? A secret word or phrase that only you know. What are biometrics? Parts of your body that can help uniquely identify you, like your fingerprint or re…

It’s a password that Google controls so when they incorrectly ban you from their services you lose access to literally everything.

Or if you drop your phone in a lake you’re out of luck too.

Post reply on HN