Live data from Hacker News

Passkeys: The beginning of the end of the password

blog.google

451–460 of 1001 posts

Re: Passkeys: The beginning of the end of the password

#451
post #357
post #294

The paragraph in the section, "What are passkeys?" tells me that they: are new, are easier, let me use biometrics, and are resistant to attacks. But, it doesn't tell me what passkeys actually are. Compare passkeys to traditional authentication factors. What's a password? A secret word or phrase that only you know. What are biometrics? Parts of your body that can help uniquely identify you, like your fingerprint or re…

You need to click on the link that is in the post: https://blog.google/technology/safety-security/one-step-clos... > Instead, your phone will store a FIDO credential called a passkey which is used to unlock your online account. The passkey makes signing in far more secure, as it’s based on public key cryptography and is only shown to your online account when you unlock your phone. It looks like a token stored on your…

> You need to click on the link that is in the post

So, a communication failure straight away. Does not bode well.

Re: Passkeys: The beginning of the end of the password

#452

Ignorant question: Are Passkeys, at some level of abstraction, permanently replacing "something you know" (password) with "something you have"? If I am in some kind of calamity (dropped my phone, got robbed, etc), and I come to a friendly person's house, it sounds to me like I simply would not be able to login to potentially critical services, no matter how much I know , because I don't have anything (the device that…

> Are Passkeys, at some level of abstraction, permanently replacing "something you know" (password) with "something you have"?

Sometimes. The authenticator you choose to use sets the policy of what makes a valid authentication. So if your authenticator is "Google Password Manager", it is whatever steps you need to get into your Google account and enable the password manager.

If you do not have the infrastructure to get into that account (say, you have a SMS fallback and your phone is dead), you'll be locked out.

If your authenticator is say a hardware security key, then most likely losing that key means you have no backups.

Even in this case, you can have more than one mechanism to recover access or to prove who you are (even if it is a second hardware key at home in the safe).

Re: Passkeys: The beginning of the end of the password

#453
post #357

Earlier quoted context omitted.

You need to click on the link that is in the post: https://blog.google/technology/safety-security/one-step-clos... > Instead, your phone will store a FIDO credential called a passkey which is used to unlock your online account. The passkey makes signing in far more secure, as it’s based on public key cryptography and is only shown to your online account when you unlock your phone. It looks like a token stored on your…

So it's like a private key but you can't access or manage it, as it's owned by Google/Apple/Microsoft? How convenient!

Passkey is an open standard, clients are not limited to Android or IOS devices.

You can for example use a Yubikey, on a Linux desktop system, to authenticate to services implementing the "passkey" standard. Does Google own my Yubikey in some way that I'm unaware of?

Nothing is owned by Google or Apple or Microsoft, there is no grand conspiracy trying to lock you into a platform.

Try educating yourself before spreading misinformation, and before assuming that everything is an Evil Conspiracy by Big Tech.

Re: Passkeys: The beginning of the end of the password

#454
post #359

Earlier quoted context omitted.

I like to explain it like this: If you use a password manager today, then you're already essentially using something you have, because you need to be in possession of your login database to retrieve passwords, and nobody can remember that in their head. Passkeys is a formalization of the idea that you should be using a password manager where all the passwords are random uncrackable 32 character strings, and if we add…

> The generalized solution to this is allowing 3rd parties to be your passkey provider, so that you can choose how your passkeys are stored The password manager I use has no cloud component (which is why I chose it), and addresses this by allowing me to export my password collection to an encrypted backup file. Would this be a thing that the passkey folks would be OK with? That would ease a lot of my hesitation.

> Would this be a thing that the passkey folks would be OK with? That would ease a lot of my hesitation.

I mean, I don't _like_ it (if I'm a passkey folk) as a widespread feature. I suspect users may be tricked into giving away the keys to the kingdom.

However, these are generally just API, there are open source projects for security keys, and having an option to hold down a button on insertion to have it turned into a filesystem with a CSV file sounds kinda neat as a bit of hackery.

There are several third party software implementations, such as those built on top of existing password managers which have pre-existing password export/import functionality and tend to document their data vault formats (or have them torn apart in reverse engineering). I suspect this will happen if it hasn't already - it would be better as a command-line tool and not a button with a wordy pop-up.

My hope is that we have independent certifications for relying parties to rely upon, but lack of certification won't lead to such a bespoke implementation being rejected by anyone. Instead, some sites may ask for you to continue using additional factors since they don't understand if your passkey meets their requirements.

Re: Passkeys: The beginning of the end of the password

#456
post #294

The paragraph in the section, "What are passkeys?" tells me that they: are new, are easier, let me use biometrics, and are resistant to attacks. But, it doesn't tell me what passkeys actually are. Compare passkeys to traditional authentication factors. What's a password? A secret word or phrase that only you know. What are biometrics? Parts of your body that can help uniquely identify you, like your fingerprint or re…

i think you underestimate how many users want to just be signed in to their account, and don't really give a damn about security in any way. they see a password as an inconvenient impediment, and if they could get rid of it tbat would be fine.

keeping your data secure is google's job, not the user's. if google stops asking for a password, that's going to make people happy and they're not going to ask a lot of questions about why.

Re: Passkeys: The beginning of the end of the password

#457

Argh. Passwords are amazing. I loathe many of the attempts at replacing them simply because the _average_ user has proven to be unable to manage them. The three factors of authentication are a thing because they all protect against somewhat orthogonal threat vectors. Possession "have" is nice because it binds the authentication to a single thing in the real world (as opposed to some digital thing that can be copied e…

"Personal opinion" hat on:

multiple factors do not provide perceived user benefit. They benefit the party who is providing service and exposed to risk.

The old Battle.net authenticator made it harder for my account to get hacked, sure. But I had a process, involving real people behind the scenes at Blizzard, to recover from that hack.

They didn't create the authenticator as a measure of altruism to users; they created it because hacks are expensive. This is why they would regularly reward users for enabling the authenticator with various items/DLC.

Now the reality is that if I get hacked multiple times, they may refuse to restore my account. They might not be able to restore my account with available information, or it might take ages due to a large scale attack (such as someone managing to deploy a key logger via zero-day browser exploit, if we are speaking to personal experience).

Services have good reason to not trust users to have good password hygiene - most do not, and breach lists only go so far to help alleviate the problem. SMS is expensive, but even sites with lower security needs use it because the alternative of recovering user accounts is more expensive.

> All factor-types can work in ways that complement eachother. Removing or at least weakening passwords is not a good way forward, we need to work on fusing all the factor-types jnto a single strong 3-factor auth.

This is likely not going to happen for anything outside of government use cases.

Biometrics on most consumer hardware are a "shortcut" for a cached knowledge factor, like a device unlock PIN on boot. They cache the knowledge factor because entering passwords constantly is a lousy experience. Likewise, changing a device biometric to match other people can be done with just the knowledge and device possession factors.

Maybe one day we will have embedded neural hardware which will transparently meet all three factors, or maybe there will be really clever solutions with all-day VR hardware, but today's consumer hardware doesn't support three factors, because the biometric factor is just an extension of the knowledge one.

Re: Passkeys: The beginning of the end of the password

#459
post #5

How is this more secure? They say "with a fingerprint, a face scan or a screen lock PIN", but basically all phones let you fall back to PINs if you dont want to do face or fingerprints. Pins are flat out not secure - typically just 4 digits. Yeah its probably better than 80% of people having "password123", but it seems strictly worse than a password + password manager? Or at least just having proper 2FA.

> it seems strictly worse than a password + password manager

Your password manager is likely the exact same thing. The underlying implementation of this is typically a system or third party password manager which added a public key-based credential type for sites. For an Android phone, this is Google Password Manager by default. For iOS, it is iCloud Keychain. Third parties like Dashlane and 1Password have indicated support for passkeys.

I would have thought your interpretation would be that this was strictly better. Even if the credential database leaks for a site, the attacker can't do anything with it - all they have is a public key, specific to that one site.

> Or at least just having proper 2FA.

If I use my android phone to log into a website, I have done 2FA. I have physical possession of my phone, and have used a gesture, PIN or biometric to confirm who I am.

The difference is in the password case, the website has no idea that I did that - all they saw is the password. With a passkey, it is possible that a site would recognize that I did a stronger, multi-factor authentication.

This may have varying strengths as a physical factor - say, provisioned database of credentials onto a device using MFA vs a FIPS-certified security key fob, but I would still argue it is "proper" 2FA.

Re: Passkeys: The beginning of the end of the password

#460

Ignorant question: Are Passkeys, at some level of abstraction, permanently replacing "something you know" (password) with "something you have"? If I am in some kind of calamity (dropped my phone, got robbed, etc), and I come to a friendly person's house, it sounds to me like I simply would not be able to login to potentially critical services, no matter how much I know , because I don't have anything (the device that…

This is my worry, but you now you just have to make sure you can access your keychain.

Test your keychain access today, “lose your devices” and see if you can still get all your keys through other methods. This is especially important with 2FA.

It is true that you cannot probably access your password without a new “owned” device though, gone are the days where you can hop onto a fresh device and type in your password of your email provider.

Post reply on HN