Live data from Hacker News

Passkeys: The beginning of the end of the password

blog.google

521–530 of 1001 posts

Re: Passkeys: The beginning of the end of the password

#521
post #294

The paragraph in the section, "What are passkeys?" tells me that they: are new, are easier, let me use biometrics, and are resistant to attacks. But, it doesn't tell me what passkeys actually are. Compare passkeys to traditional authentication factors. What's a password? A secret word or phrase that only you know. What are biometrics? Parts of your body that can help uniquely identify you, like your fingerprint or re…

Passwords will never be supplanted unless the new challenger can satisfy all of the following: * Easy to understand. (A password is just a word/phrase/string of characters only you know.) * Easy to use. (Using a password only requires remembering and typing it in when prompted.) * Convenient. (Only your ability to remember and type required. No other tools or gadgets required.) * Simple. (All of the above.) If someth…

Passkeys do all of this

* Easy to understand. Your device will just ask "sign in?"

* Easy to use. Your device will just ask "sign in?"

* Convenient. Nothing to remember, nothing to do

* Simple (all of the above)

Passkeys are/will-be way simpler than passwords for the majority of users

Re: Passkeys: The beginning of the end of the password

#522

Earlier quoted context omitted.

How is this different than a password manager with encrypted cloud backup? Your recourse if someone breaks passkeys is legal, not technical. Security must be a balance with functionality, and this is a huge improvement over passwords. (Tangentially, it would be great if we got cryptographic digital identity cards like Estonia has for signatures but that’s more of a long term goal) Cloud sync (encrypted!) is important…

You have the option to use a non cloud password sync method today. Best of all, that can sync a single password or private key across multiple vendors. This locking down inside bubbles really needs to go for me to want to use passkeys, I don't want to register 3 separate passkeys for each account I want to register 1 and sync them between my devices.

You’re not the target. Your average user who doesn’t even know what a password manager is or doesn’t want to use one is.

Re: Passkeys: The beginning of the end of the password

#523

I’m a Linux user. I don’t have an android/iOS/macOS/Windows machine. Is there a solution? Is this being used to push Linux users off the internet? Can I just fire up emulated Android and be ok? Am I screwed? Googling indicates I am, indeed, screwed. Pretty concerned about this future.

Passkey is an open standard and there exists FOSS clients which support it. We should try actually understanding and learning about what's going on instead of assuming that it's a Google conspiracy to kill Linux. (google contributes heavily to linux anyways?)

[deleted]

Re: Passkeys: The beginning of the end of the password

#524

Earlier quoted context omitted.

So it's like a private key but you can't access or manage it, as it's owned by Google/Apple/Microsoft? How convenient!

Passkey is an open standard, clients are not limited to Android or IOS devices. You can for example use a Yubikey, on a Linux desktop system, to authenticate to services implementing the "passkey" standard. Does Google own my Yubikey in some way that I'm unaware of? Nothing is owned by Google or Apple or Microsoft, there is no grand conspiracy trying to lock you into a platform. Try educating yourself before spreadin…

[deleted]

Re: Passkeys: The beginning of the end of the password

#525

I’m a Linux user. I don’t have an android/iOS/macOS/Windows machine. Is there a solution? Is this being used to push Linux users off the internet? Can I just fire up emulated Android and be ok? Am I screwed? Googling indicates I am, indeed, screwed. Pretty concerned about this future.

Passkey is an open standard and there exists FOSS clients which support it. We should try actually understanding and learning about what's going on instead of assuming that it's a Google conspiracy to kill Linux. (google contributes heavily to linux anyways?)

[deleted]

Re: Passkeys: The beginning of the end of the password

#526

I’m a Linux user. I don’t have an android/iOS/macOS/Windows machine. Is there a solution? Is this being used to push Linux users off the internet? Can I just fire up emulated Android and be ok? Am I screwed? Googling indicates I am, indeed, screwed. Pretty concerned about this future.

Passkey is an open standard and there exists FOSS clients which support it. We should try actually understanding and learning about what's going on instead of assuming that it's a Google conspiracy to kill Linux. (google contributes heavily to linux anyways?)

[deleted]

Re: Passkeys: The beginning of the end of the password

#527
post #179

Earlier quoted context omitted.

The solution, for you, is a cloud synced passkey manager, possibly a custodial one. A password manager with strong passwords is weaker than a password manager with passkeys, because passkeys use asymmetric crypto and passwords+2fa involve exchanging a shared secret over an insecure channel at some point (yes I'm considering 1-sided TLS an "insecure" channel here). Trust the security experts when they say passkeys are…

So in the event that i lost everything, i mean catastrophic, like my house burned to the ground with all my belongings, i have no kin nor "trust alternate people" configured for my account, my password manager requires my "synced in google/apple drive/cloud" passkey or my last known device, i can't retrieve it in anyway, how can i recover my account? Either have to prove that m me to my account provider, which essent…

Sure. The idea of authenticating a human based on something you know, passwords, is still useful and not going to die anytime soon. But it would be a much much safer world if you only had to remember one or two passwords than if you had to try and get passwords right for every service you use out there. A single password protecting a keychain full of passkeys is still better than reusing that same password on every single site. Hands down no argument. This is why passkeys exist. They are objectively a superior technology and you are objectively safer using them, as long as you can comfortably recover from disaster scenarios. The fact that you might choose to still use a password to get access to your passkeys is, well, up to you. You're free to take whatever posture makes most sense to you. Someone else might "trust alternate people" and another might keep a printed copy of all their passkeys in a bank vault. But whatever you choose as your preferred recovery/bootstrap method, using that to get you to a per-site passkey world makes you safer than what you're currently doing using symmetric keys everywhere.

Re: Passkeys: The beginning of the end of the password

#528

Earlier quoted context omitted.

So it's like a private key but you can't access or manage it, as it's owned by Google/Apple/Microsoft? How convenient!

Passkey is an open standard, clients are not limited to Android or IOS devices. You can for example use a Yubikey, on a Linux desktop system, to authenticate to services implementing the "passkey" standard. Does Google own my Yubikey in some way that I'm unaware of? Nothing is owned by Google or Apple or Microsoft, there is no grand conspiracy trying to lock you into a platform. Try educating yourself before spreadin…

[deleted]
Post reply on HN