Live data from Hacker News

Passkeys are now enabled by default for Google users

blog.google

681–684 of 684 posts

Re: Passkeys are now enabled by default for Google users

#681

Earlier quoted context omitted.

There are workarounds, but that doesn't mean that passkeys is a half-baked technology. The real, simple solution would be a way to write down the passkey, similar to an SSH private key.

> The real, simple solution would be a way to write down the passkey, similar to an SSH private key. Except shorter for convenience. Something you could even memorize.

Except that that thing you memorized gets transferred across the wire as part of the authentication process, leading to all sorts of places where it could be intercepted. Passkeys don’t leave the device, outside of backups and synchronization. Thats a way lower attack surface.

Re: Passkeys are now enabled by default for Google users

#682

As others have pointed out, cryptographic authentication is very hard to bootstrap if you simply loose your device. Just last month my missus cracked the glass of her iPhone. Apple repaired it under AppleCare, which is great… except … that they didn’t tell her that the “glass repair” entails them replacing the guts of the phone and wiping it in the process. Apple iPhone backups don’t contain cryptographic secrets lik…

Add to that many web sites now make it a point of pride that they employ no humans in support and will not do anything to help you get back into your account if you are locked out (Google, Meta etc).

That’s a great reason not to use those services.

Re: Passkeys are now enabled by default for Google users

#683

Earlier quoted context omitted.

I like this idea of authenticating yourself by typing things in.

Seems like it'd be a little annoying to pick different things to type in for each service, maybe we could manage those, but still have a primary 'thing to type in' to the 'thing to type in' manager, which would then handle choosing and typing the various things into the various authentication boxes.

Even better, that manager could be used to log you in cryptographically, so you’re secret never leaves the device for authentication purposes.

https://bitwarden.com/passwordless-passkeys/

Re: Passkeys are now enabled by default for Google users

#684
post #201

Earlier quoted context omitted.

Passkeys are a new technology and everyone - including users, service providers, and organizations - will take time to learn and adapt. In this interim period the recommended approach is to provide passkeys as an alternative to whatever is already offered. This is the approach that Google and many other service providers are taking. That said, you are bringing up the right questions on the general topic of account re…

But you can set family members/significant others/etc as possible recovery mechanisms! This seems like a really workable solution that I don’t see people discussing in this thread?

Aren't people lonelier than ever, have fewer friends than ever, live alone more than ever, fall out with their families more than ever?
Post reply on HN