How do you back them up locally?
Bringing passkeys to Android and Chrome
81–90 of 264 posts
Re: Bringing passkeys to Android and Chrome
#82Earlier quoted context omitted.
it is your key, it lives on your device (and is synced across devices using your cloud account if you so choose)
And BigTech's cloud (who will have no problem sharing it with the authorities). And when all your keys are on the device, it also becomes a lot easier for the government to access all your internet accounts by getting access to the device.
This is the same threat model as password managers, which are generally approved of on HN.
Re: Bringing passkeys to Android and Chrome
#83Earlier quoted context omitted.
They way keys are managed means that the passkey material is never available to Google, Apple, etc
Are the keys encrypted with a key derived from a master password? Does the decryption only occur on the user's device? Is this master password not reused for the account or has account authentication been changed to use a cryptographic proof produced on-device? If the key is ever decrypted on vendor's servers, everything else is theater. And this is all of course also excluding auto-updating vendor-supplied authentic…
From a post linked in the article:
> Passkeys in the Google Password Manager are always end-to-end encrypted: When a passkey is backed up, its private key is uploaded only in its encrypted form using an encryption key that is only accessible on the user's own devices. This protects passkeys against Google itself, or e.g. a malicious attacker inside Google. Without access to the private key, such an attacker cannot use the passkey to sign in to its corresponding online account.
> Additionally, passkey private keys are encrypted at rest on the user's devices, with a hardware-protected encryption key.
> Creating or using passkeys stored in the Google Password Manager requires a screen lock to be set up. This prevents others from using a passkey even if they have access to the user's device, but is also necessary to facilitate the end-to-end encryption and safe recovery in the case of device loss.
Re: Bringing passkeys to Android and Chrome
#84Earlier quoted context omitted.
it is your key, it lives on your device (and is synced across devices using your cloud account if you so choose)
It's a nanny-ish third-party in the middle. That increases convenience, but also greatly increases your threat surface.
It's built on the same technology as FIDO keys, so if you want to take control of it yourself, just use a hardware key.
Re: Bringing passkeys to Android and Chrome
#85Earlier quoted context omitted.
it is your key, it lives on your device (and is synced across devices using your cloud account if you so choose)
It's a nanny-ish third-party in the middle. That increases convenience, but also greatly increases your threat surface.
Like this isn't particularly different from me backing up my (encrypted) disk which contains my (further encrypted) keys to the cloud somewhere.
Re: Bringing passkeys to Android and Chrome
#86Earlier quoted context omitted.
It's a nanny-ish third-party in the middle. That increases convenience, but also greatly increases your threat surface.
Be precise: what threat is added here that is added by a third party holding encrypted keys? Like this isn't particularly different from me backing up my (encrypted) disk which contains my (further encrypted) keys to the cloud somewhere.
That's kind of the point. We have to trust that Google won't mess things up and we have essentially no recourse if they do.
Re: Bringing passkeys to Android and Chrome
#87> Passkeys on users’ phones and computers are backed up and synced through the cloud to prevent lockouts in the case of device loss. How do you back them up locally?
Keys for me, but not for thee!
Re: Bringing passkeys to Android and Chrome
#88Earlier quoted context omitted.
It's a nanny-ish third-party in the middle. That increases convenience, but also greatly increases your threat surface.
A nanny-ish third party, as opposed to Coinbase, Binance, et al?
Re: Bringing passkeys to Android and Chrome
#89Earlier quoted context omitted.
It's a nanny-ish third-party in the middle. That increases convenience, but also greatly increases your threat surface.
Is it nanny-ish just because it makes it simpler for end users? Fairly certain most users are not interested in managing their own key sharing infrastructure. It's built on the same technology as FIDO keys, so if you want to take control of it yourself, just use a hardware key.
Now, why are they doing it for free? Why take on a huge responsibility for no money, what do they get out of it?
Re: Bringing passkeys to Android and Chrome
#90Earlier quoted context omitted.
Be precise: what threat is added here that is added by a third party holding encrypted keys? Like this isn't particularly different from me backing up my (encrypted) disk which contains my (further encrypted) keys to the cloud somewhere.
I don't know, and you don't either, because I'm willing to bet that "Google" is smarter than both of us. That's kind of the point. We have to trust that Google won't mess things up and we have essentially no recourse if they do.
It isn't fair to presume that everyone shares your lack of knowlege on a subject, and it's simply incorrect to presume that because you don't understand something that it cannot be safe or reliable.