Live data from Hacker News

Bringing passkeys to Android and Chrome

android-developers.googleblog.com

81–90 of 264 posts

Re: Bringing passkeys to Android and Chrome

#82

Earlier quoted context omitted.

it is your key, it lives on your device (and is synced across devices using your cloud account if you so choose)

And BigTech's cloud (who will have no problem sharing it with the authorities). And when all your keys are on the device, it also becomes a lot easier for the government to access all your internet accounts by getting access to the device.

They're end-to-end encrypted. Did you read the article?

This is the same threat model as password managers, which are generally approved of on HN.

Re: Bringing passkeys to Android and Chrome

#83
post #30

Earlier quoted context omitted.

They way keys are managed means that the passkey material is never available to Google, Apple, etc

Are the keys encrypted with a key derived from a master password? Does the decryption only occur on the user's device? Is this master password not reused for the account or has account authentication been changed to use a cryptographic proof produced on-device? If the key is ever decrypted on vendor's servers, everything else is theater. And this is all of course also excluding auto-updating vendor-supplied authentic…

tl;dr: Yes, and further they're only decrypted using the secure chip on the device, so the vendor supplied authentication firmware can't be updated without user interaction/approval.

From a post linked in the article:

> Passkeys in the Google Password Manager are always end-to-end encrypted: When a passkey is backed up, its private key is uploaded only in its encrypted form using an encryption key that is only accessible on the user's own devices. This protects passkeys against Google itself, or e.g. a malicious attacker inside Google. Without access to the private key, such an attacker cannot use the passkey to sign in to its corresponding online account.

> Additionally, passkey private keys are encrypted at rest on the user's devices, with a hardware-protected encryption key.

> Creating or using passkeys stored in the Google Password Manager requires a screen lock to be set up. This prevents others from using a passkey even if they have access to the user's device, but is also necessary to facilitate the end-to-end encryption and safe recovery in the case of device loss.

Re: Bringing passkeys to Android and Chrome

#84
post #48

Earlier quoted context omitted.

it is your key, it lives on your device (and is synced across devices using your cloud account if you so choose)

It's a nanny-ish third-party in the middle. That increases convenience, but also greatly increases your threat surface.

Is it nanny-ish just because it makes it simpler for end users? Fairly certain most users are not interested in managing their own key sharing infrastructure.

It's built on the same technology as FIDO keys, so if you want to take control of it yourself, just use a hardware key.

Re: Bringing passkeys to Android and Chrome

#85
post #48

Earlier quoted context omitted.

it is your key, it lives on your device (and is synced across devices using your cloud account if you so choose)

It's a nanny-ish third-party in the middle. That increases convenience, but also greatly increases your threat surface.

Be precise: what threat is added here that is added by a third party holding encrypted keys?

Like this isn't particularly different from me backing up my (encrypted) disk which contains my (further encrypted) keys to the cloud somewhere.

Re: Bringing passkeys to Android and Chrome

#86
post #48

Earlier quoted context omitted.

It's a nanny-ish third-party in the middle. That increases convenience, but also greatly increases your threat surface.

Be precise: what threat is added here that is added by a third party holding encrypted keys? Like this isn't particularly different from me backing up my (encrypted) disk which contains my (further encrypted) keys to the cloud somewhere.

I don't know, and you don't either, because I'm willing to bet that "Google" is smarter than both of us.

That's kind of the point. We have to trust that Google won't mess things up and we have essentially no recourse if they do.

Re: Bringing passkeys to Android and Chrome

#87

> Passkeys on users’ phones and computers are backed up and synced through the cloud to prevent lockouts in the case of device loss. How do you back them up locally?

It seems to be the only question they are unwilling to answer.

Keys for me, but not for thee!

Re: Bringing passkeys to Android and Chrome

#88
post #48

Earlier quoted context omitted.

It's a nanny-ish third-party in the middle. That increases convenience, but also greatly increases your threat surface.

A nanny-ish third party, as opposed to Coinbase, Binance, et al?

No, those are the same thing. The "not your keys" thing in crypto is exactly the reason they tell you NOT to store your crypto with e.g. Coinbase/Binance. Just use them as on/off ramps, but have your own wallet.

Re: Bringing passkeys to Android and Chrome

#89
post #48

Earlier quoted context omitted.

It's a nanny-ish third-party in the middle. That increases convenience, but also greatly increases your threat surface.

Is it nanny-ish just because it makes it simpler for end users? Fairly certain most users are not interested in managing their own key sharing infrastructure. It's built on the same technology as FIDO keys, so if you want to take control of it yourself, just use a hardware key.

Exactly.

Now, why are they doing it for free? Why take on a huge responsibility for no money, what do they get out of it?

Re: Bringing passkeys to Android and Chrome

#90
post #86

Earlier quoted context omitted.

Be precise: what threat is added here that is added by a third party holding encrypted keys? Like this isn't particularly different from me backing up my (encrypted) disk which contains my (further encrypted) keys to the cloud somewhere.

I don't know, and you don't either, because I'm willing to bet that "Google" is smarter than both of us. That's kind of the point. We have to trust that Google won't mess things up and we have essentially no recourse if they do.

I'm unclear on what you think they could do. Is your idea here that Google is so smart that they can break end to end encryption? If so, we've got bigger problems.

It isn't fair to presume that everyone shares your lack of knowlege on a subject, and it's simply incorrect to presume that because you don't understand something that it cannot be safe or reliable.

Post reply on HN