15 ms·
Google Introduces Passkey Authentication
- hoppyhoppy2 3y agoRelated discussion yesterday at https://news.ycombinator.com/item?id=35801392 https://news.ycombinator.com/item?id=35801392
- judge2020 3y agoHowever, this is definitely a better article and clears up a lot of peoples' misconceptions present in that HN thread.
- madjam002 3y agoYet they still don't have a way to disable the 2FA prompt offered in the Gmail app (called "Google prompt"). It's a shame that you can add hardware security keys to your Google account and all of that can be bypassed just by pressing "approve" in the Gmail app when you're trying to login. The attack vector that I'm thinking of here is your phone being stolen while in public while unlocked, it doesn't even prompt for further biometrics when approving a login from the app.
- judge2020 3y agohttps://landing.google.com/advancedprotection/ https://landing.google.com/advancedprotection/ AFAIK this removes the ability to use a phone prompt as 2fa.
- madjam002 3y agoAdvanced Protection is nice but practically a non starter or very difficult in a lot of situations, e.g if you're travelling and all of your security keys get stolen and your backup security key is half way across the globe, you'll wish you had 2FA backup codes then.
- toomuchtodo 3y agoI have a trusted family member who maintains a copy of all of my recovery codes. In event of disaster, I call and provide a previously shared pass phrase, and recovery codes will be provided. Something to consider depending on your daily driver threat model and tail risk considerations. (frequent international travel while having strong opsec)
- madjam002 3y agoBut if you enable Advanced Protection then recovery/backup codes are disabled right? (Maybe I’m wrong) So the only option to have recovery codes available is to not used advanced protection and then have this “Google Prompt” forced on you, which I’d like to disable as it is another physical attack vector which is undesirable especially when travelling.
- remus 3y ago> Advanced Protection is nice but practically a non starter or very difficult in a lot of situations, e.g if you're travelling and all of your security keys get stolen and your backup security key is half way across the globe, you'll wish you had 2FA backup codes then. All security is a trade off. For a good chunk of people that is a rare enough occurrence that it is a good trade off for them.
- madjam002 3y agoYeah for sure, which is why I’m not fussed about not being able to use Advanced Protection because I don’t fit in with their target audience. But I do wish that people on standard accounts could just disable their forced “Google Prompt” authentication method and just use their own 2FA security keys with fallback to backup codes.
- icf80 3y agoSkip password when possible You’ll be able to sign in securely with just a passkey or device prompt.
- lxgr 3y ago> Yet they still don't have a way to disable the 2FA prompt offered in the Gmail app (called "Google prompt"). There used to be a way to intentionally (after 2FA) add or remove devices to "Google prompt". These days, it just seems to be any device I'm logged in to, sadly.
- explodingwaffle 3y agoYep. I complained about that on HN recently- https://news.ycombinator.com/item?id=35692884 https://news.ycombinator.com/item?id=35692884 though since then it has, at least started working again. I didn’t mention it in that post but that is _exactly_ the attack vector I had in mind also- even if someone stole my phone, Touch ID should stop them from getting at my passwords.
- dheera 3y ago> The attack vector that I'm thinking of here is your phone being stolen This is exactly why I'm a big fan of larger, heavier devices, such as my rack-mounted desktop PC, being their own 2FA device. It's pretty hard to steal my 4U desktop that is bolted down, there's no reason why it should depend on anything else for 2FA. Similarly, laptops should be their own 2FA device and not depend on a phone, since people are generally more careful to not take laptops into high-crime areas.
- icf80 3y agoThey added a fix for that, see it in your security settings Skip password when possible - You’ll be able to sign in securely with just a passkey or device prompt.
- madjam002 3y agoThat setting doesn’t affect what I’m saying. I want to disable Google Prompt as it’s insecure for my threat model. All “skip password when possible” does is give you the option to use a passkey to login without a password, it doesn’t prevent an attacker from using a password + Google Prompt to login, bypassing the need for any of the configured 2FA security keys or passkeys.
- icf80 3y agopassword is still available, even with passkey
- lostmsu 3y agoWhat I don't understand is why with a passkey they don't ask for the second factor anymore. I feel like I would want that.
- howinteresting 3y agoThe theory is that the two factors are something you have (your phone) and something you are (your biometric).
- hospitalJail 3y agoI'm happy that my important stuff is behind both a password + my phone. Having both behind your phone makes it easy to drug someone and get inside.
- howinteresting 3y agoI largely agree, though with something like 1password it definitely is convenient to not type in your master password each time.
- pphysch 3y agoIf someone has your phone, they probably have your emails/authenticators, which means they have most of your passwords. Passkeys simplify the email reset/OTP loop, for the most part.
- hot_gril 3y agoEven people using 2FA are probably storing the passwords on the phone via a password manager. Those without a password manager are probably reusing passwords or choosing insecure ones. I'd maybe be worried about the drugging if I'd ever heard of it happening to someone I know.
- derefr 3y ago> Even people using 2FA are probably storing the passwords on the phone via a password manager. Yes, but this is the reason that password managers encrypt your other passwords with a master password, rather than a master biometric. The master password is still the "something you know" factor.
- tonymet 3y agoThis still feels like a beta product, with a foot-gun of a UX * I activated the passkey, but since i had one saved from an old device, it did not set up my new device. So i got locked out of my account (luckily i have a backup option) * How does this work with desktop PCs that don't have a camera? * Now we have a web of primary, secondary, n-ary authentication methods that need managed. Password, app 2-fa, phone 2-fa, tokens etc. Any one could be a weak link in the chain. Now warnings, notifs & reporting is needed to maintain security among all the auth methods. It reminds me of the XKCD "standard" that now means we have n+1 protocols
- wilkystyle 3y agoDefinitely agree with concerns regarding the UX. While I'm sure many of us here can understand the following paragraph from the article... > In fact, if you sign in on a device shared with others, you should not create a passkey there. When you create a passkey on a device, anyone with access to that device and the ability to unlock it, can sign in to your Google Account. ... I wonder about the general layperson, especially older generations who (in my experience) tend not to use very secure passwords or MFA. Historically, all they would need to do is use their username and password, and now they are into their account, regardless of which device or location they are at. With passkeys, they have to not only learn a new login paradigm, but also remember that it's different if they are signing in at e.g. the library vs on a desktop at home.
- tonymet 3y agoI believe the tech industry needs a special segment of Accessibility catering to the elderly We are not taking responsibility for the unusable UX we are applying to cars, home appliances, phones, consumer devices, televisions, etc. Mechanical and even electronic devices have an intuitive direct-feedback UI. Flip on an old iron and it heats up. Modern devices are multi-modal, with soft-touch keys and modal LCD displays. Some buttons are long-press (variable input). And don't get me started on cars. Total chaos.
- echeese 3y agoThe way it works with desktop is that the browser displays a QR code, and scan it with the camera app, which allows you to register or log in.
- belter 3y agoThis looks like an ssh public-private key scheme but with the private key locked to your (Google) device only. What am I missing. Why all the fuss?
- linuxdude314 3y agoIt’s just a new name for WebAuthn/FIDO2 credentials. It’s easier to say, remember, and write the thus more marketable. This support has existed for a while, but not with this rebrand. I hope more companies will adopt this approach as it seems like an effective strategy.
- kccqzy 3y agoIt's an industry standard with good cross-platform support. So you can also choose to have the private key locked to your Apple device (with iCloud syncing) and Windows too.
- danShumway 3y ago> with good cross-platform support Not to rehash the entire previous post, but this should have a giant asterisk next to it. It's very technically cross-platform, but there is no batch interchange format. If you use Safari, your passkeys are only synced to iCloud. You can share them via AirDrop... to other Apple users. If you lose your phone, you can recover them... if you buy another iPhone. You can use your iPhone to log in on a Windows device, that part is cross-platform. And you can add that device as a second authenticator. But there's no actual portability there. You have (limited) cross-platform support (there is no Open Source platform authenticator that I'm aware of, and I'm not aware of any platform authenticator for Linux). But you can likely use passkeys with whatever platform you want. It's just once you choose a platform, there's no way to export from that platform unless you per-site add a new authenticator.
- derefr 3y agoPasskeys are already device-bound; there would be no point in cross-ecosystem sync. They're maybe backed up to a provider's cloud, but that's in case you reformat your computer and want to restore it from backup; not for moving the passkey around. Think of a passkey as a device identity credential. It gives credential X that you can register on your backend as belonging to device Y; not to user Y. You need to additionally keep in your backend a mapping from devices to users — where almost certainly, a user HAS MANY devices. You know how, in well-thought-out auth systems, you can "sign in with a password" and "sign in with [SSO provider]", and those will result in signing into the same account, where both the password credential and the IdP subject-claim are separate "credentials" bound to that account? Each passkey is a "credential bound to the account" in that sense. You create one for each device, and they all log you into the same account. In short, they're a "third-party-ization" of the thing that Apple, Google, etc already do with their "you're trying to sign into your Apple/Google/etc account from a new device. Confirm this on an existing device" workflows — where each device creates its own separate credential, that is enrolled to your cloud account. This is that, but for any third party website, rather than just the cloud service itself.
- butz 3y ago"They work on all major platforms and browsers" Is any Linux distribution, let's say Ubuntu or Fedora a "major platform"? Is Firefox a "major browser"?
- linuxdude314 3y agoIt’s going to be anything that supports WebAuthn/FIDO2 credentials. There are PAM modules you can install and configure for Linux and OSX. Browser support is slightly different depending on the browser, but support for credential creation and assertion using a U2F Token (passkey) is supported by Edge, Chrome, and Firefox.
- danShumway 3y agoVery important caveat, this is only for roaming authenticators like Yubikeys (https://webauthn.me/browser-support https://webauthn.me/browser-support). There is not (that I'm aware of) any support for platform authenticators on Linux (which is what most users will be thinking of when they use the word "passkey"). Roaming authentication is well supported on Linux, and you can cross-device sign in using your iOS/Android phone (assuming you haven't DeGoogled it), but the Mac/Windows experience of just having the computer itself act as an authenticator isn't supported. You're still going to need to use a locked down, proprietary device to log in, it's just that the proprietary device can help you log in on your Open device.
- aftbit 3y agoCan you link to more documentation on this issue? Why can my Linux box not act as an authenticator, perhaps using TPM or just with software security?
- danShumway 3y ago> Why can my Linux box not act as an authenticator That is a really good question. For whatever reason, I'm not aware of a single Open Source platform authenticator for any platform. It seems to me like that would be a pretty big priority for an Open standard, but what do I know? Google has said they have "no plans" to support platform authentication on Linux[0]. I don't know if this is just them saying they don't plan to build a platform authenticator themselves, or if they're saying that if a Linux box advertises that it has a platform authenticator, they're not going to trust it. Either way, passkeys basically require you to either buy a Yubikey/dongle (which will not support cloud sync) or to use a proprietary OS as your authenticator. https://developers.google.com/identity/passkeys/supported-environments#:~:text=Passkeys%20from%20Google%20Password%20Manager%20are%20available%20to%20all%20Android%20apps%2C%20including%20Chrome%20and%20other%20browsers https://developers.google.com/identity/passkeys/supported-en...
- lapcat 3y agohttps://news.ycombinator.com/item?id=35801392 https://news.ycombinator.com/item?id=35801392 (603 comments)
- okasaki 3y ago"So long passwords, thanks for all the phish" "The beginning of the end of the password" This is confusing. Is there some plan on Google's part to kill passwords that I'm not aware of?
- neuronexmachina 3y agoThat's basically the premise of the FIDO Alliance, which Google is part of: https://fidoalliance.org/what-is-fido/ https://fidoalliance.org/what-is-fido/
- aksss 3y agoAlso relevant link - FIDO’s press release about Apple, MS, Google commitment to passwordless sign-ins. https://fidoalliance.org/apple-google-and-microsoft-commit-to-expanded-support-for-fido-standard-to-accelerate-availability-of-passwordless-sign-ins/ https://fidoalliance.org/apple-google-and-microsoft-commit-t...
- kccqzy 3y agoThere is a plan to kill passwords, but the plan isn't just by Google. It's a unified plans across major players. In terms of marketing, anecdotally I see far more mentions of passkeys by Apple and related discussions. Apple: https://developer.apple.com/videos/play/wwdc2021/10106/ https://developer.apple.com/videos/play/wwdc2021/10106/ https://developer.apple.com/passkeys/ https://developer.apple.com/passkeys/
- hulitu 3y ago> Unlike passwords, passkeys can only exist on your devices. They cannot be written down or accidentally given to a bad actor. Pegasus ?
- SXX 3y agoAs far as I get hacking into phone and root access is not enough to extract secret key. There also Secure Enclave exploit needed and supposedly it will be much harder to come by.
- jmholla 3y agoThey negate this later with: > In addition, some platforms securely back your passkeys up and sync them to other devices you own. If they can be copied (or "synced"), they can be copied to a piece of paper and copied to a nefarious actor.
- lumb63 3y agoHow is this, practically, any better than existing 2FA? A 2FA code is stored on a device just like a passkey is. Passwords had a security and a usability problem, I guess, and so the solution was to add 2FA, which allegedly improves security. Now, we’re dropping the security of passwords to solve the usability issue. This doesn’t seem to be a big improvement to me.
- hot_gril 3y agoIt's less secure than 2FA and more secure than passwords. How is it practically better than 2FA, because it's easier.
- rootusrootus 3y agoGiven that most regular 2FA is implemented with SMS and doesn't even require stealing someone's device, I think passkeys are arguably more secure.
- hot_gril 3y agoOh totally. I was only thinking about the TOTP 2FA, for which I also have a giant rant about being user-hostile.
- divan 3y ago> 2FA code is stored on the device That's not how 2FA works.
- lumb63 3y agoI understand, but your statement feels pedantic. Practically, if someone has access to your device, your 2FA codes are compromised.
- divan 3y agoYes, Passkeys do not offer much against rubber-hose cryptanalysis. Actually, it's a bit worse than passwords as it doesn't require captured human to be concious. I believe Passkeys are great for those whose threat profile doesn't include physical assault risks.
- rootveg 3y ago"So long passwords, thanks for all the phish" that's pretty funny actually
- bt4u 3y ago[dead]
- hnburnsy 3y agoClick bait title, the password is not going away, unlike the dolphins who left earth... >Creating a passkey on your Google Account makes it an option for sign-in. Existing methods, including your password, will still work in case you need them, for example when using devices that don't support passkeys yet. Passkeys are still new and it will take some time before they work everywhere. However, creating a passkey today still comes with security benefits as it allows us to pay closer attention to the sign-ins that fall back to passwords. Over time, we'll increasingly scrutinize these as passkeys gain broader support and familiarity.
- MattRix 3y agoI’m gonna give you the benefit of the doubt and assume “click bait” was also meant to be a fishing pun.
- lelandbatey 3y agoHow do I back these up in case of catastrophic data loss, such as my house and all my possessions burning down (there are approximately 350000 house fires a year in the USA, so it's worth worrying about when its your entire digital life)? I take my security safety, but I take the durability of my digital life much more seriously. Right now, I am able to back up all my personal passwords and all my personal TOTP secrets into printed paper form that I keep in tamper-evident packaging and distribute to a safe-deposit box and the basements/attics of different trusted friends/family members. The printed packet of paper has instructions on how to use it, the passwords and TOTP secrets themselves, and the brief source code for one program, one that lets you generate TOTP codes from all my secrets (TOTP is very simple, it's like 30 lines of python[0]). I've tested it all and it is sufficient to access any account I have. Since it's all recorded on paper, each packet will function for my entire lifetime; I don't have to worry about storing a device and that device's charging/power equipment, and I don't have to worry about that device's capacitors or battery going bad in 10 years. So in the world of "passkeys", how do I simply and durably record them so that if need be, someone who is not me, who I've never met, and who has access to none of my electronic devices, can authenticate as me given that this person is willing to put several days effort into dealing with my authentication archive (e.g. an estate lawyer)? I know that this is "possible"; it's all based on data and secrets recorded somewhere, but I'm having a hard time understanding the FIDO description, and I don't see an Open-Source equivalent of what Google's offering here. Is there a "KeePassX" of the passkey world? [0] - https://github.com/susam/mintotp/blob/main/mintotp.py https://github.com/susam/mintotp/blob/main/mintotp.py
- lxgr 3y agoRegister a Yubikey in addition to all the services supporting WebAuthN and put it in the tamper-evident envelope? > Is there a "KeePassX" of the passkey world? Both 1Password and Bitwarden have announced support as soon as OS support will become available, the latter being open source.
- jrm4 3y agoAgain, a reminder that this is an across the board terrible awful idea. It's all the dangers of 3rd party passwords - namely, before you had two parties, now you have three and thus inherently less safe - but worse. Now, it's just even HARDER for you to control your own keys to your own stuff. There's one and only one reasonable way to execute this, and that's to include huge liability for the 3rd parties. Unless they'll pay up or otherwise fix in the event of a breach, this is a non-starter.
- gjsman-1000 3y agoI think it’s a nonstarter because the n00bs and n0rm1es will have no idea what to make of it, and will quickly go back to passwords because they just work predictably. To me it reeks of something that looked great, when you show a room of engineers. But for regular people?
- ewoodrich 3y agoPerhaps, but I recently added passkeys for Apple and Google accounts and the actual enrollment process and login didn't feel much more complicated than using the built in password manager for Chrome plus Touch or Face ID which people are already familiar with. That itself may be too complicated for some but it essentially was a few automatic prompts and instructions to scan my finger to login after it was done.
- musictubes 3y agoI don't understand your concern. How is it more difficult to control the keys? Why is it less secure than 2fa solutions? Every worry I've heard about passkeys can be leveled at 2fa schemes as well. The upside of passkeys is they can't be phished, can't be revealed in data breaches, and can't be forgotten. What third company is involved? Are you thinking about syncing services? With the exception of Linux (for now), you can have passkeys enabled on any modern device. It is just public/private key sharing right? A bad actor would have to have your device and be able to unlock it in order to get access to your accounts secured with passkeys. Every time passkeys are mentioned on HN the FUD starts flying and people lose their minds. Passwords are terrible with many weaknesses. There isn't perfect security, there are always weaknesses but I have yet to be shown how passkeys are worse than passwords for typical users.
- awinter-py 3y agocan someone who understands the cryptographic basis explain how centralized this is? it sounds like an app can consume passkey logins without registering with a provider? do providers phone home when I log in? can providers block an app from using them? can I self-host a provider, or is there a shortlist of approved providers? is there any provider that allows me to backup private key without sending it to their cloud? is it similar to openid in that it shares email etc with the app on login?
- cma 3y agoIt will really be a shame if we got ssh-like public key authentication for the web, but can't self-host it.
- deleted 3y ago[deleted]
- kdbg 3y agoFirst, just a high-level overview over how it would work as an app/consumer which is not terribly centralized outside of requiring browser support: Passkeys are an open standard, and they basically are just public/private keys with a wrapper. When you create a credential which is just a call to `navigator.credentials.create` with options to indicate a PublicKeyCredential type and that it should be a client-side discoverable key and a user ID to associate with it (and some optional info). Its gives you back some meta-info and the public key to store. For a login flow, similarly a call to `navigator.credentials.get` indicating you want one of those discoverable keys to be used and a challenge. The browser returns a signature to you along with the key info (that user ID from the creation) and you are responsible to verify the signature is appropriately signed. --- So, on the actual crypto side, nothing about it requires any centralization, there is no required phoning home or to a remote source. On the creation/storage/retrieval side, the WebAuthn Authenticator Model is defined as part of the standard so anyone can implement it. I don't know enough about how you'd register as such an authenticator. Dashlane already supports passkeys, so it is possible for a third-party to do so, Bitwarden and 1Password are also working on it. So my understanding would be that self-hosting is more just a matter of giving it time for others to implement the necessary components and not there being any restriction on who can do this.
- theknocker 3y ago[dead]
- hnburnsy 3y ago>Creating a passkey on your Google Account makes it an option for sign-in. Existing methods, including your password, will still work in case you need them, for example when using devices that don't support passkeys yet. Passkeys are still new and it will take some time before they work everywhere. However, creating a passkey today still comes with security benefits as it allows us to pay closer attention to the sign-ins that fall back to passwords. Over time, we'll increasingly scrutinize these as passkeys gain broader support and familiarity. So my password that I stupidly shared among my accounts and was then leaked, can still be used to compromise my Google Account. Wake me when I can create a Google Account without a password, email, or phone number, period.
- Andrex 3y agoProbably not far off. Sounds like with other methods (SMS 2FA, USB hardware key, etc.) you may be able to eventually turn password sign-in off on your Google account and use passkeys exclusively.
- lxgr 3y agoA phone number is both an authentication mode and rudimentary bot/sockpuppet protection. (It’s pretty bad at both, but that’s a different story.) Passkeys can substitute the former, but (by design) not the latter.
- elwebmaster 3y agoThat's it! When I can use solely my hardware security key to signup/login then we are talking. The rest is just marketing.
- drivebycomment 3y agoNothing stops you from registering multiple passkeys, change the password to a long random string and forget about it - then you effectively have passkey only account.
- hnburnsy 3y agoExcellent point, just tried to create a new Google Account and it requires a phone number that can receive a text message so account is still open to SIM swap.
- braincode 3y agoNot supported on free Google "legacy" org accounts (pre-Google Workspace), greeted with "Passkeys aren’t allowed on this account." message :/
- kxrm 3y agoYea I see the same but I believe, according to their blog post, they are rolling out support on workspaces at a later date. https://blog.google/technology/safety-security/the-beginning-of-the-end-of-the-password/ https://blog.google/technology/safety-security/the-beginning...
- judge2020 3y agoThis is odd - as soon as this became available, I created a passkey on my Workspace account, but now it says "Passkeys aren’t allowed on this account". And it still prompts me to "simplify my sign-in experience" when I sign in on this account.
- willhackett 3y agoI wonder if they'll update Chrome to support Keychain on Mac.
- Animats 3y agoQuestions: 1. If you are using this to authenticate a non-Google service, can Google cut off your access to that service? 2. If your Google account is terminated, do you still have access to non-Google services? 3. Does Google possess sufficient information to log into non-Google services as you? 4. In the event that any of the above happen, do you still have the right to sue Google?
- prepend 3y agoThis is just for authenticating to google, right?
- Nifty3929 3y agoYes, but if you use the “Login with Google” function on many 3rd party websites, then what? If Google locks you out, can you get back into your account on the 3rd party website? I think this is a great question, and that the answer depends on the 3rd party site.
- theaiquestion 3y ago> Yes, but if you use the “Login with Google” function on many 3rd party websites, then what? AFAIK this part has nothing to do with passkey's and is an issue with OAUTH, and has been an issue for years.
- tisc 3y ago> […] and is an issue with OAUTH This issue is not caused by OAuth, but by offering authentication via a third party. If you allow visitors to authenticate via a third party, you implicitly trust that third party. If that third party decides to revoke your account, then the logical consequence is that you can no longer authenticate. There’s no solution for this problem imo, other than not allowing authentication via a third party. It is the same as airlines; They want you to identify using a passport. If your country decides to revoke your passport, you cannot check-in. That’s not an issue, but a logical consequence of choices made.
- knaik94 3y agoThere's no meaningful benefit of this over a password and 2FA authentication for users who are already proactive about security. I also doubt that passkeys will be protected by the fifth amendment the way passwords are, based on the "key vs combination" argument. While I trust Google password manager to help me remember passwords and even use sign in with google, I don't want to let Google or any company to manage my initial method of authentication for me. At their core, passkeys are a easy and nice way to move from passwords to public private key cryptography. And hardware based authentication does allow more security. And by leveraging the tpm, hardware-backed keystore, or security enclave, you can use your phone and computer the way FIDO keys are already used. But there are many reasons why I will wait as long as possible, maybe indefinitely before I start using passkeys. The idea of this being tied to Google or any other major company for my logins is not okay. There are many cases of people being locked out of Google accounts without the ability to appeal. I don't appreciate the idea of large companies being able to whitelist which passkeys are allowed, which is possible depending on how attestation certificates are handled. With current 2factor, you can control the secrets yourself if you choose to. While it's true that you can't be phished into sharing your passkey as easily, you also lose a lot of convience and flexibility in login management. And it makes login sharing or multi-account management very inconvenient and difficult. I was hopeful with 2FA rolled out that my accounts would be more secure, but most companies give you very little control over which methods of 2FA are allowed or enabled. I don't want to be forced to enroll a phone number just to enable TOTP 2FA. I want to be able to choose between TOTP or HOTP for my accounts. I don't want to be forced to use a 2FA app that doesn't allow me to export and manage the secrets myself. In some ways FIDO keys solve some of those issues, but the hardware security aspect of it contradicts giving the end user the choice to self manage. I expect some policies will change over time based on uptake and issues people face. https://www.concordlawschool.edu/blog/constitutional-law/fifth-amendment-biometrics/ https://www.concordlawschool.edu/blog/constitutional-law/fif... Edit: Apparently, in iOS and Android, passkeys are backed up to the cloud, and iOS even allows you to airdrop them. https://www.nytimes.com/wirecutter/blog/what-are-passkeys-and-how-they-can-replace-passwords/ https://www.nytimes.com/wirecutter/blog/what-are-passkeys-an...
- gerash 3y agoWait, this lets you use your device as the "passkey" to log-in into Google instead of you typing your Google account password. I don't quite follow how your lack of trust in Google password manager is relevant.
- nyanpasu64 3y ago> Passkey sync providers like the Google Password Manager and iCloud Keychain use end-to-end encryption to keep your passkeys private. https://security.googleblog.com/2022/10/SecurityofPasskeysintheGooglePasswordManager.html https://security.googleblog.com/2022/10/SecurityofPasskeysin... claims it's encrypted using "an encryption key that is only accessible on the user's own devices": > When a user sets up a new Android device by transferring data from an older device, existing end-to-end encryption keys are securely transferred to the new device. In some cases, for example, when the older device was lost or damaged, users may need to recover the end-to-end encryption keys from a secure online backup. > To recover the end-to-end encryption key, the user must provide the lock screen PIN, password, or pattern of another existing device that had access to those keys. > Screen lock PINs, passwords or patterns themselves are not known to Google. The data that allows Google to verify correct input of a device's screen lock is stored on Google's servers in secure hardware enclaves and cannot be read by Google or any other entity. How does Google know my device's local PIN in the first place? Are Android phones phoning home to Google with their local PINs, like how they already "helpfully" backup your Wi-Fi passwords to Google servers? And what's stopping the FBI from asking Google to send them every device's PIN as it's created?
- tasn 3y agoWhat's even more ridiculous is calling it end-to-end encryption when it's secured by a short numeric pin (what most people use). The search space for brute forcing it is so insanely small that it doesn't matter how much password stretching you do, it's trivial for Google/anyone with access to the keystore to brute force.
- dukeofdoom 3y agoI tried using a work computer as a guest without signing into a google account on windows, and web pages would not load for me. It kept asking for me to sign in. This was on windows. Just curious if this is the default behaviour on windows chrome now, that you can't browse the web without signing in. Switched to mac a few years back.
- istillwritecode 3y agoI assume the goal is to keep people logged in. The bullshit reason is to get rid of passwords. I have passwords that are strong and 20 years old, so I regard passkey as evil.
- account-5 3y agoI'm never using this unless I'm in control of the certs and where they're stored. This if a fragile solution to the issue of password reuse and bad security practices from vendors.
- judge2020 3y agoPasskeys don't send the hardware identifier or anything else to the service when you authenticate with them - all they see is a signature and a public key with no authority/signing chain or anything. So you can very well create software passkey implementations and whatnot, or use something like a Yubikey for your passkey storage.
- account-5 3y agoMy personal preference is for it not to be tied to a device that can be lost, stolen, broken. That way I don't need multiple backup devices to login to one service. My password manager generates unique strong passwords, is offline and no big multinational advertising company controls it. The only thing I need to worry about is individual companies security practices. Passkeys offer me nothing of an improvement over this and only more obstacles and hoops to jump through. Until I can use passkeys like I can my password manager I'm not using them
- T3RMINATED 3y ago[dead]