3 ms·
On point 1 if google decides to lock you out of its service, it generally doesn't stop at a single device but all other devices you own and associated accounts
by devsda 3y ago
On point 1 if google decides to lock you out of its service, it generally doesn't stop at a single device but all other devices you own and associated accounts can also be impacted.
So, the solution here seems to be not just creating backup devices (using the same account) but diversify the platforms as well like use a mix of android, yubikey, ios and any other supported platforms.
Doubt many people would have the time and resources to do it correctly.
- notatoad 3y agoAs long as one of the backup methods included in "the time and resources to do it correctly" includes signing in with a password like you always have, I'd guess that most people will have done that.
- larusso 3y agoThe fallback to a password in this case feels so wrong. I mean it’s like ssh with password prompt enabled. They let this open for the conversion phase and monitor how often a user with a passkey is still using the password. But the ultimate goal should be to get rid of username/password credentials. I’m still uncertain if this will ever happen though. Given the track record of giant corps to lock out users for various reasons.
- xyzzy123 3y agoAlso, diversity means you trust all of the providers; from a security perspective it's worse.
- stouset 3y agoNo? Your private keys are still on your physical device which you own. The providers do not get your key material. If your threat model includes “the manufacturer of the device I use to authenticate myself is actively working against me”, you are already completely lost.
- xyzzy123 3y agoIn order to be usable, many (most?) providers will implement some kind of override to allow recovery workflows. Have a look at https://media.fidoalliance.org/wp-content/uploads/2022/03/How-FIDO-Addresses-a-Full-Range-of-Use-Cases-March24.pdf https://media.fidoalliance.org/wp-content/uploads/2022/03/Ho... and multi-device passkeys. Your keys may never leave secure storage (tho again that is an implementation detail), but how sure are you about the sync implementation or the backend configuration that dictates which keys or methods are acceptable authenticators? As a trivial example, it seems very likely that providers will implement one or more forms of backdoor to ensure that LEOs can access your cloud resources.