35 ms·
Passkeys are now enabled by default for Google users
- redrblackr 3y agoI was surprised by the amount of dislike of passkeys in this thread until I realised I had misunderstood what passkeys refer to. I thought it was the same as security keys, which are like digital, but still physical, keys. They are awesome, one just has to have two and you are set. Passkeys tied to a cloud service or device like a smartphone are a terrible alternative (comparatively), from privacy and security (as in not get locked out) standpoints. At least they use fido2 so pushing for passkeys add support for security keys at the same time..
- ok_dad 3y agoahhhhh! yet another setting I have to go disable in my Google account. I use yubikeys for 2fa for a dang reason, don’t try and force me to do stupid shit like this which will actually decrease my security! I’m glad I only keep my Google account around for historical purposes and YouTube.
- CatWChainsaw 3y agoA thousand nopes. I don't care if it is 100% secure. This is one instance where "cloud" is better. Having the mother of all failsafes be a device that can be stolen, broken, or just plain borked on a dime, and potentially your entire digital life is now locked from your access for good? Great innovation there google, please kill this in 18 months please.
- awinter-py 3y agough companies reallly shouldn't blog about cyber awareness month until they fix the acronym
- Bu9818 3y agoIf I'm allowed to use a software implementation (like with TOTP) so that my private keys can be stored in for e.g. a KeePassXC database so that I can back it up by having multiple copies, then I'm okay with it. Is it possible for sites to deny certain webauthn providers (ignoring scenarios like attestation forcing you to use a locked down system where you can't run keepassxc)? Hopefully Tor Browser can turn on security.webauth.webauthn in a safe way before sites force it to be used, too.
- hedora 3y agoCan we decide to band together as an industry and call this “zero factor authentication,” since you login without using something you know or something you own/control? The only way I can think of to explain this to a non-techie is “your account is now tied to your [singular] device, and neither a password nor a replacement device (like a new sim card) will let you in.” So, it really does remove both factors from 2FA, and the logical conclusion holds. Either anyone can get into an account with a “I broke my phone” social engineering attack, or the account owner cannot reliably authenticate.
- echeese 3y agoSomething you have: Your phone Something you know: Your pin Something you are: Your FaceID/Fingerprint
- hedora 3y agoFaceID and pins just unlock the secure enclave, which stores the password^H^H^H^Hkey on the phone that will eventually break. So, when you are holding your dead phone, you realize that there is nothing you know or have that will let you into the account (and there never was such a thing).
- smeej 3y agoThere's one elephant in the room I'm not hearing enough about, namely the legal precedent (at least in the U.S.) that you can legally be compelled to provide a biometric identifier (fingerprint, face scan, etc.), but cannot be compelled to provide a password, as that would be "compelled speech" and violate the first amendment. I disable all kinds of biometrics from my devices when traveling for this reason specifically. Passwords in my password manager aren't the whole password. There's another component in my head that I won't (and, more importantly, cannot be compelled to) disclose.
- kasdi 3y agoInteresting point. Seems like a point where the law lacks behind technological progress. Though, in any case, most people aren’t aware of the detailed laws and when pressured enough by enough authority - perhaps not quite lawfully - they will give in. So, this seems to me a rather niche case where both sides know and follow the law, which is usually not the case.
- xhkkffbf 3y agoOne of my companies switched to Yubi pass keys. They were super cool -- until I tried to log in on a computer with only USB-A ports. My key is USB-C. I suppose I need to get an adapter now.
- toomuchtodo 3y agoPasskeys are stored within your device, iPhone, Android, browser, or system keychain. https://passkeys.directory/ https://passkeys.directory/ https://www.stavros.io/posts/clearing-up-some-passkeys-misconceptions/ https://www.stavros.io/posts/clearing-up-some-passkeys-misco... https://support.apple.com/en-us/102195 https://support.apple.com/en-us/102195
- rnijveld 3y agoThey don’t have to be though, a yubikey can be used as a passkey as well.
- toomuchtodo 3y agoThey can be, but most people will use what is built into their mobile ecosystem of choice, with built in sync/backup. Physical secure authenticators in general use will likely remain rare, but are still useful for use cases where passkeys that can be synced or migrated are not secure enough (and you want access governed with a simple physical device).
- jasonjayr 3y agoDoes this work with Linux Desktop ?
- flkenosad 3y agoWhat if you use an old-fashioned desktop PC?
- vdelitz 3y agoif the PC has Bluetooth you could use a passkey from a smartphone - besides that, if it's a Windows PC, you could use Windows Hello (with a PIN)
- dogleash 3y ago[flagged]
- fckgw 3y agoNo? You wanna expand on that?
- vdelitz 3y agoI don't think so
- marcosdumay 3y agoThe title triggers me by itself. The article is actually much less problematic. Anyway, I guess the way people are reacting on the comments is overwhelmingly due to the language. And the fact that it doesn't even try to explain anything. IMO, the author didn't really know the things the article is about and is writing about some 3rd party information.
- px43 3y agoExcept that Google and everyone else pushing passkeys have been publishing massive volumes of highly technical details about all of this for years. You're looking at a non-technical blog post targeted towards the general public, and non technical journalists. Any technical details you want are just a search away.
- endisneigh 3y agoOnce this rolls out plus attestation the days of using mainstream sites anonymously with an account will come to an end.
- postalrat 3y agoYou think your are anonymous? Please.
- isykt 3y agoWhy is a pin more secure than a password?
- kube-system 3y agoIt isn't, and this isn't authentication with a pin. Passkeys also requires the device. Using a pin with this is 2-factor. Pin + hardware token.
- isykt 3y agoSo why not just have a password that then unlocks the passkey? I already have a password manager.
- snowwrestler 3y agoSure, PINs can be long and alphanumeric on most phones these days.
- isykt 3y agoHow is that different from a password? PIN stands for Personal Identification Number. Words change meaning all the time, of course, but in this case there’s no reason to call it a PIN when there’s already another word for it.
- snowwrestler 3y agoThe important difference is that it is stored on the local device, not the remote server. Since the things stored on the remote server have been called “passwords” for decades, it seems helpful to call the local thing a “PIN” to help more easily distinguish it. IMO it’s not more silly than calling a hand-held computer a “phone.”
- michaelt 3y agoThe standards group that was behind Fido/U2F has been taken over by people who want to push a new product. That new product is "Log in with your phone" and phone lock screens allow biometrics and pins. Password managers are not relevant, as you don't use a password manager to unlock your phone. The people behind the takeover don't really give a shit about Yubikey-style tokens (which haven't achieved much market penetration anyway) but they've left them in to make the takeover less blatent.
- jjoonathan 3y agoUgh, is this why my FIDO key started making me enter a redundant pin on the company login page (so: enter password, press FIDO key, enter PIN, press FIDO key)?
- di4na 3y agoYes. That plus the way apple implemented it. In my case i was already on passkeys and google decided to just... forget them all on my other computers. I can't use them to get in anymore. Why? Who the heck knows. This whole passkey shit is going to be a nightmare for UX.
- lazide 3y ago“Weaponized” 2fa (already very common) is a huge UX fail too. In theory this could reduce those terrible flows.
- ghaff 3y agoIn general, the levels of security that people will increasingly need going forward, and the increasing requirement by companies to use that level of security, will be a usability pain for many people and a nightmare for at least a subset.
- rurp 3y agoIs there any evidence that Google needs to mess with authentication flows? My mental model of the median Google account holder is that they have a bunch of photos/emails/docs/etc that are extremely valuable to them and their family, but of little value to criminals. With a dynamic like that, the security only has to be so high to deter random hackers and making it too difficult or confusing will ruin a lot of valid accounts and do much more harm than the criminals would have. There are reasons to be skeptical of Google's motives here given their history of wanting to create user lock-in in various ways, and caring more about shiny new tech than general user experience.
- davkan 3y ago
- p1mrx 3y agoWhat happens if I lose my phone?
- ellisv 3y agoWhat happens if you forget your password?
- lopis 3y agoYou recover it?
- MrStonedOne 3y ago[dead]
- fbdab103 3y agoA password I can write down. A phone can be lost/stolen/black screen.
- qup 3y agoThey let me use my phone to login again
- zb3 3y agoI reset it using my SMS 2FA phone. I can't lose that number because in my country I'm legally entitled to it.
- 3y ago
- bufferoverflow 3y agoIsn't it obvious that logging in with your face or your fingerprint is less secure? Sure, it's convenient, but any thug can just forcefully unlock your device.
- bbddg 3y agoI think for anyone not working in national security, any thug could just as easily get your password out of you.
- forward1 3y agoReminds me of this wondeful scene in Ronin: Everybody has a limit. I spent some time in interrogation... once. They make it hard on you ? - They don't make it easy. Yeah, it was unpleasant. I held out as long as I could. All the stuff they tried. You just can't hold out for ever. How'd they finally get to you? They gave me a grasshopper. - What's a grasshopper? That's two part gin, two part brandy, one part crème de menthe...
- kube-system 3y agoMost thugs don't have physical access required to exploit this. They're on the other side of the world and are doing credential stuffing attacks.
- renegat0x0 3y agoIn case od data leak - you cannot change your face, or fingerprints. You can change passwords though.
- ezfe 3y agoGood news that you can’t bring someone’s face to google and ask for access to their account… Please don’t insert commentary when it’s clear you don’t know what you’re talking about
- renegat0x0 3y ago
- powera 3y agoNope, not signing up. The trend from Google continues to be towards "if you lose your phone with your credentials, you will be unable to log in". And Google refuses to create a scalable system that allows you access to your account by verifying your identity in person. This is a recipe for disaster. And, possibly, a warning to move off GMail before it gets worse.
- ed312 3y agoI'm about at the threshold for wanting to de-google my life. Do you have an alternative email provide you recommend?
- hooverd 3y agoI use fastmail.com because I wanted to use my own domain. They're not free - make of that what you will.
- queuebert 3y agoFastmail rocks. I decided years ago to be the customer not the product, so I don't mind paying for services I use. An added benefit of Fastmail is somehow its calendar is able to sync between my Outlook work calendar and some shared Google calendars I have, while Google is completely unable to reliably sync a shared Outlook calendar for me.
- opan 3y agoAnything with working IMAP so you can use your own client. So, not Protonmail or Tutanota.
- edvinbesic 3y agoNot parent but the more important thing in "de-googling" is to move your logins to your own domain. That way you are not tied to a single provider and can always switch if your current one starts degrading. After over a decade of @gmail being my primary personal email it is pretty painstaking to move all of my logins over, and some services do not allow you to change your email at all so your mileage may vary.
- frabcus 3y agoAs a user I still don't understand this. What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again?
- jjav 3y ago> What happens if there's a house fire or something and all my devices where I'm logged in with Google break? How do I log into my account again? Easy: you will never log in to google again. Since google has zero reachable support, that's the end of your account. This works better with something like a credit union where as a last resort just can just walk in there in person with IDs and restore access. But with these internet giant companies which take pride in not having any reachable support ever? Nope, nope and no.
- konschubert 3y agoAnd what if somebody breaks into my google/iCloud account and syncs all my passkeys to their machines?
- px43 3y agoIf they're in your Google/iCloud, you're already in a game over scenario. The point of all this is to prevent that from happening. You can try to recover by revoking all your passkeys and starting over with hardware tokens, but that's likely what a sophisticated attacker is going to try as well, and they're probably faster than you. Still way way better than passwords.
- konschubert 3y agoIf they break into my iCloud then they’re in my iCloud. They’re not in all my other accounts, because I use an encrypted password manager that isn’t iCloud.
- skarra 3y agoThink of it as using iCloud as your password manager and storing your OTPs - someone breaks into your iCloud, they get access to all the passwords and OTPs to login to any service in iCloud. Always take the security of your password manager / sync accounts seriously. Use hardwre security keys if needed on the "root accounts".
- netsec_burn 3y agoThis is an interesting direction. It's worth noting that biometrics, like fingerprints or facial recognition, aren't really 'secrets'. They can be observed or leveraged without a users knowledge or consent, and in many ways function more like a username than a password.
- csjh 3y agoDon't they need both physical access to device + fingerprints/face?
- px43 3y agoYes.
- the_snooze 3y agoPasskeys really aren't biometric authentication per se. If you use TouchID, for instance, Google isn't authenticating you based on your fingerprint. Rather, the fingerprint merely unlocks the cryptographic key pair that's then used to authenticate you. I use Yubico Security Keys myself as passkeys. They're protected by a 6-digit PIN. But that PIN is strictly local to the device, meant to prevent snoops from logging in just by having physical access to the device (the keys get blown away after 10 consecutive unsuccessful PIN attempts). When I enter the PIN, the keys unlock, and it's those keys that get me into my Google account.
- kube-system 3y agoPasswords are also not entirely secret, as they're shared by definition. Passkeys use public-private key crypto, which is more secure in every way.
- mlk 3y agoPassword should be stored as salted hash, so they are not really shared.
- kube-system 3y ago
- iand 3y ago"To use passkeys, you just use a fingerprint, face scan or pin to unlock your device, and they are 40% faster than passwords — and rely on a type of cryptography that makes them more secure. " Who wrote this sentence? It's just a mess.
- TheRealPomax 3y agoalso, "ah yes, a several digit pin, famously more secure than a same-length password that adds even as little as letters".
- wkat4242 3y agoA pin is pretty safe when it unlocks a hardware token that limits the amount of attempts. It's basically like a chip & pin bank card.
- progbits 3y agoPIN for secure module with throttling and max wrong attempt count is indeed safer than a password you can brute force offline.
- andrewstuart2 3y agoBrute forcing offline kinda only works if you have a stolen hash or artifact like that. For a service like Google, they definitely have rate limits on password attempts. I'm not saying I prefer either one here, just that password authentication doesn't automatically mean you can brute force offline.
- postalrat 3y agoThe real key is stored in a chip. Your pin unlocks the real key. The chip has hardware to rate limit pin attempts. These types of chips tend to have many layers of physical security to protect the real key.
- wrs 3y ago
- TheBlight 3y agoProbably a stupid question but why can't photos of my face be used to defeat this?
- adzm 3y agoIt would have to be scanned by a device that has already logged in, basically.
- kube-system 3y agoThe biometrics aren't authenticating you. They only unlock your phone, which stores the private key used to authenticate you.
- TheBlight 3y agoI see. So really this is public/private key authentication and the face/pin/fingerprint etc is just the typical device unlock stuff.
- grotorea 3y agoYes, that's mostly it.
- stalfosknight 3y agoAlso a photo of your face wouldn't be sufficient for FaceID.
- ezfe 3y agoThis has nothing to do with your face is the simple answer. If your platform uses face scanning, you can read how it protects you from that. For FaceID on iOS, it uses additional sensors beyond just a camera.
- jval43 3y agoNever. You can pry my passwords from my cold, dead hands.
- grotorea 3y agoSomeday, we will have brain reading technology to extract information from a newly dead brain, like we have to extract it from a RAM that was just turned off https://en.wikipedia.org/wiki/Cold_boot_attack https://en.wikipedia.org/wiki/Cold_boot_attack
- tempest_ 3y agoLol just saw the creator I assume.
- jawns 3y agoCoincidentally, we can also pry fingerprints from your cold, dead hands.
- 0cf8612b2e1e 3y agoEntirely this. I do not trust devices to always be working or on my person. I will only use this if I can generate an offline, perfect fidelity backup of my codes. “But it’s safe in the Google/Apple/Microsoft cloud” is not an acceptable answer.
- yieldcrv 3y agodoes this work in conjunction with multifactor authentication? like biometric + one time passcode?
- kube-system 3y agoIt is multifactor authentication. The second factor is a private key stored in your device.
- rcarmo 3y agoAs usual, the multi-device/multi-OS and recovery scenarios are simply just glossed over. I'll stick with a password vault I can sync to multiple OSes, thanks.
- Flimm 3y agoYou can associate multiple passkeys with your account. Your account can have a passkey that is synced across Android/Chrome, and another passkey that is synced across Apple devices and browsers.
- lazide 3y agoThe vaults have been adding passkey support (1Password already has it, for instance).
- rcarmo 3y agoI will never willingly go back to using 1Password.
- grotorea 3y agoA FAQ at the bottom answers some questions https://safety.google/authentication/passkey/ https://safety.google/authentication/passkey/ . Seems that the recovery if you lose the devices with stored passkeys is still using a password. And will it be possible to use software keys and backup them to wherever I want and use them with Google or is it going to demand TPMs or that I keep the key in a secure vault in my phone or something or the sort? There still isn't a way to use this on desktop Linux right?
- hooverd 3y agoThere's nothing about the PKI aspects of passkeys that requires you to buy into a vendor ecosystem and have them on device, right? They're just key pairs, but I guess it's a good as chance as ever to ram through device attestation.
- renegat0x0 3y agoIn one of my groups leaders decided to reuse google suite accounts. It was really difficult for me to accept the account from a other person. Google sent multiple notification to other person phone, had to unlogin, configure two factor authentication, the other person had to ignore warnings about Linux access. It was nightmare.
- rmellow 3y agoSimpson's Paradox lives here. On average, this might increase security (the vast majority of users are terrible at using passwords). For proficient users who use passwords securely, this is an acute drop in security (if forced to use). Forced phone number 2FA has the same effect; in Big G's case forcing phone number 2FA is anti-anonymity disguised as security. In this case, it's a bid for biometrics.
- forward1 3y ago> Forced phone number 2FA has the same effect; in Big G's case forcing phone number 2FA is anti-anonymity disguised as security. It can actually be both; in fact it very likely needs to be: 1. Phone numbers are the best long-term identity most people have 2. Google has billions of users and needs to support account recovery at unbelievable scale 3. Many people lose passwords and devices, but very few lose phone numbers It logically follows google uses phone numbers to assign and delegate identity on their platform. Is this bad for privacy? Yes, but it's also very good for security because it allows users to control their data using a third-party authenticated "credential" they don't have to manage.
- rmellow 3y agoAll of this is valid! But it would be even more secure if there was an opt-in "I don't want to use my phone as 2FA". Phone number authentication creates a weakness for anyone who is in a targeted attack. A motivated attacker can easily bribe/trick a telecom employee, or if physically accessible, swipe the phone itself to read 2FA texts.
- px43 3y agoSign up for Google's Advanced Protection Program. It's been around since 2017, and last I checked, it's the only way to fully disable the use of your phone number for authentication. https://landing.google.com/advancedprotection/ https://landing.google.com/advancedprotection/
- grotorea 3y ago> For proficient users who use passwords securely, this is an acute drop in security (if forced to use). Why? Because the user can have their device stolen and the PIN guessed? Can't you use a long password instead of a PIN if you want to? And this part I'm not sure of, please correct me if you know. If I understand it correctly there's one security advantage even assuming a sophisticated user who is immune to weak passwords, password reuse or phishing. If there's ever a leak of Google passkeys, the leak would only get public keys, which can't be used for login, making the leak mostly useless.
- CosmicShadow 3y agoIs it hard to remember the one password you use for all Google services everyone's already been doing forever and will still have to do for every other site? When's the last time anyone even had to log into Google on any device? I'm signed in everywhere all the time and it almost never seems to expire... My desktop doesn't have a camera, fingerprint reader or touch screen...
- 1980phipsi 3y agoFinger prints and face scans are better replacements for user names than passwords. I had read some good things about YubiKey, but I don't think I could get it to work on my corporate computerr.
- the_snooze 3y agoPasskeys aren't "finger prints and face scans." They're dolled-up versions of SSH key authentication. Just as SSH private keys can have passphrases to unlock them, passkeys can have passwords, passphrases, PINs, or biometrics to unlock them too. Servers don't authenticate you on those PINs or biometrics; those merely unlock the associated private key.
- reisse 3y agoAlways remember that passwords are protected by Fifth Amendment and similiar laws in other countries, but there is no law prohibiting officer to put your phone in front of your face to unlock it.
- postalrat 3y agoSo do you have one password memorized or hundreds?
- smeej 3y agoOne, the one to my password manager, where the rest of my passwords are stored--but without the additional part I add after I paste the password that is stored in my head.
- fragmede 3y agoWhy make claims for other locations when you don't know about them, and it could lead to serious consequences? In particular the UK has no such compunction.
- jjgreen 3y agoTwo years in prison for failing to unlock your phone in the UK (Section 49 of the Regulation of Investigatory Powers Act). Don't forget that password!
- shepherdjerred 3y agoFor iPhone users, you can mash your power button and it'll require a PIN to unlock the phone. Biometric auth will be disabled.
- TMWNN 3y agoThe post mentions eBay as a site using passkeys. eBay's implementation on PC accepts Touch ID, while Google's implementation did not the last time I tried it.
- vdelitz 3y agotry this one: https://g.co/passkeys https://g.co/passkeys (you need to have set up a passkey before though)
- TMWNN 3y agoThank you. I am embarrassed to say that using the site reminded me that, actually, I had already created Touch ID passkeys for my Google accounts. I think what confused me is that passkeys were not available for Google Workspace yet, so my account there couldn't use passkeys. That has now changed.
- groovybits 3y agoI see a lot of misinformation, or misunderstanding, of Passkeys in this thread. I highly recommend reading Steve Gibson's notes on Passkeys from his Security Now! podcast episode #870: https://www.grc.com/sn/sn-870-notes.pdf https://www.grc.com/sn/sn-870-notes.pdf (p. 10-13) For context, Gibson developed, and completed, an entirely secure and working solution to the problem Passkeys aims to solve, called SQRL (which I argue is better than Passkeys in a few ways). He is familiar with this problem space, and explains Passkeys in a straightforward way. You can find this full podcast episode on Twit.tv: https://twit.tv/shows/security-now/episodes/870 https://twit.tv/shows/security-now/episodes/870 You can also find a full text transcript of the episode, transcribed by a human - by hand, here: https://www.grc.com/sn/sn-870.htm https://www.grc.com/sn/sn-870.htm
- jehb 3y agoThere are a lot of interesting points being made in the conversation here. What I haven't seen yet is a reminder that a Google Account is effectively Google's private property that they're letting you access in exchange for vacuuming up your personal data. The only winning move is not to play.
- dagoodboy 3y agoWhen can we use real crypto on a Smart Card / PIV / CAC without relying on Google, MS, or the Government?
- kseifried 3y agoI might regret this but I have an (almost finished) draft of a paper on Passkeys, it is available, with comments enabled (which will be turned off if vandalism becomes a problem) at: https://docs.google.com/document/d/1eBjQDWkbqXJSL4GRrAdTUcAx2mVRA9YeTJKr2JgnT0U/edit?usp=sharing https://docs.google.com/document/d/1eBjQDWkbqXJSL4GRrAdTUcAx... TL;DR: ============ Major insights in this paper: Passkeys level up security, and while Passkeys make some tradeoffs concerning security vs. usability, they do not introduce any new attacks and make many existing attacks much harder or impossible (e.g. brute forcing attacks or credential stuffing) Passkeys will bypass the hurdle of getting people to start using password managers, and will likely result in the widespread use of biometrics to secure Passkeys Passkeys can potentially make account sharing harder once attestation is supported, something a lot of service vendors are in favor of. Passkeys are also easier to deploy and reliable due to optional device synchronization, which should reduce the need for account recoveries and lower support costs Passkey client support in both software and secure hardware tokens is widespread and available now on most platforms, browsers and most third-party password managers Passkeys are being deployed by major vendors (e.g. Google https://blog.google/technology/safety-security/passkeys-default-google-accounts/ https://blog.google/technology/safety-security/passkeys-defa...) ============ Conclusion: No new significant risks or attacks are introduced from the threat model perspective. From a usability and reliability perspective, Passkeys are infinitely better than passwords. Finally, from a support perspective, chances are that if you currently use a system to manage your passwords, it already has Passkey support. For high-security applications, you can also choose to use your hardware token. Web applications and websites are becoming increasingly critical to everyday life (banking, healthcare, education, shopping, etc.). We must improve security across the board and get rid of old and insecure things like usernames and passwords. The world has also changed, and virtually everyone has a smartphone, something unimaginable even ten years ago, let alone twenty. Simply put, in every situation where you use a password, you should upgrade to a Passkey if possible.
- drdaeman 3y ago> one common strategy is via displaying a QR code The problem with Passkeys is not that it's not possible, but that the standard is lacking any guidelines for things like this. There is no interoperability in general, it's accidental at best. And this is concerning. Same goes for a lot of aspects that are attributed to Passkeys as "this can be solved this way", but in no way documented (in a way promoted by any major vendor), let alone standardized, let alone be required by some standard to be "Passkey-compliant". In short, I think this can be summarized as "Passkeys lack proper standardized best practices document, encouraged by renown parties". It is wrong to hand-wave at some specific implementation and say that because that implementation is okay, the whole standard is fine. ---- Also, you may consider adding another concern, "authenticator must be physically present to be registered". This limits ability to add new devices (which was not an issue with other systems, such as TLS client certificates). In simple terms, one cannot add a Yubikey that lies in a safe in a secure vault under a mountain, they must have it at hand, when they're online. This Passkeys/Webauthn limitation leads to people having significantly greater difficulty adding backup options, contributing to higher chances of getting locked out (temporarily or permanently) that it could've been, would Passkeys be designed differently. ---- Both things don't explicitly introduce any new weaknesses, compared to passwords. But the problem with Passkeys is that they're here to stay for a long while. So a push towards "you must fix this before it's too late" petitioning collective FAANG (who are the only entities that were able to push asymmetric crypto to web, no grassroots movement was able to do this - many attempts were made and all had died in oblivion) is extremely important.
- dilippkumar 3y agoHottake here: The biggest mistake that the passkeys movement did is try to make it sound more marketable at the cost of oversimplification. First up, these aren’t really “no password” mechanisms. They’re closer to ssh certificates. You need to authenticate through some other mechanism and then agree to do the equivalent of creating and installing ssh certificates on your device. The ssh certificates get synchronized across your devices securely by your cloud provider. But they can never serve as the primary authentication mechanism - that will still have to be a traditional authentication mechanism. It’s mildly infuriating that someone decided to take this simple idea and confuse the fuck out of everyone by positioning it as some alternative to a password based authentication mechanism. Obviously everyone is going to come and ask a ton of questions about how a mechanism without any passwords should work. And then the responses further confuse everyone because they don’t want to admit “no actually you still need passwords” /rant
- grotorea 3y agoBut do you need passwords? The way things are setup now you do, the password is the recovery mechanism. If the recovery mechanism was instead something like "photo of face next to government ID" then Google could stop using passwords next week. > But they can never serve as the primary authentication mechanism - that will still have to be a traditional authentication mechanism. Why not?
- ghaff 3y ago> If the recovery mechanism was instead something like "photo of face next to government ID" then Google could stop using passwords next week. Think about the failure mechanisms. What government ID? Why might the face change? Etc. Even if these sound like outliers, at scale essentially anything will happen.
- vdelitz 3y agowhat if you sign up a new account somewhere with a passkey? Then, it's the primary authentication method, right?
- 3y ago
- JaneLovesDotNet 3y agoCorrect me if I'm wrong but isn't it fair to say that passkeys secured on your phone are more secure than 1FA (password) but less secure than "traditional" 2FA? Passkey 2FA: unlock your phone and the passkey on your phone can log you in. Traditional 2FA: remember a password AND unlock your phone (where your TOTP is stored) and you can login If I were to rate all 3 methods on a scale of 1 to 10, for convenience and security, I'd say: Method Convenience Security Password only: 4/10 2/10 Passkey 2FA: 9/10 8/10 Traditional 2FA: 6/10 9/10 Fair?
- orev 3y agoNobody should be using a remembered password anymore. Most people are likely using the phone for both the password and the MFA code.
- vdelitz 3y agoAgree
- JaneLovesDotNet 3y agoRight, in which case passkeys would be equally secure. But if you DO memorize the password (for example for your most sensitive account), then it feels like traditional 2FA is more secure. That being said passkeys win if you also take convenience into account. I've updated my original comment with convenience scores to reflect that.
- doublerabbit 3y ago> Nobody should be using a remembered password anymore. Nobody is a strong number, why? I don't want to use biometrics for logging in to my SSH terminal. I dislike having to use my phone for authentication methods. I go many places without my phone. Even tempted to gon on holiday without it. Maybe I'm just one of the few who actually enjoys turning it off when coding, developing or whatever.
- sbuk 3y ago
- PreInternet01 3y agoG: Here's a cool new security feature! HN: Yeah, but what if disaster scenario? A1: If you're authenticating to Google because your $DAYJOB mandates it, contact your Enterprise Administrator. As part of their multi-gazillion deal with the dark side, I'm sure there is some kind of support for a recovery mechanism, and if there isn't: yeah paid holiday until they figure it out! A2: If you rely on Google for personal-slash-small-business reasons, please refer to the previous writing on the wall, and accept that all is probably lost...
- Macha 3y agoI mean, A2 is a problem. I'd wager that more people are selecting how to manage their personal accounts than selecting how to manage accounts for an enterprise.
- deleted 3y ago[deleted]
- aboringusername 3y agoOne question I don't often see asked in regards to passkeys: what is the legal standing in regards to law enforcement access to 'passkeys' vs passwords? For example, it is completely valid to say I genuinely do not know my 1000 long multiple special character password; it could be on a piece of paper, in a file encrypted with multiple layers. Essentially, there is no foolproof way to ever prove whether I know a given password, or not, especially if the password is only ever in my head (assuming the plaintext version is never logged, all you would ever have as 'proof' is a hash to compare it to). Passkeys make it so that, I imagine, there is an element of 'proof' at all times; your face, fingerprints (which in some countries you are required by law to provide), I can't disprove I "own" my fingers so that element is always there, and you can be compelled to provide your fingerprints at any time for any reason - with a password, it is impossible to know whether I know a password. In that sense, a password is far, far, far stronger than any other method of authentication. Take a scenario: Mr Police wants access to your phone, it's protected only by your fingerprint, pretty easy to gain access. Now do the same but with a password that's sufficiently complex, written on a now shredded piece of paper, and there is genuine plausible deniability. I imagine in a lot of cases this is extremely important and passkeys will be shunned altogether.
- nicman23 3y agobut i cannot just use a password for IMAP ffs
- cjcampbell 3y agoI'm surprised that they're moving forward with this already. As of last week, there were still enough rough edges on their implementation that I disabled it for my Workspace tenants. The two most irritating: 1. Advanced protection doesn't yet support passkeys. You must keep U2F in place for now. 2. If you have a U2F key configured on your account, Google will prompt you to use it as a passkey before telling you that it's not a passkey and you must login with your password. The net result is that anyone using phishing resistant MFA loses the ability to have their MFA step "remembered" on a device because Google will always prompt for the U2F factor before the password. This aside, I've been doing a lot of testing with FIDO2 flows using security keys and passkeys across device types and platforms in preparation to roll out passwordless via Okta with a couple of smaller clients. Overall, I love the authentication flow, but there are a lot of gotchas to keep in mind. We've spent a considerable amount of time mapping out the happy path, creating onboarding resources, and documenting business continuity scenarios. The personal use case is actually more of a challenge in some ways, because you need to think about each service rather than just one IdP. FYI, the easy path right now if you need to support multiple environments is to invest in 1Password or another password manager that supports passkeys. This provides the most consistent user experience and works across most platforms, though we're still having trouble with Android 14. We're sticking to hardware keys for highly privileged accounts, so admins get a pair of FIDO2 keys. Everyone else gets one Yubikey, which serves as a backup if they lose access to their devices or need to login on an untrusted device. Android is also a problem here. Even in 14, it doesn't seem to support passwordless FIDO2 flows.
- prima-facie 3y ago> Android is also a problem here. Even in 14, it doesn't seem to support passwordless FIDO2 flows. Why would they? When Passkeys provide another opportunity for Google to lock-in their customers.
- cjcampbell 3y agoI probably could have framed this more clearly. I don’t think my point really supports the lock-in argument. Google has been a big proponent of FIDO, having been an early adopter of U2F in Chrome and leveraging it for advanced protection. More recently, they have extended Chrome support to FIDO2/passkeys and made this move to make it the favored means of authentication for Google accounts. Given that strategy, it’s a bit of a head scratcher to see Android lagging behind its desktop and mobile competitors. Why stick your mobile customers with second class support for the passwordless technologies you’re pushing everywhere else?!
- nottorp 3y agoNo one has managed yet to explain to me how you recover access to an account using these passkeys if you somehow lose access to all your devices. Note that i said "all your devices" so the cloud backup you dream of will also be inaccessible because I can't authenticate to that either. And I know about backups... what about your average user who is likely to own a single phone and no other device? They lose access to everything if they drop it in the toilet?
- secabeen 3y agoNow extend that; it's not you trying to recover access, it's your relatives or heirs trying to do so, because you are incapacitated or dead.
- sbuk 3y agoLegacy contact https://support.apple.com/en-gb/HT212360 https://support.apple.com/en-gb/HT212360 Account recovery contact https://support.apple.com/en-gb/HT212513 https://support.apple.com/en-gb/HT212513
- jiveturkey 3y agohttps://safety.google/authentication/passkey/ https://safety.google/authentication/passkey/ > Yes, you can continue to log in using your traditional log in [sic] method, which in most cases would be using your username and password.
- zackmorris 3y agoWill this work for social login, like if I use my iPhone to sign into Gmail with a passkey, can I then sign into Reddit with Gmail and not have to enter a password? I'm assuming so.
- Bluecobra 3y agoSo what happens when I die and my spouse or next of kin has to deal with this stuff? As the executor of my father's estate, he kept a physical password book that was instrumental in making it easy for me to settle his affairs.
- sbuk 3y agoLegacy contacts. https://support.apple.com/en-gb/HT212360 https://support.apple.com/en-gb/HT212360
- wkat4242 3y agoHmmm. I don't want to be dependent on any cloud provider for my logins. Any passkey solution must be fully self hosted for me to accept it. Is there such a thing yet?
- the_snooze 3y agoI use Yubico Security Keys as passkeys. One at home, one in my office, one on my person. All with a local PIN lock (and 10-failure-device-reset) so simply having the hardware is insufficient to log in. The only annoying thing about this setup is having to manually add each key to each new passkey-enabled account I have.
- wkat4242 3y agoYeah I have yubikeys, the problem is that most of the services I use don't offer to enroll more than one. Also there's the issue of limited slots on each key for passwordless. I like the whole idea of syncing a single key. But the whole chain must be owned by me and me alone.
- kats 3y agoDon't quite know how these work yet, but I appreciate how much work it took to make something good enough that it was approved. Cheers
- k8svet 3y agoOh I'm seething. Screw google, so god damn much. They've been accidentally enabling it for nearly a month if not more. And the UX has been infinitely confusing. I've been using 2fa for a decade (not an exaggeration, an understatement). I've been using u2f since the first month it was available and FUCK Google for this blog post. A month ago I logged in and tried to check on my security tokens. Their UI was silently upconverting them. Without telling me. And the flow made it look like it was just deleting them. Hours later I realize it had re-enrolled them AND IT LOST THE DESCRIPTION I GAVE TO THEM. To be clear, it trashedt the decription I gave them during (what I didn't know at the time) was re-enrolling them as passkeys, because i sure as hell wansnt in the passkeys area. So not only did I inadvertently change them, they're now indistinguishable and unidentifiable to me. So if I want to ensure my primary and backup tokens are enrolled properly , I have to do it all over again, with all of them in my possession Seriously, I have defended google against all sort of claims with respect to their 2FA and they can absolutely get up their own after what they pulled, and now this blog post. Do some god damn basic (user) testing FFS. I would literally pay $1000usd right this second to scream at the people who green-lit and implemented this. And another $1000usd to ensure to people here that I know DAMN WELL what I'm talking about here. It's not like I don't have video evidence of exactly what I'm stating here on an unlisted YT video tweeted at Google Security. Edit2: to be VERY clear, I have a video I reviewed, just now, that shows me trying to enroll an existing Security Token with a description, it disappearing, it then appearing as a Passkey with no description.
- sillysaurusx 3y agoYour comment would be more impactful if it explained clearly what the problem is. What does it mean to upconvert a security token? In fact, what’s a security token? (I ask mainly so that I can watch out for whatever bit you. On the face of it, the blog post seems pretty anodyne. The screenshot shows that it’s optional, not forced, since there’s a "not now" button.) EDIT: oh, they auto converted your security keys to passkeys? With no option to roll back? Yeah, that’s not great. https://support.google.com/accounts/answer/6103523?hl=en&co=GENIE.Platform%3DAndroid https://support.google.com/accounts/answer/6103523?hl=en&co=...
- 3y ago
- latchkey 3y agoStill can't store passkeys in Bitwarden, which is a bummer. Should be coming in Oct though per the message at the top of this page. https://bitwarden.com/blog/bitwarden-passkey-management/ https://bitwarden.com/blog/bitwarden-passkey-management/
- HumblyTossed 3y ago> What are Passkeys? > Passkeys are a new way to sign in to apps and websites. They’re both easier to use and more secure than passwords, so users no longer need to rely on the names of pets, birthdays or the infamous “password123.” Instead, passkeys let users sign in to apps and sites the same way they unlock their devices: with a fingerprint, a face scan or a screen lock PIN. And, unlike passwords, passkeys are resistant to online attacks like phishing, making them more secure than things like SMS one-time codes. I HATE paragraphs like this. It's as if you're purposely obfuscating what they really are.
- deleted 3y ago[deleted]
- gumby 3y agoThis may cause me to "up"grade to 1Password 8, which I have been dreading.
- LeoPanthera 3y agoBe aware what you're getting into: https://news.ycombinator.com/item?id=37836783 https://news.ycombinator.com/item?id=37836783
- sbuk 3y agoBeware of spreading FUD. Password managers like 1Password sync the data locally. If they are offline, for whatever reason, you can still access the passwords locally. You can easily test this by disabling networking on your device and accessing your data in the 1Password apps.
- gumby 3y agoUgh.
- rawgabbit 3y agoWhile I believe this is a step in the right direction. I have read too many horror stories of people who were locked out of their Google and iCloud accounts with no real possibility of getting back in. I don’t think I am alone in thinking I am on borrowed time. Someday, probably due to my own fault I will be locked out of Google and my digital life will be over. If a private company can offer a similar login method like login.gov and let me talk to a real person when I am locked out like the USPS, I will be screaming shut up and take my money.
- skybrian 3y agoImagining pessimistic scenarios is useful if it spurs action. In this case, appropriate action would be to learn about Google's account recovery options and take advantage of them. Make sure you have multiple, independent ways of logging in. (For example, by printing out backup codes and keeping them with your important papers.) But even this can't protect against getting locked out of your Google account due to some Google policy change, so ideally we'd rehearse how to get by without it.
- hedora 3y agoI haven’t heard of people getting locked out of iCloud. Losing all your devices nukes E2EE stuff, but that’s not much stuff by default. In particular, photos, device backups and messages are recoverable. I thought the Apple Store would check your driver’s license or whatever and reset your password, recovering whatever is protected by the escrow keys. I know Google loses accounts all the time, mostly thanks to “surprise 2FA” combined with zero tech support. I’d believe Apple screws this up too, but I haven’t heard any anecdotes. Care to share a link to examples?
- verytrivial 3y agoDisaster recovery. This is 100% my biggest worry with 2FA/MFA. I also think this is one of the reasons stuff like PGP never took off (don't @ me regarding perfect forward secrecy): the problem has always been managing some little, precious thing and the ramifications of what happens if it put beyond use or is used by some bad actor.
- jiveturkey 3y agoI feel that this is net negative. You have to meet people where they are at. per some support document (sorry lost the link), by default, Android users will have passkeys synced to their google account. So first of all, this is a lock-in play on Google's part. The passkey FAQ only mentions iCloud, so second of all it's a duopoly reinforcement. (This really needed Apple to first release passkey support.) Beyond that, there are so very many ifs, ands, and buts around recovery and third party device usage that a typical user can't really keep it straight. It's more convenient ... until it isn't.
- fortran77 3y agoMy 90 year old mother saw this change, clicked on something she can’t remember, and now can’t login. She’s been able to login using the username and password she keeps on a card next to the computer just fine up to now.
- LeoPanthera 3y ago1Password enabled PassKey support recently and I was "surprised" to learn that there is no way of exporting them out of 1Password. They're not included in the 1PUX format export, nor in the CSV. That means that they're literally impossible to back up. If 1Password goes down, or the company stops operating, or anything else like that, your Passkeys are just... gone. Absolutely no way to recover them.
- numpad0 3y agoCan't you enroll a Yubikey and keep it in a safe?
- maxwellg 3y ago1Password's Passkey support feels very aggressively growth-hacky to me. They intercept calls to `window.credentials` and if you want to use 1Password along side other verifiers like Yubikey, you need to go into your settings and disable their passkeys offering entirely. It's similar to how they also intercept (and globally disable!) Google One Tap prompts in order to show their own OAuth prompt. I only use their Chrome extension so I'm not sure if the native app experience is significantly different.
- LeoPanthera 3y agoI'm kind of mad at 1Password - but this isn't correct. When the 1Password prompt some up, you can click the little "USB key" icon which ostensibly is for hardware keys, but all it does is pass control back to the OS, at which point your iCloud prompt, or whatever provider you are using, can be used.
- maxwellg 3y agoAh, good to know. I immediately turned off the monkeypatching and didn't spend too much time playing around with it.
- shepherdjerred 3y agoIt's a feature that came out just last month. Give them some time.
- rkagerer 3y agoIf I may, I'll repeat a comment I made a few days ago: Give me an implementation I can self-host, without Google, Apple, etc. having effective control (including claws in my relevant software supply chain) and with an easy user experience, where I can maintain secure backups (on my own infrastructure, thank you) and smooth transition to future devices, and ideally, if needed, securely export root keys (cause if I don't control them then someone else owns them), and maybe I'll be interested. In the meantime plain old high-entropy passwords with a good manager gives me all those features and a simplicity that's hard to beat. In my 30+ years of computing I've suffered more harm from failures of other companies than I have from any failure of my own diligence. The whole lesson learned is to reduce trust in them and, maybe I'm wrong, but everything I've read about passkeys and the like seems to put me at liberty of the companies developing and pushing the implementations of them down my throat. It will take a lot of trust before I give up my ability to copy/paste my credentials. (https://news.ycombinator.com/item?id=37794379#37796842 https://news.ycombinator.com/item?id=37794379#37796842)
- CharlesW 3y agoPresumably your current password manager meets those requirements. Why not just use it (if it doesn't support passkeys today, it surely will) to manage your passkeys as well?
- deleted 3y ago[deleted]
- whartung 3y agoAs I understand it (which mean I can be completely wrong), in order to utilize Passkeys, at least at the browser level, you need support within the browser. Firefox has a build that supports passkeys, and I believe 1Password has an extension for Firefox that supports passkeys. If "all you need" for Passkey support is a custom extension, it should be straightforward to create one that does whatever you want (including storing your private keys in plain text in your home directory, which many argue is a bad idea, but that's not the point). Is 1Password a magically signed and authorized extension, or can any Joe pound out a quick hack using JS and Firefox? I appreciate that the client and credential management should be sophisticated and secure, etc. But the API is the API, it's supposed to be an open API, and I can understand Chrome, Safari, and Edge, being closed source browsers, may or may not allow anyone to hack their own keystore regimen. But, I don't think Firefox is doing that (unless the 1Password extension is magically blessed by Firefox somehow). At a minimum, you can always go the source, and rebuild Firefox to do what you want. Involved, to be sure, but possible.
- shadowgovt 3y agoPasskeys make accessing all your online services as easy as accessing your phone. ... that is a statement that some people will find convenient and some people will find terrifying. As much as I'm excited for the convenience, this is my primary concern: how easy is it for a stranger to unlock your phone? Most people intentionally keep their phones easy to unlock because they're doing that dozens of times a day.
- TacticalCoder 3y agoSo what is going to happen to those who were using U2F and then later on webauthn? If you registered, say, a Yubikey, many moons ago, on your Google account. Is this Yubikey now automagically going to become a "passkey"? Or will you have to choose between logging in with your Yubikey or with a new passkey? (say something Google controls, in your phone for example)
- enasterosophes 3y agoI just tried turning one of my yubikeys into a passkey on my google account to see what will happened. The response was that the device is not valid. I think they are keen on biometrics for their passkey implementation?
- qudat 3y agoI'm probably wrong but I expected passkey and yubikey to be interchangable. So if you are presented with a browser prompt for webauthn, you can use yubikey or passkey
- efitz 3y agoThere's a good, simplified diagram of how passkeys work here: https://github.com/passwordless-id/webauthn#how-does-the-protocol-work https://github.com/passwordless-id/webauthn#how-does-the-pro...
- leotravis10 3y agoLauren Weinstein is sounding the alarm on passkeys which is flawed and that it would make a huge headache for a lot of people especilly normal folks. https://mastodon.laurenweinstein.org/@lauren/111103819626952178 https://mastodon.laurenweinstein.org/@lauren/111103819626952... https://mastodon.laurenweinstein.org/@lauren/111211366080459949 https://mastodon.laurenweinstein.org/@lauren/111211366080459...
- d-z-m 3y agoTo me, it's unclear what the headache is. If the argument is about the consequences of passkeys for most ordinary people, most people are signed into their google account on their mobile device. In that case, your account is compromised anyway if your device authentication is breached. For Google in particular, password/passkey isn't a binary choice(currently). You can fall back to the password sign-in flow if your device doesn't have a passkey.
- two_handfuls 3y ago“Weak device authentication”? I though all phones had fingerprint scanners or face scanning nowadays?
- deleted 3y ago[deleted]
- zestyping 3y agoThis debate is frustrating because it lacks data — it's full of opinions about which risk is worse than which other. To compare the risks and benefits, we need to know how often people actually re-use passwords, use 2FA, rely solely on their phone screen lock for access to all their accounts, use biometrics, need account recovery, and so on. That data is the only way to settle the debate (and would allow each person can settle it for themselves, perhaps differently based on their circumstances). Google has most of this data. They should publish it to back up their claims.
- grotorea 3y ago
- mission_failed 3y agoMost accounts with passwords have the fail-safe method of 'prove my identity to company, they reset'. I.e if you can't remember your bank password, there are paths for the bank to reset for you. Anything that Google controls you have absolutely no way to get in contact to resolve issues. This is already a problem with all of their products. Locking all of your access behind a Google controlled door is just setting yourself up for a future nightmare.
- garganzol 3y agoWhat happens if the phone is lost? A famous Google support, I presume?
- theyknowitsxmas 3y agoIt's stupid these are required just to enable TOTP.
- jiggawatts 3y agoAs others have pointed out, cryptographic authentication is very hard to bootstrap if you simply loose your device. Just last month my missus cracked the glass of her iPhone. Apple repaired it under AppleCare, which is great… except… that they didn’t tell her that the “glass repair” entails them replacing the guts of the phone and wiping it in the process. Apple iPhone backups don’t contain cryptographic secrets like eSIMs! She got stuck in a loop where she couldn’t activate her eSIM because that needed her email, but her email needed MS Authenticator, which she couldn’t activate without an SMS. She had to drive to the Telco with a pile of photo ID to reissue her eSIM. Her bank account got locked in the process despite the password being correct because of some sort of phone hardware lock. This took days to fix and multiple in-person visits to various organisations. If this had happened while overseas on holiday, she would have been screwed. Times have changed. Your entire digital identity is now a smart card in your phones That Smart Card is either a SIM card or an onboard TPM chip, but in any event if you lose it, you may as well be dead as far as anyone else is concerned. Passkeys make this much worse. At least if you still have a physical SIM you can transfer it from any phone to any other phone. Passkeys are not cross-vendor transferable! Run away screaming. Don’t believe the hype. Wait until the vendors get their act together and come up with a solution for transfer and recovery.
- hbt 3y agowhat you are describing is why I use a virtual phone for all services. you can do it on your own with twilio, then create a phone number and have a program forward you stuff to your real phone. the twilio phone is hard to lose as it has an api and you can toss it when you want to start over. except now, you need an entire phone virtualized as your proxy instead of just a twilio phone number. they keep raising the barrier
- jesseendahl 3y agoThis provides significantly weaker account security than using a passkey. 2FA codes delivered over SMS can be phished.
- 3y ago
- pentagrama 3y ago>To use passkeys, you just use a fingerprint, face scan or pin to unlock your device, and they are 40% faster than passwords >We’ve found that one of the most immediate benefits of passkeys is that they spare people the headache of remembering all those numbers and special characters in passwords. So they aren't considering at all how easy is the autofill password feature with a password manager (that they even have built in Chrome/Android).
- jesseendahl 3y ago>So they aren't considering at all how easy is the autofill password feature with a password manager Passwords are a nightmare for both users and service providers for a variety of reasons. And password autofill is a bandaid at best. If I had a quarter for the number of times I've personally used a password manager to auto generate a password which was then either reject by the website due to absurd password complexity requirements, or had the password seemingly accepted but in reality silently truncated behind the scenes.... I know you're commenting on a Google blog post, but FWIW Apple acknowledges password managers/autofill in the "Deploy passkeys at work" talk from WWDC 2023: "Let’s look at a side-by-side comparison of the experience of creating a new password versus creating a new passkey. As you can see, creating a passkey is significantly faster and easier than creating a password. Just Face ID and you’re done. Now that we’ve looked at creation, let’s compare the experience of signing back in. With a password, the user has to remember and type in the password. With a passkey, they just Face ID and they’re done. A password manager can help improve the experience, but even the best password manager can’t compete with the user experience of passkeys. You are used to having to make tradeoffs between better security and a better user experience. Passkeys achieve something rare: great security and a great user experience." Source: https://developer.apple.com/videos/play/wwdc2023/10263/?time=309 https://developer.apple.com/videos/play/wwdc2023/10263/?time...
- gomox 3y agoIn practice the actually concerning use case is not creating a key or using it, but safeguarding it and recovering it.
- 3y ago
- nytesky 3y agoCan you store a passkey on a YubiKey? Or just buy a $100 android phone just for passkey backup to keep at home?
- Shank 3y ago1. Yes! Using resident keys, yubikeys can store a number of them. Not an infinite number. It's 25 resident keys. 2. Most services let you add more than one passkey. Using 1Password, or using iCloud Keychain or similar, you can sync passkeys between devices. Even with iCloud Keychain, if you have only one device, you're given a recovery code that can bootstrap the entire system from zero if your only device is stolen.
- december456 3y agoI wont add on to the technical aspect of the discussion, but this whole article is "its easier and its faster and its less expensive for you!!", a data-harvesting tactic having been done for years. Please think, people. I get the security aspect, but this technology gives up an astronomic amount of personal freedom - even if vendor lock-in is somehow eliminated - and biometric data.
- jesseendahl 3y agoYou don't know what you're talking about. Biometric data is only stored on your device. Logging into an app or website with a passkey just uses bog standard asymmetric crypto (public/private keypair). Also a lot of thought was put into the WebAuthn standard (an open standard) to make sure it can't be used as a tracking vector.
- sbuk 3y agoPlease think. The biometric data is on-device. This is, in very simplistic terms, public key cryptography where the private key is locked to a device. How that device is authenticated is immaterial to passkey authentication to another service.