4 ms·
Simpson's Paradox lives here. On average, this might increase security (the vast majority of users are terrible at using passwords). For proficient users who
by rmellow 3y ago
Simpson's Paradox lives here.
On average, this might increase security (the vast majority of users are terrible at using passwords).
For proficient users who use passwords securely, this is an acute drop in security (if forced to use).
Forced phone number 2FA has the same effect; in Big G's case forcing phone number 2FA is anti-anonymity disguised as security. In this case, it's a bid for biometrics.
- forward1 3y ago> Forced phone number 2FA has the same effect; in Big G's case forcing phone number 2FA is anti-anonymity disguised as security. It can actually be both; in fact it very likely needs to be: 1. Phone numbers are the best long-term identity most people have 2. Google has billions of users and needs to support account recovery at unbelievable scale 3. Many people lose passwords and devices, but very few lose phone numbers It logically follows google uses phone numbers to assign and delegate identity on their platform. Is this bad for privacy? Yes, but it's also very good for security because it allows users to control their data using a third-party authenticated "credential" they don't have to manage.
- rmellow 3y agoAll of this is valid! But it would be even more secure if there was an opt-in "I don't want to use my phone as 2FA". Phone number authentication creates a weakness for anyone who is in a targeted attack. A motivated attacker can easily bribe/trick a telecom employee, or if physically accessible, swipe the phone itself to read 2FA texts.
- px43 3y agoSign up for Google's Advanced Protection Program. It's been around since 2017, and last I checked, it's the only way to fully disable the use of your phone number for authentication. https://landing.google.com/advancedprotection/ https://landing.google.com/advancedprotection/
- grotorea 3y ago> For proficient users who use passwords securely, this is an acute drop in security (if forced to use). Why? Because the user can have their device stolen and the PIN guessed? Can't you use a long password instead of a PIN if you want to? And this part I'm not sure of, please correct me if you know. If I understand it correctly there's one security advantage even assuming a sophisticated user who is immune to weak passwords, password reuse or phishing. If there's ever a leak of Google passkeys, the leak would only get public keys, which can't be used for login, making the leak mostly useless.
- raxxorraxor 3y agoI live in a country where my phone is forcibly tied to my identity. I will not use it to authenticate anywhere. For business purposes with my business phone perhaps, but certainly not for my private life. That would be a huge decrease in security.
- novok 3y agoPasskey isnt google or apple dependent. You can have holders / managers that are your own, which is necessary for corps and govt.
- aseipp 3y ago> In this case, it's a bid for biometrics Biometrics are used to unlock an local, on-device key storage mechanism which contains a private key, and from that you can derive a public key, and that's what Passkeys fundamentally are, is a public/private keypair you use to validate you are logging into a website. If Google were harvesting your biometrics they were just doing it already and it has nothing to do with this. This is an extremely basic detail of the security model that has been true since long before these were introduced, back when the iPhone started using e.g. the secure enclave; I don't know why people on this website talk so adamantly about things they clearly do not understand at all. It's honestly kind of astounding. > For proficient users who use passwords securely, this is an acute drop in security (if forced to use). No, it isn't, it's the moral equivalent of an SSH key to login to a server instead of using SSH password to login to a server, but now apply that to a website. And beyond that, it's objectively wrong; for instance passkeys are literally phishing resistant, and no amount of thinking you can "use passwords securely" can change that simple fact.