6 ms·
Passkeys are a new technology and everyone - including users, service providers, and organizations - will take time to learn and adapt. In this interim period t
by skarra 3y ago
Passkeys are a new technology and everyone - including users, service providers, and organizations - will take time to learn and adapt. In this interim period the recommended approach is to provide passkeys as an alternative to whatever is already offered. This is the approach that Google and many other service providers are taking.
That said, you are bringing up the right questions on the general topic of account recovery that everyone should be asking even without passkeys: "How would I login if I forget my password / lose access to my password manager / lose my second factor devices" and have a plan. Introduction and adoption of passkeys do not completely eliminate the need for thinking about your account recovery situation.
However, there is one special case where using passkeys is actually better for account recovery. If you create passkeys for your Google account on an Apple device with iCloud keychain, the passkeys are synched to your iCloud, so now even if you lose all your devices because your house burned down, as long as you have access to your iCloud account, you can just get all the passkeys for your Google accounts(and other websites).
Now, you may ask: 'what if I lose access to my Apple iCloud account" -> that's a fair question! Which is why I said Account Recovery concerns do not completely go away - but they can be significantly reduced with passkeys in many cases.
- pseudalopex 3y agoYou should disclose your employer more consistently.
- skarra 3y agoI work on Google's authentication team. I have mentioned this elsewhere in the thread.
- pseudalopex 3y agoYour other disclosure is why I said more consistently. Do you believe all readers will read all comments and index mentally by user name?
- CogitoCogito 3y ago> That said, you are bringing up the right questions on the general topic of account recovery that everyone should be asking even without passkeys: "How would I login if I forget my password / lose access to my password manager / lose my second factor devices" and have a plan. Introduction and adoption of passkeys do not completely eliminate the need for thinking about your account recovery situation. Talk about victim blaming. Google and other companies introduce policies that make total identity lockout both easier and more problematic. Instead of investing in customer service to deal with this issue, the customer needs to "have a plan". What a crazy coincidence that this policy increases Google's profitability by decreasing support.
- LolWolf 3y agoBut you can set family members/significant others/etc as possible recovery mechanisms! This seems like a really workable solution that I don’t see people discussing in this thread?
- CatWChainsaw 3y agoAren't people lonelier than ever, have fewer friends than ever, live alone more than ever, fall out with their families more than ever?
- vorpalhex 3y agoRearranging deck chairs on the titantic. This whole scheme depends on either users being savvy enough to do vault backups or depending on service providers being functional. Both are quite doomed. Users have a path for passwords - they can write them down on paper and keep them with their important things. This tends to work for most folks. The backup story for passkeys is horrible. There is no path for my elderly relatives who don't use cloud services. Until that is fixed, passkeys will never replace passwords. Don't forget password sharing! That is a whole screwed up story with passkeys too.
- skarra 3y agoPasskeys represent the cumulative wisdom and experience (and compromises!) of the whole industry on how to keep users safe online. Appreciate your opinions that these efforts are doomed. It is safe to say, "We'll surely find out!"
- CogitoCogito 3y ago> Passkeys represent the cumulative wisdom and experience (and compromises!) of the whole industry on how to keep users safe online. That is true _if_ you do not highly weigh all the concerns that have been brought up in this thread today. I do not trust Google to help if things go wrong so why would I ever consider such a system wise? Frankly, you seem to be ignoring concerns if they contradict your belief that this system is better. I'm reminded of Upton Sinclair.
- pseudalopex 3y agoDid you see they worked for Google? Or did you guess correctly?[1] [1] https://news.ycombinator.com/item?id=37833206 https://news.ycombinator.com/item?id=37833206
- vorpalhex 3y ago"The Industry" also has interests like making password sharing impossible, uniquely tracking users and _doesn't care_ if users get locked out. The industry does not put users first. It puts it's own risk reduction first.
- jasonjayr 3y agoHow can a user, right now, take control + ownership of backing up their own pass keys, without iCloud or Google? This is a privilege I currently enjoy right now, and one I am not really eager to give up.
- vel0city 3y agoI've got security keys on Yubikeys, Android devices, and Windows devices. Only one of these are Google.
- shepherdjerred 3y agoI use 1Password [0] for syncing passkeys, and it works quite well. I would imagine other password managers are building similar features. [0]: https://support.1password.com/save-use-passkeys/ https://support.1password.com/save-use-passkeys/
- pseudalopex 3y ago1Password does not give control and ownership.[1] [1] https://news.ycombinator.com/item?id=37836783 https://news.ycombinator.com/item?id=37836783
- skarra 3y agoPassword managers like Dashlane and 1Password have announced support for storing and synching passkeys. As passkeys becomes more popular I expect more providers to step up as well. Ecosystem lockin is not how we make a new technology like this successful. And all players in the game understand that.
- pseudalopex 3y ago1Password does not give control and ownership.[1] [1] https://news.ycombinator.com/item?id=37836783 https://news.ycombinator.com/item?id=37836783
- jasonjayr 3y agoAppreciate the response. And I wish this message was front and center. The Attestation feature is what worries me, when, say, the bank turns it on for a few 'blessed' providers, or mandate a hardware implementation. Watching https://github.com/keepassxreboot/keepassxc/issues/1870 https://github.com/keepassxreboot/keepassxc/issues/1870 with baited breath... :)
- drdaeman 3y agoAll those issues were obvious from the day zero, and raised multiple times by many people. They're deliberately ignored by the stakeholders. They strongly want to lock you in to their own authentication platforms (iCloud Keychain, Windows Hello, 1Password*), that's why they don't want to address this. It's impossible they're not aware about those issues. Anyone with a brain and some technical expertise would come up with those questions in an evening or two, and Passkeys were worked on for months. To best of my awareness, there is no official acknowledgement (support replies "no, you can't do this" doesn't count, that's just restating facts, not acknowledging an issue). *) Ok, 1Password says they're all about user freedoms and that it's up to user to decide where they store their passkeys - but that's what they say, not what they do. What they do is indistinguishable from Apple and Microsoft.
- jesseendahl 3y agoYou can recover access to your iCloud Keychain even if you've lost 100% of your devices. See the section titled "Recovery security" in this article: https://support.apple.com/en-us/102195 https://support.apple.com/en-us/102195 Relevant excerpt for those too lazy to click through: "However, it's also important that passkeys be recoverable even in the event that all associated devices are lost. Passkeys can be recovered through iCloud keychain escrow, which is also protected against brute-force attacks, even by Apple."
- drdaeman 3y agoIf I understand it correctly, this only works on another Apple device, though. So you'll need a spare iPhone or something. Also, I'm pretty sure if Apple decides to block your iCloud account, you're most likely SOL.
- vorpalhex 3y ago> To recover a keychain, a user must authenticate with their iCloud account and password and respond to an SMS sent to their registered phone number.
- skarra 3y agoOn account recovery, the user is strictly no worse off with passkeys relative to passwords and arguably actually better off in many cases. This is not what I'd call deliberately ignoring concerns.