3 ms·
But don't you also get into that account via your passkey? How do you know that the passkey you are using to get into the Google/Apple account isn't the same on
by Nathanba 2y ago
But don't you also get into that account via your passkey? How do you know that the passkey you are using to get into the Google/Apple account isn't the same one that will be lost if you lose your phone? I've actually implemented passkeys on my website and I still don't use passkeys for e.g my own Google account because I don't trust it.
- vel0city 2y agoI actually recently unexpectedly broke my phone. Getting back into my Google account protected by passkeys was pretty simple though, I just logged in to my new phone with a passkey stored on another device. Which is fine, because I've got several different devices with passkeys on them. Same thing with logging into my mail provider which I use passkeys for. A few accounts I did have to go find a backup passphrase for, but none of those accounts are the kind of accounts I'd normally be trying to get into while on vacation or something. I don't travel very far or very long without a couple of different authenticators. If its farther than a bus fare and I'll be gone for a while, I'll probably have at least two, maybe three authenticators on me. For example, my phone, my laptop, and a yubikey. Its only a few dollars for the public transit around me, so if my car explodes on the other side of town with my bag containing my keys and my laptop in it and I had to jump out into the river to avoid the explosion and debris and it broke my phone I'll still be fine to get home with a few dollar bills in my pocket. Or hopefully those other physical security tokens commonly called credit cards will also still work. And there I'll probably have my desktop at home and another yubikey. But honestly that kind of thing doesn't happen to me too often so I'm not too worried.
- Nathanba 2y agoAll you said is that it worked for you, you even emphasize that your usecase was different because you have several devices. This doesn't relate to my question.
- vel0city 2y ago> your usecase was different because you have several devices So we just normalize having multiple devices, and suddenly my use case is the same as everyone else's. Its not like I'm talking about everyone having a dozen $1,000 devices. Several of my authenticators were like $20-30 and have lasted over a decade even getting thrown in the washing machine and getting left in the rain and dropped in the pool. One was on my keys when I was daily driving a motorcycle in a rainy season and still works a decade later. People don't find it weird to have two car keys and those things often cost hundreds of dollars these days to be replaced.
- Nathanba 2y agoPeople aren't going to buy little usb sticks, some phones don't even have usb ports and the NFC or bluetooth connection never works properly. Also generally even having multiple devices isn't going to save you when you really need saving. Like in a house fire or while on vacation and your phone breaks, who really keeps a second phone around constantly with all the passkeys on it, like e.g in your hotel room? Then what if someone breaks in and steals your backup phone, now you have to invalidate all those passkeys somehow right? I also don't know whether there is even any recovery process planned or possible, I guess not? So why on earth would I pick a new system like passkeys where I can't just have Google email me a new password vs. a system where that is impossible? Effectively my email account is like a second device in the password system which is far easier to carry around than a physical device. Sure a second, different email account could get itself password guessed but the chances of that are so small, it's pointless to think about and even if it does get hacked, even then it probably wont matter because it will only get used during recovery processes for a few seconds. It also still doesn't answer the question around how I would know whether the passkey I created on a different device will work. One time a login process on Windows told me to use a QR scanner via my phone and then I got logged in. Okay so did that create a new passkey now and where? Both devices were involved in the login process, it was unclear to me. Maybe it was also the registration process, they are so similar now that I can't remember. I guess maybe half the problem is that the proposition seems so strange: We are being told that all of a sudden having multiple "passwords" for the same account is actually great, it's secure. In fact: Just have a new password for the same account on every device, you can just keep creating new passkeys and it's no problem at all?! Oh and btw, if you lose any one of those your entire account is utterly compromised and good luck figuring out which of those passkeys you have to invalidate now. Somehow this is okay and secure.