4 ms·
Cool, where are they stored? (I know the answer: 'it depends', and that's the big problem with their usability: most users haven't a clue what the answer is and
by rcxdude 23d ago
Cool, where are they stored? (I know the answer: 'it depends', and that's the big problem with their usability: most users haven't a clue what the answer is and most tech support can't answer that question straightforwardly because it depends on some decisions the user probably didn't even realise they made).
- wolvoleo 23d agoIn a secure vault on your phone
- mystifyingpoi 23d agoSo if I drop my phone to the toilet, I will forever lose access to everything? Since the vault is on my phone.
- faust201 23d agoA majority have more than one phone. Or at least they can get a new SIM card and sign into the iCloud account. Then all passkeys are synced from cloud. Yes, if you are edward snowden then not for you. For rest of us - it is useful
- caryme 23d agoA majority have more than one phone?
- faust201 23d agoOr they have a laptop or tablet - even the cheapest one that has logged into Google or Apple. That way they can recover.
- chrystalkey 23d agoIdk how much money you must be having, but all of my bubbles only ever go with one device
- faust201 23d agothis is ridiculous. I don't even have a bubble device. Run lineageos in a decent 2020 device moto G32 for €100. Yes, you can afford to host everything locally. Not everyone can.
- recursive 23d agoThis is crazy. I have one phone and zero iCloud. I don't think I'm that unusual.
- faust201 23d agoYou are exaggerating. If the loss or lockdown is so bad then many would have stopped using any of icloud or google equivalent. People are able to depend on it. People are able to repair and use phones even when it falls into abyss.
- recursive 23d agoWell, I mean yes. People for whom it works. Others never started.
- rcxdude 23d agoNot always. And which vault? There can be multiple on a given device. This isn't some hypothetical 'mollify the user's worries' question, this is an important practical question of what do they need to worry about losing access to. Trust me when I say that most users I have talked to have absolutely no idea about this, and usually only find out when they've already lost them.
- malfist 23d agoHow do I use it on my desktop or laptop then? What if I switch browsers on my phone? What if I get a new phone? What if I change from android to iOS or visa versa? What if I need to log into the site on my Wii U's browser?
- faust201 23d agoas long as you have one working device all will be OK. Either you scan the QR code shown by the website. or if you did login to Chrome with google account then desktop or laptop will just sign you -friction less. Same with iCloud account. If you browser vendor has implemented passkey then all good. Most things are built for the majority users. Most don't change. Most don't debate browser wars in hn. Life is like that. For Wii etc. You just scan the QR code shown in the TV interface. all just works. Yes, if you want 100% privacy and will do only your own dovecot server then it is not for you.
- Johnny555 23d ago>How do I use it on my desktop or laptop then >What if I switch browsers on my phone >What if I get a new phone You can let Apple sync your passkeys between devices using iCloud Keychain. Then you can create a passkey on one device and have it available on all of your devices. Google also syncs passkeys to the cloud and lets you use them on Windows (with Chrome) >What if I change from android to iOS or visa versa I resolve this by storing most of my passkeys in my password manager. I still store the "important" ones (like online banking) in my phone so a password manager breach doesn't make me lose my money. >What if I need to log into the site on my Wii U's browser? Passkeys were designed to let you have more than one, so if you have a device that doesn't let you use your password manager, then just set up another passkey.
- cpburns2009 23d agoGreat, what happens if I lose my phone?
- iamnothere 23d agoOn my keychain in a USB hardware token. With a couple of backup tokens in fire safes.
- rcxdude 23d agoIf you're using a USB hardware token your knowledge of it is at least an order of magnitude better than the median user's. I know where my passkeys are stored, I don't know where my family member's passkeys are stored and neither do they. The same is true for most of my otherwise fairly technical co-workers.
- iamnothere 23d agoThere needs to be industry and government leadership on this to gradually require hardware token usage, for at least critical financial and government applications. Right now everyone is putting their energy behind passkeys, but those are much harder to understand than a physical token. I don’t know any non-technical people who understand how passkeys are normally tied to the device (or the manufacturer-provided cloud account in some cases), how to set them up on a second device, why you might want to do that, etc. And many technical people still don’t get it either!
- ampersandwhich 23d agoAbsolutely not. If that is required, I will do my damndest to only use implementations that deliberately lie about the hardware status. Your line of reasoning is dangerous.
- faust201 23d agoThen that family member does not worry like you do worry. The main point is assuming one can have a proper security for Google account - everything else becomes easy. The fearmongering of losing google account should stop. Yes, some people lose it. There are a larger proportion losing/getting pwned by repeat use. For the majority - just pressing the fingerprint to access an account (like amazon/eBay) via passkey is great. Fairly technical co-workers - I used to suggest them to buy USB security key few years ago. Now that same fairly technical some how has at least 2 devices with them - so they just skipped the USB security key need - and just use Google (in Android) or iPhone in Apple ecosystem. Everything just works. Yes, there will be a poor soul that may lost everything with only one device.
- qmmmur 23d agoin 1password