3 ms·
Now we aren't talking about a security problem, we're talking about who really owns what. Google can lock you out of your account no matter what kind of authen
by krupan 13d ago
Now we aren't talking about a security problem, we're talking about who really owns what. Google can lock you out of your account no matter what kind of authentication they use for that account
- Telaneo 13d agoIt's a lot easier to be locked out with a passkey than without one.
- krupan 13d agoNo it's not. Google flips a bit in their database and no matter what kind of authentication you set up with them, you get denied
- Telaneo 12d agoThis does not reflect my own lived experience. But if true, that means that Google can choose to not provide you a recovery service, which is functionally the same as them not having it.
- krupan 12d agoI'm not even sure what your point is anymore. If Google decides they don't want you to log in anymore, you can't log in anymore. It doesn't matter if you try to log in with a passkey, a password, your fingerprint, or sending a secret code in with carrier pidgeon. This has nothing to do with passkeys vs passwords vs anything else. If Google does want you to be able to log in then they will work with you to make that happen, whether you forgot your password, lost your passkey, or your carrier pidgeon died. Passkeys are not special in this regard at all. What does make them special is that nobody can use a phishing attack to steal your passkey and log in to your account. Nobody can guess your passkey and log into your account. Nobody can intercept your passkey in flight and log in as you. That's the important distinction.