Hacker Newsnew | past | comments | ask | show | jobs | submit | ilchalpenl's commentslogin

> Let's assume that they were all Passkeys.

Lets assume I put all the effort to explain.

I will give you a better example.

- Lets say you have a google account with pixel phone

- You are using it and added 1000 passkeys

- All are synced to your Google account

- Destroy and Get a new phone. Login to your google account with recovery code.

- All your passkeys are in your phone again.

There are plans in fidoalliance.org to make it portable. Pretty sure you are still not going to move to it.


It works fine until Google suddenly decides that your new device is not you and asks you to confirm login from previous device...


Or until Google decides that you did a wrongthink and bans your account, including locking you out of your old phone.


See.. the sad thing for doomsayers like you is that if even 1% of users were affected then there would be mass exodus from Gmail. It does not.

Yes, you don't use Gmail so it does not matter. You may be don't know. And often even average Joe some how has a oldphone or iPad that has oldgmail account there or logged into wife's phone or phone based SMS whatever.

it is ok to hate passkeys or google or love only self-hosted but let others do what they want.

I have been user of solokeys (since the first one) - only opensource hardware keys. works for me...

But if you go to the local highstreet then there are tons of people doing this screenrepair etc just to recover the account. Average Joe doesnot mind paying for that. Even will give the repair guy full password to transfer all data from old to new phone.


Apple's keychain or google password manager - can hold 2000 passkeys easily.


Nothing in the post you're replying to is about "is 2000 passkeys storable", it's about "if I have 2000 passkeys and I need to move between an Apple device and an Android device, do I need to establish a second set of 2000 passkeys"?


Not at the moment. But if you sign into google account in iPhone then you can use Google's passkeys in iPhone.

At the end, passkeys are built not for the tin-foil, (I hate Google Apple fellows), I want to keep every single locally, RMS fans. No.

A majority will benefit. End of matter.

A majority don't change platforms (I have not seen them do it).

And lets be honest - even if they were portable are you privacy person that is going to do it? No.


No, the majority will not. If through some miracles, passkeys gain sudden and wide adoption, there will be a day of reckoning come around the next mobile refreshment cycle, maybe earlier.

People break their phones. That is normal experience. Entirely unsupported by passkeys as they are today.

I'm actually surprised we didn't have more pushback for ubiquitous 2FA, as they have similar threat profile - i.e. addressing the tin-foil threats of cybersecurity aficionados, while entirely ignoring the common threats to real people, in particular the one of broken or lost mobile device.


Incorrect. They break but they fix it.

People break their phones less often compared to telling them keep their keepassdatabase in sync across devices.

Even recently my friend fixed his iPhone XR (10 year old) 3rd party. Everything including passkeys work fine.


No you don't. I use the same passkeys for all my devices sync'd with bitwarden.


Exactly. Bitwarden, not the Apple/Google/Microsoft keychain. That's the problem.


Dunno why the downvotes, if you're willing to trust Apple or Google this is a good method for passkey usage. because your touchID/faceid/opticalid auth gate the keyring's on either of these vendors your passkey works without having to migrate them. EDIT: Also ANY device that you add to your iCloud has access to the passkeys you've made... it's a dream for secure access.


What happens when the user decides to move to an Android device, or even is suspended from Apple for a suspected breach of the terms of service, or Apple decides to not support their country anymore? There are countless reasons to prefer to manage one's own access.


True... Theoretically correct but in practical sense?

All these doom mongering of suspension happens so rarely that majority don't care.

There are countless reason to DIY. Agree. But passkeys will help the majority.

Also note that the kind of people - like journalists etc - that need to use DIY/local are the ones that are likely to use passkey. Reality.


Downvotes does not matter. People here that are privacy inclined always find ways to argue about Google or Apple (any major companies). But if you look at their private lives - they adopt tech ASAP. A majority have Apple Pay or Google Pay. Paypal. At the same time use bitwarden also. (And that is fine)

These privacy zealots fail to realise that majority of population does not have time to setup bitwarden server or lineageos or zfs storage etc.


The downvotes are because the commenter did not read or at least did not fully comprehend the meaning of the post they were responding to.


Did you not read the comment thread you're responding to?


> Edit: One final consideration, my spouse and I share user/name passwords for some things (notably Pandora and our Amazon Prime account) since they don’t handle things like family logins well; how do both my wife and I use amazon or Pandora with passkeys? Do we each set up passkeys? How do I get her Pass if that’s not an option?

Lets say it is a android phone. Open amazon app. login in the usual user/password + 2FA (like with QRcode or phone). create passkey. done. This passkey would have been now synced to your google account.

Take next spouse phone. Open amazon website or app. try login it will try for passkey but cannot find it. so

- login in the usual user/password + 2FA (like with QRcode or phone). create passkey. done - Now this passkey would have synced to spouse google account.

In future, assuming you have apple or windows laptop. assume you have signed into Google (chrome). Now go to amazon. It will ask - shall I sign in with passkey. Yes, give your macos fingerprint or windows hello or password of that laptop. login Done magically. You dont even need to remember username or password.

Assuming you both have iPhones. You can sync the passkey to icloud account. And for every new iDevice it will be available.

The main bottleneck of passkey would be that all 3rd party sites will have another non-passkey way as backup to login. I have never seen a website that would say - remove all other methods and keep only passkey.

In a way passkey is 99% convenience. If a hacker would some how get your sms and password they can by-pass.


Thanks. One glaring issue I see is that right now police can’t ask you for your password in the USA (a violation of the right against self-incrimination). They can however get a search warrant for your device and your biometrics, and wouldn’t need your password if they can gain access through your pass key.


If you have it enabled, and you're in custody or at a border or similar, and have biometric auth enabled on your phone/computer, they can hold it up to your face or force you to put your finger on it to unlock it. Search warrant be damned.


According to Google,

> Approximately 90% people never go out of their country...

I am sure > 90% will happily love to have the convenience.

Yes, people like you can setup bitwarden etc. Nothing wrong. Passkey works for majority of people.

BTW, passkey can also be used without biometrics. It needs only the authentication of the device.


> wouldn’t need your password if t

Once you talk about privacy/security then - I am not even sure you should do it here in HN - a bastion for encouraging Silicon valley practices.

In principle, you can remove biometrics and still use passkey (by using phone password only).

If you see my text, I wrote clearly - passkeys are great convenience + security - For the majority. People don't need to waste time in searching login names.

TBH, I was in a few Free Software Foundation Europe and linux conferences in the last year - in my view - at least half of them were using - passkey with iPhone or Android (including Playservices). So people have accepted the reality.


> I see is that right now police can’t ask you for your password in the USA (a violation of the right against self-incrimination).

Hope they don't see your HN post. It is visible even without login.


The title is correct. But any of you changes or lessons are perfectly fine. (Sure, a bit awkward to do ssh from cafes). May be reading the Google SRE PDF (or equivalent) would have been a bit more useful. At my wife's business one of the team member shall LOGIN to DO/AWS every month send a screenshot that account/CC is in good standing.


Is the buyer at fault or the seller?


> Is the buyer at fault or the seller?

It’s Putin’s, and a small group around him.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: