Or if you drop your phone in a lake you’re out of luck too.
Or if you drop your phone in a lake you’re out of luck too.
You use passkeys as a preferred login method.
If you do not have your passkey, you can tap "Try Another Way" and use your password as usual.
It just becomes much harder to phish out this password.
If you've also lost access to your email, you've got other problems.
Or better still, use a password calculator app such as https://spectre.app/
This kind of approach generates your passwords for different sites based on login information and a single password only you know. No other passwords are stored on any devices or services, not even within the app on the device you are using it on.
Which enables you to have different passwords for each service and solves the problem of "too many passwords to remember" without just having to write them all down in a dozen ways that can also be compromised.
https://www.yubico.com/blog/a-yubico-faq-about-passkeys/ https://nordpass.com/passwordless/ https://www.future.1password.com/passkeys/
The protocol is private key stored on your hardware; public on the service you're authing to. Google doesn't have a way to MITM that, but if you lose the machine storing the private key, best have another way to auth.
(Note: some implementations, including Chrome on Android, do allow sync and sharing of the key, but IIUC even if Google bars you access to your account, the phone will still have the private key and can still do the login).
right, so passwords it is then.
One of the main gripes people have is about whether or not the user actually has access to the key or not.
ie. Can I save my passkey somewhere that I control, can I login on another device, etc. etc. Or do I need google's sync/account to do that for me.
Google controls the software so it can MITM.