Lose your (google) passkeys account for whatever reason (ai says no, wrongthink, itar ban), and you risk losing your digital life.
Edit: If you need MFA please do check out solokey, an open source Fido project.
Lose your (google) passkeys account for whatever reason (ai says no, wrongthink, itar ban), and you risk losing your digital life.
Edit: If you need MFA please do check out solokey, an open source Fido project.
“We have concluded the review of the information you’ve submitted. To prevent possible fraud and abuse, your Google products and services will remain suspended. It is our policy to not discuss the specific reasons for these suspensions.
Note that in the Google <PRODUCT> Terms of Service, we reserve the right to change, suspend, or discontinue any aspect of our services at any time, including availability of a service or any feature, without notice and without liability. We also reserve the right to impose limits on certain Service features or restrict access to some or all of the Services without notice and without liability.”
It can wreck your life. Getting a suspension lifted can take a truly stupid amount of effort depending on the reason (if you even know it). For me it involved basically stalking employees until I was able to find someone who could actually review my account. Literally looking up employees by department and name on LinkedIn and Twitter, then trying to find their phone number and texting them. I must have sounded crazy. But I was able to find someone to help. Then it took like 5 minutes to fix. It was clear it was just a mistake on their end—an, “overzealous anti-fraud algorithm.” I probably spent around 60 hours in totally trying to get my account restored.
After getting access back I stopped using that account and made sure to distribute access to different accounts and emails. Using a single Google account is just way too risky. The more services you use the more likely you are to encounter an account suspending issue. I’ve heard of many cases where people get hacked and Google’s response is to ban the victim permanently. Facebook has similarly atrocious policies.
The thing is, for every Google service you really should have a separate account. One for dev, one for YouTube, one for Gmail, one for Wallet. Maybe one for Chrome if you use it as a password manager. One for AdWords. One for payments if you use any merchant services.
Every service you add to an account increases your odds of suspension. Oddly, I’ve also heard that one of the reasons guy can get banned is for having multiple accounts. So I’m not sure if my new policy is any better than my old one.
- They do not let you use any other client -- that's a bummer but let's say I can live with that
- But the real bugger is - while they allow catch-all, they (actually their clients because you can't use something like Apple Mail, or Thunderbird) do not allow sending email from "any" email address even on your own domain, which is the mandatory compliment to catch-all, and without it catch-all is half useless.
Note: Though I have never quite understood their reasoning for not allowing you to use other clients -- the mails to other domains/providers anyway go unencrypted and just like any other email in the world. This is a weird kind of walled garden.
The point was one might not want to go to Tutanota in the first place and rather go to another provider instead of going to another provider after a switch.
One practical way is to buy your own domain and set up a Google Business account for it. It includes email. So if anything happens, you will still be able to at least transfer the email to another provider.
That’s why the risk of storing passkeys with Google is so great. Your account gets hacked, someone removes all your devices and then the account gets banned. You stand to lose access to hundreds of linked services.
However gsuite does not protect you from bans , google will just as likely ban the entire tenant for infractions by a single user
I'm sure it does, but "if anything happens, you will still be able to at least transfer the email to another provider" doesn't apply since you can't "transfer {YouTube,money in Wallet,password from sync,etc} to another provider" in the same way as email. These things are more than just an address you can point to something else.
Google does allow your data to be exported[1] including YT videos and most of other things in your account in a non-proprietary[2] format, in addition the APIs from Google are fairly deep to extract a ton of information from your account
It is not their problem that other services do not always support imports from Google even when such peers exist.
Google is no means a saint, or supporter of open formats or of easy export formats, but for a company they do a reasonable job for a feature designed for people leaving their ecosystem
[1] https://support.google.com/accounts/answer/3024190?hl=en
[2] Non-proprietary to them, even if not fully open i.e. MP4 or DOCX instead of only supporting WEBM or ODT
[3] Used by regular users, not sysadmins i.e. DNS / Certificates by CAs et al. do not count
It is bonkers we treat SaaS as always available and that data will never be lost forever[1]
Big Co may not loose data in the abstract sense, but it can be still lost to us, not just of suspended accounts, it could be access is now restricted by new pricing tiers, or because Big Co have decided you are no longer active and deleted your data or myriad other reasons.
Always take backups .
[1] it shouldn't matter if it is paid or free service either. There is always things in the ToS that allows Big Co to do what they want without notice.
That said, I think the big issue here is not so much about data and exports, but rather that Google occupies a fairly central space in the internet. If you want to make money developing mobile applications then Android – and thus a Google account – is kind of required; there's been plenty of "I have a business selling Android apps and it was taken away from one day to the next with no explanation". The same applies to YouTube: you can make money posting videos on the internet with out it, but it's a lot harder.
One practical way is to, you know, not rely on any Google account at all.
The only Google app/service I have not been able to find an alternative for is Google Maps so I use that without logging in (no, in my geographic location there is no option - Apple Maps is worse than pathetic here and OSM apps are fancy things to install and uninstall once in a while).
For me personally, the small loss is acceptable. I know that it's going to take me maybe a day to set up everything on another provider.
Google had a recent blog post about it, but the push started with Apple at WWDC22 (and one session at WWDC21), to the point some assumed it was an Apple-only feature. An effort like this requires coordination from major players to take off with the impact they want (replacing passwords).
https://www.theverge.com/2022/8/5/23293643/apple-passkeys-fi...
1Password has been tracking services which support passkeys, and so far adoption seems slow. I’ve been checking their website on and off for months and it has hovered at about the same number of websites, occasionally going down.
I'm not defending passkeys but you people need to pick a side to shill for.
The flip side here is that Apple gives a user near zero power in their walled garden, and is hostile towards anyone outside of it. So Apple passkeys can't take away user control because they never had any.
And I have no doubt that he believes it and intends to implement it. But that's not a guarantee that the corporation around him won't decide tomorrow that they don't want to implement it.
It’s a statement from the Engineering Manager of the “Authentication Experience” team. Ricky’s not a random unknown Apple developer, they’re someone with knowledge and authority on these matters. And as far as I know they’ve been reliable regarding what they share publicly.
> you people need to pick a side to shill for.
This type of rhetoric is unnecessarily divisive, though. Attacking people isn’t an effective way of changing their mind or making them reconsider their point. Quite the contrary, it only makes them clam up.
I do disagree ignoring them is the best. This gives them an echo chamber here and can others can get the impression they are always right. The attack was not helpful as you said. I'll try to do better in the future.
From my experience and observation, the people who hate on specific groups are more set in their ways than the people hated on.
The preconception that someone is a shill and won’t change their mind does more harm to the conversation than what the other person believes. It is impossible to change someone’s mind if you start from the assumption that it won’t happen.
Case in point: this very thread. It seemed like the person I replied to was angry and set in their ways, but they took stock of what was said, apologised, and vowed to do better. That is a positive outcome for everyone and all it took was to not lash out in return and a belief that everyone can have a bad day.
Now I carefully ensure that I am not depending on Apple/iCloud for anything either, because honestly that is just like Google and even though you can reach a human being at Apple, their support (at least in India) seems to be trained to perfection in stone-walling you and denying you even an escalation.
So no, I hope this passkey thing is optional or there are third party players (Mozilla?, BitWarden? etc) in this play. And I hope there will always be a recovery option that will be just user's and not with with the passkey provider "by design".
But knowing Apple and Google I think they will make it infinitely harder for any third party to become an option on their devices or platform that there won't really be a competition. It would be worse than the case where "iOS has alternative browsers, but not really". I somehow have a bad feeling about this passkey thing unless third party providers get to become, by explicit user permission and setup, A first class citizen of passkey on. a device.
I'm not keen on handing my identity over to a third-party to manage. And I share the concerns of the commenter up-thread that TLA agencies have fingers in this pie; if they don't, then they're not doing their jobs.
I had a go at implementing oAuth and self-hosting it; but part of the problem with (some of) these open protocols is that people with much more time on their hands than you, and with membership on the specification committees, start messing with the protocols and making them much more complicated. That happened to CalDAV - I wrote a CalDAV server, but it was obsolete as soon as it was finished, because the specs had already moved on.
If only this passkey thing was a Fido standard that could be used with the product you linked us!
I did, but are they vaporware? Website has not been updated with Solo 2 information, but there's a Kickstarter that claims I can still buy early bird keys that will ship almost 2 years ago? Their github repos haven't had meaningful activity in well over a year: https://github.com/solokeys/
I own several myself.
There are other options out there.
If Google closed operations tomorrow, it wouldn’t affect anyone using a passkey to login to any service other than Google’s own.
They need to prove that this isn't going to be a bait and switch. Give users 100% control over their pass keys NOW before we consider using the service.
Otherwise, they're gonna play the "Oh, but most non-tech users will benifit from this" and then we get critical mass becuse a majority of users are non-tech users, and then the import/export function ends up being like the Official Linux Google Drive Client.
No. You’d be screwed when all of your devices stopped working before you enrolled another passkey with the services you use, or setting up a password login if you’d never done that before. That wouldn’t be great but you’d be far more exposed earlier to the fact that you were using devices which no longer receive updates.
The important thing to keep in mind here is context: people are getting compromised daily due to password weaknesses. People are going through account recovery processes for similar reasons, too, so a key question isn’t whether there’s a perfect option but rather how it’ll change those numbers.
That's the point: Google wants to collect your digital life and control it. But they also don't want to deal with any requirements to ensure you can actually use or recover it expediently.
So it's not "if Google close up shop" it's "due to reasons we've (our AI decided too) ban your account. Don't bother contacting us, as there is no customer service".
No. Other people have posted incorrect claims but repetition doesn’t make them less wrong. If Google locks your account, you lose the ability to add new devices to that account but all of your current devices will still have their synced keys stored on their devices as well as the ability to use other passkeys, recovery codes, etc. If Google locks your account, this is nowhere near the biggest problem you’ll have.
Isn't this entirely orthogonal to the usage of passkeys? You could "lose your digital life" if you forgot your password, or remembered your password but tripped their risk scoring system (eg. fresh login from an unusual location).
In terms of key, it's either stored at the OS/browser level (Windows Hello), or at the hardware level (Yubikey). Imagine them as if there were SSH key files; You hold the private key(s), protected by a PIN/password and Google simply has the public key(s) to authenticate you.
Even if Google disabled the account, it still doesn't block you from using other stored Passkeys that are tied to other providers. The only place where you'd get in trouble is if these third-parties like the DMV used Google as their SSO.
"Orthogonal" - the better word for most circumstances unrelated to math is "unrelated". Depending on the situation, "has nothing to do with" works pretty well too.
And to the GP: Since passkeys (and passwords, and etcetera) are related to some extent to one's "digital life", then they cannot be "entirely orthogonal".
To really, really nitpick, even in math, orthogonality does not imply unrelatedness. Two objects being orthogonal to each other means that they both are related to the extent they belong to the same coordinate system.
I guess, by my standards then, using the phrasing "entirely orthogonal" indicates that you believe that the two things are related to the extent they belong to the same coordinate system, but never meet.
I don't like this usage because it seems that "digital life" embodies the entire coordinate system in which "passkeys" exist. Nothing is "orthogonal" to its coordinate system, at most it's orthogonal to an axis in that coordinate system.
I'm kind of tired of this nitpicking myself, though. Please don't borrow nomenclature from other fields when already existing nomenclature (or better yet, colloquial terms) work just fine. Thanks.
> >Lose your (google) passkeys account for whatever reason (ai says no, wrongthink, itar ban), and you risk losing your digital life.
> Isn't this entirely orthogonal to the usage of passkeys? You could "lose your digital life" if you forgot your password, or remembered your password but tripped their risk scoring system (eg. fresh login from an unusual location).
So the person they responded to was saying that loss of (centrally coordinated) passkeys means potential loss of all digital life.
They are responding that a loss of (centrally coordinated) digital life can happen for a variety of other reasons unrelated to passkeys.
The first person is narrowly concerned with central coordination of a particular passkey system, and the second person is saying that if "loss of one's digital life" is the primary concern, then they should instead be concerned with broader central coordination and verification. In essence, their criticism is that cause and effect are being reversed, or at least mistaken.
I dropped out of school in the middle of taking linear algebra, so you know more about math than I do. Maybe orthogonal was appropriate here, but I'm still going to push back against its colloquial use in most situations.
A better way to put the concern is the use of a passkey and access to digital life accounts should be independent, but the concern is in practice they could become entangled.
If you lose your driving license, but still have your passport things are easy.
What if you lose your passport, driving license, birth certificate and all other forms of ID? It's like that bad.