Google is making their weak, flawed passkey system the default login method
lauren.vortex.com
lauren.vortex.com
It's even fundamentally misguided - passkeys behave the same as random passwords stored in a password managers (they're... pretty much the same without the copy/pasting). What's the flaw here?
"completely on device authentication security which for many users is extremely weak"
... but you need physical access to the device too. Plus, for most modern devices with TPM-like ICs, it's probably more secure than a PC with a password manager?
Last time I checked it wasn't possible, but that's 5 months ago.
And don't forget passwords are protected by the fifth Amendment, biometrics aren't.
shrugs
I understand that this lapses certain security boundaries, but if you get my phone unlocked then it's game-over anyways. Hell, same for pretty much everything I own, regardless of the software on it. If the device is unlocked, you have guaranteed access to pretty much everything that matters. For all I know, you could have copied down my notes app with my WiFi password in it and exfiltrated my entire camera roll. You have access to Google Authenticator, my email, my phone and pretty much 90% of the data I would have otherwise wanted to hide.
It's once again this XKCD converging on every modern security model imaginable: https://xkcd.com/1200/
Security will never be automated to be fool proof; there is a modicum of thought the user needs to put into their security profile.
How would passkeys stop them if they are are in physical possession of the device and can unlock it? It doesn't seem passkeys protect you more here.
Some applications support requiring a login with either a dedicated PIN, password or biometrics upon each activity launch (e.g. Telegram, Signal). The only way for an attacker to breach that is to either scrape the phone for credential stuffing or to force me to unlock the app.
Unfortunately, at least for Telegram and Signal neither support a "duress PIN", and iPhones and Android don't as well. Basically, a PIN code that when supplied to any app leads the device to lock itself down completely - force-close all applications immediately, wipe all encryption keys from RAM to prohibit a "freeze" attack, and shut down the device. Ideally it would also distribute a trigger to all other devices and services one owns that these lock themselves down as well, and only let themselves unlock after being supplied with a dedicated password.
And this is how applications storing passkeys behave (e.g. 1Password). Where's the security issue here?
Most apps don't, an attacker can do a lot of damage as long as they manage to keep the phone from activating screen lock.
> Important: When you create a passkey, you opt in to a passkey-first, password-less sign-in experience. Create passkeys only on personal devices that you control. Even if you sign out of your Google Account, once you create a passkey on a device, anyone who can unlock the device can sign back into your Google Account with the passkey.
[1] https://support.google.com/accounts/answer/13548313?hl=en
it would be great if backup codes were NOT usable except under <conditions> and/or use of a backup code permitted access only after <N day delay>.
I hate all the resistance to even small improvements over passwords (like passkeys). The only question we should be asking is, "does this improve on passwords?" In this case, yes it does. With passkeys, it's only the person who powns your phone that gets to log into all your accounts. With passwords, it's the person that powns your phone, or gets your password through phishing, or hacks one the the many websites that also has a copy of your password. This is an improvement! Let's do it!
Surely that's the standard for security for "people who know what they're doing"?!
Maybe because you had an iPhone and your new Phone is an Android, or you don't like the prices of 1password etc.
At the moment you are stuck.
In general "game over devices" tend to be a bad idea. I’ve seen people type in their passcodes. People may have seen me type in mine when FaceID gives me trouble on my iPad. I’m not at all comfortable with the idea that someone jacking my iPad will have root access to my life.
I don’t think we should stick with them, but there’s a difference between sticking with something and forcing everyone to use something else. Is it true that you won’t be able to use passwords at all in the new scheme? If so, this seems… risky.
Question. Suppose I have a passkey on my device. Obviously it gets synced to some sort of cloud, so that if I lose my device, I don’t lose my account. But does everyone who has access to any device get all my passkeys?
I hope not, but part of the blog post was to raise awareness. This is a nice reminder it’s time to look into passkeys deeply.
> "game over devices" tend to be a bad idea
If you have something worth stealing, don't put it on your phone.
If you have $1000 in Robinhood or Coinbase along with passwords for TikTok and Instagram in your password manager, sure, put it all on your phone for convenience. It wouldn't be a catastrophe if they were stolen.
But if you have anything that's worth protecting, trade convenience for security. Keep banking, brokerage and crypto apps off the phone. Don't use your phone for password managers and 2FA.
Use a Chromebook with no extensions for sensitive stuff. It's less convenient, but there's no chance of life-changing theft if someone takes your phone at the club.
FYI you can set a PIN on Google Authenticator so it can’t be opened without your PIN. This should be different than your Lock Screen PIN.
Sensitive information (WI-FI password etc) should be stored in a password app such as 1Password etc.
Even if my phone is unlocked I need to auth via FaceId to be able to open the Google Authenticator app for example.
Wondering if I should into whether more apps have this functionality...
Even if the device is unlocked.
That’s why we’re moving to a passwordless world.