Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
[dupe] One step closer to a passwordless future (blog.google)
20 points by HieronymusBosch on May 5, 2022 | hide | past | favorite | 16 comments


So their vision of the future is that to do anything online, one MUST have a phone (ahem, portable wiretap)? And Google is going to be keeping my secrets for me, for my own good?

I'm not sure I'm down with any of that.


You can put FIDO creds on a 20 dollar hardware token. It's just that not everyone has that, so you can use your phone too if you want.


... especially since I choose to no longer have a phone/tracking device.


Not just a phone, an Android Phone! The login popup thingy (Google Prompts) is not available for any other mobile OS but for Android :(


I use iOS devices and I get a login prompt using the YouTube for iOS app.


Here's the joined announcement by Google, Apple and Microsoft under the FIDO alliance umbrella:

https://fidoalliance.org/apple-google-and-microsoft-commit-t...


That’s a whole lot of text saying “things will be simpler” on repeat, without specifying how things are going to be and why that is simpler.

Anyone got a link to something less hand-wavey and more concrete?


Can someone explains to me what happens if you lose your phone, or if you temporarily lose access to it (e.g. leave it at home)?


You have a backup $30 hardware key on your keychain, or you don't log in - same way you can't log in if you don't have your 2fa device nowadays.


That's exactly why I don't use 2FA.


This is not the future I want to live in. For all the talk about web3 and decentralization, this is the one thing I truly wish existed as a fully decentralized service. I would gladly pay.


"To sign into a website on your computer, you’ll just need your phone nearby and you’ll simply be prompted to unlock it for access."

Wait, why do you need a phone to sign in to a computer if it's just cryptographic signatures? Surely they don't want to abolish online anonymity?


They'll have to pry my password and 2FA device from my cold dead hands.


What could possibly go wrong?


Just put the chip in my heart already, I don’t give a shit anymore.


Google so far been trying to do this for 6-7 years since they attempted to force push FIDO through Android.

W3C adoption stalled, and they shot them in the foot with de-facto 3 incompatible standards rolled out under the same name.

Smartcards are an alternative solution, been working for 20+ years, and they keep being sabotaged to make way for FIDO (signing/encryption/enrolment APIs being axed from browsers.)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: