9 ms·
Then what's the point of it all if a hacker can still get into my account using the traditional methods? This seems to be just opening up another avenue of atta
by chupaolo 3y ago
Then what's the point of it all if a hacker can still get into my account using the traditional methods? This seems to be just opening up another avenue of attack.
- px43 3y agoMy Google account is set up such that account recovery requires me to actually travel to Mountain View and present several forms of ID, and that's just how I want it to be.
- lxgr 3y agoAre you joking or does Google really do in-person verification for high-value accounts (e.g. GCP or Play Store developer accounts)?
- grotorea 3y agoIf I understand it correctly it will avoid phishing, assuming people notice there's something up when they see a page asking for a traditional login for no good reason when they have passkeys. And it may be a transitionary step towards no passwords or something.
- skarra 3y agoYou can read more about the security properties of passkeys on your Google account on this post from earlier this year when support was originally announced: https://security.googleblog.com/2023/05/so-long-passwords-thanks-for-all-phish.html https://security.googleblog.com/2023/05/so-long-passwords-th...