Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

No web service is like that. They all offer recovery options. We aren't talking about Bitcoin here.
 help



The trend of companies becoming easier to contact and customer service becoming better is well-documented.

Tell that to the people who have lost access to their Google account.

Now we aren't talking about a security problem, we're talking about who really owns what. Google can lock you out of your account no matter what kind of authentication they use for that account

It's a lot easier to be locked out with a passkey than without one.

No it's not. Google flips a bit in their database and no matter what kind of authentication you set up with them, you get denied

This does not reflect my own lived experience.

But if true, that means that Google can choose to not provide you a recovery service, which is functionally the same as them not having it.


I'm not even sure what your point is anymore. If Google decides they don't want you to log in anymore, you can't log in anymore. It doesn't matter if you try to log in with a passkey, a password, your fingerprint, or sending a secret code in with carrier pidgeon. This has nothing to do with passkeys vs passwords vs anything else.

If Google does want you to be able to log in then they will work with you to make that happen, whether you forgot your password, lost your passkey, or your carrier pidgeon died.

Passkeys are not special in this regard at all. What does make them special is that nobody can use a phishing attack to steal your passkey and log in to your account. Nobody can guess your passkey and log into your account. Nobody can intercept your passkey in flight and log in as you. That's the important distinction.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: