My MIL setup a passkey accidentally on her Google account and now has no idea where it is. Removing it now requires her password which she’s also forgotten. But now for some reason on Google I can’t initiate any type of forgot your password flow because of how Google sets up things and I have zero clue where she stored the passkey.
Ran into the same issue with my dad the other day. Has a passkey set up on his Google account. Bear in mind that he doesn’t know what a passkey is, so Google obviously sent him through a pattern at one point to get him to create one.
He didn’t have access to it the other day and we needed access to his account. He didn’t remember his password, and we were unable to reset it because you need the passkey! No other options to authenticate for a reset were available.
Add in the fact that I was trying to help him with this by long distance call and you can imagine the frustration.
As someone with elderly parents, the Googles and the Microsofts of the world really don't seem to give a shit about the elderly anymore, if they ever did. Random UI updates and workflow changes with no announcements, thinking they're "intuitive."
One of these days the product managers who push these things thinking "oh, it's easy, you just . . ." are either going to be explaining it to confused Mom or Dad, or they're going to be elderly and irritated themselves. Until then I hope they stub their toe or step on random Legos regularly.
I'm not even elderly but I would really like an e-mail client with a stable UI. I used to like Apple Mail but it's been a buggy mess since Catalina. It doesn't even sort or search mail reliably any more. It's basically a trope at this point but a robot-rewrite-in-Rust seems inevitable at this point.
A while ago I helped an elderly relative migrate off off a copy of Eudora that they'd been using for many years. (To Thunderbird.)
Originally it was about difficulty migrating to a new laptop with a different version of Windows, but I was quite firm about it because when I realized it wasn't able to do secure connections for some reason, so the instant they took their laptop to public Wi-Fi...
P.S.: Migrating decades of local messages was a huge problem. It's been so long that many import/export tools are defunct. I was even loading up extremely old versions of Thunderbird to see if I could import to that and then upgrade.
However the GitHub edition (not Sourceforge) of Eudora2Unix [0] saved me and deserves a shout-out here.
It took some tweaks and a harness to repeatedly try the conversion, since I wanted something I could literally drop into the Thunderbird profile folder. The final result wasn't perfect, (some file attachment issues linger) but it's way better than having it all at risk of Eudora.exe just refusing to launch one day.
[0] https://github.com/jonabbey/eudora2unix
>He didn’t remember his password, and we were unable to reset it because you need the passkey! No other options to authenticate for a reset were available.
Google treats both a password and a passkey as a primary factor, and if you forget either of them you have to go through their account recovery flow: https://support.google.com/accounts/answer/7682439?hl=en
AFAIK there's nothing different about the recovery scenario for a Google account in that state regardless of whether it has a password in use as its primary cred, a passkey in use as primary credential, or both.
Thanks. Upon further investigation we could have hit “Try another way” on the account recovery process UI a few times to get to a workable account recovery method.
Would be nice if Google would lay your recovery options out for you (which I am used to it doing in regard to 2FA if you are doing a regular log in) instead of having to hammer the “Try another way” link repeatedly as it cycles through options.
WDYM -- I thought "try another way" is supposed to list all possible options instead of cycling through them!
It does when I log in. You click "Try another way" and then it brings up a menu of options you have for 2FA. For some reason they have designed the account recovery flow to be different.
So, if you are used to the "Try another way" flow on login, it can be confusing to see an entirely different "Try another way" flow on account recovery.
I set my father (late 70s) up with a physical passkey (yubikey), and a backup key. He uses it for the important accounts (google, apple, bank, etc).
It’s been fine.
Yubikeys generally have much worse recovery scenarios than passkeys do, for consumers. In enterprise if you lose your yubikey, an IT admin can help you get back into your account. If you lose a security key as a consumer, you're generally in a much tougher account recovery situation.
You need extra backup keys in a safe place. They don’t explain that well.
Not all services let you enroll multiple keys. Amazon, with all the money in the world, was guilty of this for a long time.
Practically, it is a huge challenge. I would want my day to day fob, an onsite backup, and an offsite backup. That’s a lot of hassle and potential for mistakes. To even register the offsite backup means I need access to it. Remotely copying a password database is so much reliable
If you use a security key only for the most important accounts like Apple or Google, keys are set up once and then unchanged for years.
This is why I've always been a fan of these. They are easy for laypeople to understand.
Yep, I've never had Google, PayPal, or Amazon ask me about a passkey with a yubikey.
The current ones are passkeys
Doesn't the passkey have to be on her phone or computer?
It should be but haven’t checked her apple vault. I checked Google password manager and her windows password manager and there nothing in either. She might have used her phone and it’s in her iOS vault which I’ll check next. But this is what makes this entire passkey thing a mess. She’s 75, she didn’t do this on purpose and the ecosystem is just a mess
Everything about it is.
Also in the process of helping my dad with his phone, 76 and my grandmother 99. Maybe this works better with Apple, but the biggest problem on Android is, that it feels like every update shuffles everything around. Allmost no point in explaining, that they can solve some things on their own.
And all the time new things on the screen, new features they don't understand, need nor asked for.
Im young and I dont even bother learning how to use my Android phone's new features since it feels like everything moves or changes all the time. there's no point trying to get familiar with most of the features.
That's because most people at Google use iPhones as their primary phones, they hardly know or care about the UX
if any android pms or execs read this comment, it should be like a slap in the face. a scathing indictment of the state of their product.
just hang their heads in shame and walk into the sea
We're at a point where the biggest possible contribution to humanity of many PMs in big corps would be to just... drop dead. Feature-freeze rather than furthering the enshittification, as that seems all they're capable of.
I'd wish the world would just become boring again.
They’d just hire more to replace them and keep chaos machine running
Apple does seem to have one of the best and most secure passkey implementations.
A little snarky, but...
It _is_ true that it's more secure when even the people that the passkey was created for can't use it.
They seem unnecessarily opaque about it all.
I just made one for PayPal using my MacBook which seems to have ended up in Bitwarden rather than the mac thing. But there's nothing in Bitwarden to say list all passkeys. Not sure how I check elsewhere. Maybe they should email you "you have created a paypal passkey in Tim's Bitwarden" or something. Then at least you could search the email for "passkey"?
I wonder if I can use Bitwarden on another device with that? I honestly don't know.
You can't search for passkeys, but you can search for logins by URL and check the much shorter list for passkeys. The good news is that having the passkey in Bitwarden means you can use it on another device.
Even the concept of "where on the PC" has been totally annihilated by OS vendors and app developers. Is it on the filesystem? Is it on The Cloud? Is it vaguely "In An App"? Is it in some "Secure Enclave"? Who the fuck knows anymore? And the apps are no help--they insist on blurring the lines between local and cloud, hiding full paths, and generally just saying "Don't worry about where your data actually is. We pinky swear to be able to find it for you!"
Windows prompting her about Bluetooth for the pass key threw me too. I thought for sure she had clicked the wrong thing before I realized that somehow her widows pass key requires communicating to some device? Maybe her phone? No idea
I know on my Windows if I sign into icloud.com I have the option of using a passkey which I do by scanning a picture with my iPhone and it also using Bluetooth, presumably to prove physical presence of it.
No, it doesn't have to be associated with the phone, and IMO you are better off not letting the big tech companies own your identity, which is effectively getting Apple or Google to store it in your phone for you ends up being. There are physical passkeys that feel like a door key in everyday use. You can attach them to your house key ring, and like house keys are near indestructible. Lookup the Yubikey 5 NFC.
The only downside is unlike a house key, you can't get a backup "cut". Copying a physical passkey currently isn't possible. If you lose it, you've lost access to all your logins. As the article says, their recommended workaround is to keep backup physical passkeys, and log all your passkeys (including the backups) into every site. Which is insane - very few people have the patience to do that.
The article is really a long rant about that one issue - there is currently no way to securely backup a physical passkey. Solve that, and all the other issues melt away.
Who the fuck knows?
I for sure don't. Websites only know there is a passkey associated with my account, and the OS only knows there might be one on the device, or maybe on another device, and offers me options to check here or do a Bluetooth/QR Code dance, and when all of them fail, I'm no closer to knowing where the damn passkey is.