Ran into the same issue with my dad the other day. Has a passkey set up on his Google account. Bear in mind that he doesn’t know what a passkey is, so Google obviously sent him through a pattern at one point to get him to create one.

He didn’t have access to it the other day and we needed access to his account. He didn’t remember his password, and we were unable to reset it because you need the passkey! No other options to authenticate for a reset were available.

Add in the fact that I was trying to help him with this by long distance call and you can imagine the frustration.

As someone with elderly parents, the Googles and the Microsofts of the world really don't seem to give a shit about the elderly anymore, if they ever did. Random UI updates and workflow changes with no announcements, thinking they're "intuitive."

One of these days the product managers who push these things thinking "oh, it's easy, you just . . ." are either going to be explaining it to confused Mom or Dad, or they're going to be elderly and irritated themselves. Until then I hope they stub their toe or step on random Legos regularly.

I'm not even elderly but I would really like an e-mail client with a stable UI. I used to like Apple Mail but it's been a buggy mess since Catalina. It doesn't even sort or search mail reliably any more. It's basically a trope at this point but a robot-rewrite-in-Rust seems inevitable at this point.

A while ago I helped an elderly relative migrate off off a copy of Eudora that they'd been using for many years. (To Thunderbird.)

Originally it was about difficulty migrating to a new laptop with a different version of Windows, but I was quite firm about it because when I realized it wasn't able to do secure connections for some reason, so the instant they took their laptop to public Wi-Fi...

P.S.: Migrating decades of local messages was a huge problem. It's been so long that many import/export tools are defunct. I was even loading up extremely old versions of Thunderbird to see if I could import to that and then upgrade.

However the GitHub edition (not Sourceforge) of Eudora2Unix [0] saved me and deserves a shout-out here.

It took some tweaks and a harness to repeatedly try the conversion, since I wanted something I could literally drop into the Thunderbird profile folder. The final result wasn't perfect, (some file attachment issues linger) but it's way better than having it all at risk of Eudora.exe just refusing to launch one day.

[0] https://github.com/jonabbey/eudora2unix

>He didn’t remember his password, and we were unable to reset it because you need the passkey! No other options to authenticate for a reset were available.

Google treats both a password and a passkey as a primary factor, and if you forget either of them you have to go through their account recovery flow: https://support.google.com/accounts/answer/7682439?hl=en

AFAIK there's nothing different about the recovery scenario for a Google account in that state regardless of whether it has a password in use as its primary cred, a passkey in use as primary credential, or both.

Thanks. Upon further investigation we could have hit “Try another way” on the account recovery process UI a few times to get to a workable account recovery method.

Would be nice if Google would lay your recovery options out for you (which I am used to it doing in regard to 2FA if you are doing a regular log in) instead of having to hammer the “Try another way” link repeatedly as it cycles through options.

WDYM -- I thought "try another way" is supposed to list all possible options instead of cycling through them!

It does when I log in. You click "Try another way" and then it brings up a menu of options you have for 2FA. For some reason they have designed the account recovery flow to be different.

So, if you are used to the "Try another way" flow on login, it can be confusing to see an entirely different "Try another way" flow on account recovery.

[deleted]

I set my father (late 70s) up with a physical passkey (yubikey), and a backup key. He uses it for the important accounts (google, apple, bank, etc).

It’s been fine.

Yubikeys generally have much worse recovery scenarios than passkeys do, for consumers. In enterprise if you lose your yubikey, an IT admin can help you get back into your account. If you lose a security key as a consumer, you're generally in a much tougher account recovery situation.

You need extra backup keys in a safe place. They don’t explain that well.

Not all services let you enroll multiple keys. Amazon, with all the money in the world, was guilty of this for a long time.

Practically, it is a huge challenge. I would want my day to day fob, an onsite backup, and an offsite backup. That’s a lot of hassle and potential for mistakes. To even register the offsite backup means I need access to it. Remotely copying a password database is so much reliable

If you use a security key only for the most important accounts like Apple or Google, keys are set up once and then unchanged for years.

This is why I've always been a fan of these. They are easy for laypeople to understand.

Yep, I've never had Google, PayPal, or Amazon ask me about a passkey with a yubikey.

The current ones are passkeys