Need help?
<- Back

Comments (390)

  • gortok
    I do not know how to use a Passkey in a way that won’t impede how I log in to systems. I’ve been in tech for 26 years, and I understand the Public/private key behind what a Passkey is. Here’s what I don’t understand:I access a website through at least four different devices (my iPad, iPhone, Windows Desktop computer, and MacBook Pro) and three different browsers on each device (Brave, Firefox, Safari) , and I use LastPass. If I accidentally set up a passkey on my phone (let’s say I use Safari one day instead of my go-to, Brave), can I still log in without that passkey on other devices? Is there a way to ensure that passkey can be used on other devices? Can I add another passkey on another device? How many passkeys can I set up for a particular site/app? I have at least 6 different combination of browser/devices in use.I don’t want to use Passkeys because I don’t the answers to those questions, and I don’t know whether each website/app that has set up Passkeys has decided the answers to those questions in the same way as the others. For now, I’m going to stick with LastPass and use Passwords; because no matter whether I lose my device or not or whether I’m on my own devices or not, I can be sure I’ll be able to get into a site/app.Edit: One final consideration, my spouse and I share user/name passwords for some things (notably Pandora and our Amazon Prime account) since they don’t handle things like family logins well; how do both my wife and I use amazon or Pandora with passkeys? Do we each set up passkeys? How do I get her Pass if that’s not an option?
  • tossitawayplz
    The first time I got asked by a site if I wanted to use a passkey I immediately googled what they were and... never really found the answer, not in the 5mins I devoted to being distracting from my task at hand anyway."magic fairy dust to login to apps." is the most accurate description I've seen.Unlike a password or a TOTP token, I know how those work, I know its my responsibility to keep track of them. If my passkey is on my phone what happens if I lose my phone? Do I need a unique passkey per device? How do I rotate them? What if a device gets stolen?I'm so glad I'm not alone in thinking these are so poorly explained.
  • christina97
    It’s quite the opposite. Passkeys are phenomenal for a lot of consumers. Based on this thread, it’s the engineers who understand authentication in the first place and have their own system (eg password manager) that are confused.Consider a user in the Apple ecosystem: you are already conditioned to just do Touch ID or Face ID when asked. I was on Amazon the other day, it prompted randomly for “want to set up a passkey to sign in easier”? I set it up and now I can easily sign in to Amazon on my mac or iphone with zero friction.For the normal consumer this is not a replacement for “dig out my password manager and copy-paste/autofill my password”, it’s a replacement for “oh it’s prompting for my password again” -> proceed to type your shared password for all sites.
  • programmertote
    Like some folks already commented here, even as someone who has been working in tech for 20+ years, I find Passkey confusing. I understand the key aspect in computer science term, but I don't know how to use it across devices. Another big worry is that if I tie that to a physical key, then I might lose it (because it's physical) and never get it back.
  • rsyring
    FWIW: I find passkeys to be a very simple and easy to use concept.Simple: it's like a password that I don't have to type inEasy to use: because I use 1Password and just have it installed on everything. On Android, it can be set as the default passkey provider so, even on mobile, I am using passkeys shared across devices.Is this "less secure" because I'm sharing the keys through 1Password. I suppose, at some level. But before that, I was simply sharing passwords through 1Password in the exact same way. So, I don't think my security posture has changed any.What has changed is the UX and IMO for the better. Now I don't have to generate/fill/copy-paste text strings for user names or passwords. 1Password knows what site I'm on and usually responds automatically when I'm in a passkey context. If I have more than one passkey available, because I have multiple accounts (for something like Google Workspace), it shows me options and I pick the one I want.Honestly, it's mostly a "just works" system and I like it a lot better than passwords.YMMV, of course.
  • c7b
    UX is not the problem with Passkeys. Passkeys were designed to align with the interests of BigTech, who are bent on stopping the abomination that is general computing devices in the hands of consumers and forcing them into their walled gardens. The language that is used for taking away freedoms is the same as always, safety. Where we ended up with Passkeys is an operating model that is suitable for corporate devices, i.e. the user can only do what the owners of the device allow them to. Suboptimal UX is downstream from that problem.
  • exabrial
    With physical U2F key, I could explain to my 78 year-old-parents "this is a physical key needed to access your account. Think of it like the front door key to your house. Don't lose it or lend it to anyone. We should have a couple of backup keys too." And they got completely understood and added it to all of their accounts. This was not hard. People assumed consumers were too stupid to do this without even giving them a chance.
  • f30e3dfed1c9
    My take: (1) I've had passwords handled pretty well for a long time now: same password manager for something like 15 years; (2) companies are pushing pretty hard to get me to use passkeys instead.From (2) I assume that the companies see benefits to themselves. I don't care about benefits to them. I don't see much in the way of benefits to me, so I'm not changing anything if I don't have to.I'll admit to not having looked into passkeys all that much. Someday, I might. But for the time being, I don't see much point. I imagine that eventually I'll be more or less forced to deal with passkeys in at least some contexts. Will leave that for later.For now, it's all a big "no thanks" from me.
  • legitster
    I think about this a lot when using our corporate SSO tool.When I hit the button to log into Slack, there are like, 3 popups in succession - the last one ultimately asking for my fingerprint. Then when I give it, there is a flurry of web pages that get loaded and redirects that happen until finally Slack pops up again.There isn't any realistic world in which I check each window to make sure everything is happening right and I am not being MitM'd.I'm a fairly technical person, and I would be unable to perceive the difference between a really tight security environment and my computer being hijacked.
  • tonymet
    The fundamental blind spot engineers have had with every authorization protocol for 30 years is forgetting that trust must be mutual. The lone exception has been phishing prevention with user-selected avatars, and that didn't last long.Every advancement in "security" has assumed the service needs to more strictly identify the customer, without caring about the customer's trust for the service, or experience with performing the identification ritual.So when your bank asks you for a code or your mom's maiden name, they never offer anything to verify they are who they say they are. whenever I ask they say "of course we're from chase, we just called you", without realizing how absurd that is.Now Passkeys suffer an even worse dilemma. Now the customer has 3 dimensions of tools to record & use in order to log in. Did I use email, google, facebook, apple ID to log in? Did I save this code via phone, text, authenticator app (which one, there are multiple incompatible ones)? Did I use a passkey ? where is that passkey located? my phone, my browser storage, my authentication extension.We started with a single dimension of email + password to log in. Now it's an entire decision tree that has to be recorded. How do you even record this? disqus : credential = email, password = "see bitwarden", 2fa = microsoft authenticator, passkey = "on iphone in icloud" viator: credential = google sso, password = same, 2fa = symantec, passkey = "edge on windows 11 laptop in office" This is absolutely absurd!I thought engineers were tested for scaling during the interview process. This protocol doesn't even scale to a single site.
  • schmichael
    I mostly love passkeys to be honest even though I use multiple browsers across multiple devices and OSes (iOS, Chromebook, Linux, macOS, Xbox, etc). Bitwarden’s support is (finally) pretty good.My problem is that I manage a lot of accounts for my family which makes passkeys a nightmare. If I’m out and a kid gets chucked into a login flow that happens to require a passkey, I can’t text a password and TOTP code to the adult with them. I know that’s terrible opsec but the reality is people share accounts and passkeys are designed to thwart that.
  • ranger207
    The website for my HSA required me to set up a passkey last time I logged in. I set it up on my work laptop and my work password manager, which means I can now no longer access my account from my personal computer. This is fantastic, just what I wanted
  • herf
    I think portability is very confusing: they rolled out passkeys with no device portability (device-bound) and only recently added it (CXP). So for anyone with multiple devices it was a relative disaster - why should my Windows PC hold a device-bound passkey to anything? How do I login on Linux or macOS? Picking a password manager to do portability also means another kind of lockin, though maybe you can live with that kind if you really trust the company. Even so, the password managers all seem to be competing to have relaxed security, so that vault and account passwords are the same, or you are asked to type your master password into a webpage - surely we didn't replace per-site passwords with this?
  • TechRemarker
    Yes, a bit of a mess. As the only practical way for most to use is with a password manager. So essentially, all your accounts still have a real password, just you enter that into your password manager app. So if your device is every compromised and someone has your master password then you are screwed.And of course, passkeys on most all sites don't really improve security since someone can just choose to login with user/pass instead since presumably very few sites allow you to have just passkey.Also if you use a password manager you may get locked into using that platform. Or ideally using a third party one but then having to pay a subscription, or using an open source option that is not ideal for the average person.If one uses a passkey as intended and without a password manager and the site truly only supports logging in via your passkey, for all the touted benefits of passkeys, that would be a nightmare if a person loses access to their device, etc.
  • et1337
    Throwing my hat in the ring, I think passkeys were also invented by engineers with zero understanding of the average developer: https://etodd.io/2026/04/06/passkeys-are-too-hard/
  • randomblock1
    Stop thinking of them as alternatives to passwords. That is something they do, incidentally. Really, they are an alternative to normal TOTP 2FA (and shudders SMS 2FA). Those were already dependent on an app on a single device, or a password manager. And now, you can have the security of that, automatically used with biometrics. It is only because they are so secure, due to being a cryptographic key, that they can replace passwords.They really should come up with a way to transfer them across devices/password managers though.
  • dang
    > I run a tech company and I have no idea what a passkey is and at this point I’m too afraid to askI thought I was the only one!
  • deaux
    This comment section is the best example of all time of the arrogance of Big Tech and its employees. Please try to take a second thinking outside of your bubble before commenting ridiculous stuff.Yes, as a wealthy American, you "live in the Apple ecosystem". 99% of the world doesn't. And guess what, they're affected by passkeys all the same. They use a Windows laptop, and either an Android phone or iPhone. A lot of people even have an Android phone and an iPad. And no laptop at all. But at work or school they have to use Windows.It's quite simple. Besides people "living in a single ecosystem" (discussed above, this is almost nobody), passkeys are only viable (i.e. not very painful to use) if you use a dedicated cross-platform password manager. Yet people who use those - which too is a globally negligible percentage - are exactly the people who tend to have near nothing to gain from passkeys, and only to lose. The majority of them is tech-savvy and they use auto-generated unique passwords. In that scenario, the minuscule improvement in security is meaningless and not worth it.Ironically, this comment section shows exactly why passkeys are a shit show. Half the people here are exactly those who are coming up with this shit in their FAANG jobs, happily part of the global 1% (of which their tech-illiterate grandma too is part of), and they have no idea or care in the world for the remaining 99%. Unless of course this was simply a land grab for lock-in, which is about as likely.
  • datakan
    Passkeys are just SSH keys in how they work. We've been doing this since the 90's. The only people that use SSH keys are the Linux savvy users and those who are forced to via an enterprise solution for vaulting.The average person doesn't know anything about this stuff nor do they care. I also have yet to see a Passkey solution that didn't also have a password on it and a nice little box letting people choose to use the password instead of the passkey. They just added a new layer on top of all the old ones and created confusion. Now people use password and passkey interchangably in conversations and no one knows what they are talking about.
  • techteach00
    I like the authenticator option. I literally cannot understand if that's the same thing as passkeys.
  • johngalt
    If you want a consistent, and seamless authentication experience, then one party has to own that experience. Go federation/SSO. Sign into everything with microsoft, or google as your identity provider, and live with the privacy implications.Passkeys are great, and they take a significant amount of work away from the user, and make them much less prone to phishing attacks while also not turning their entire online identity into the property of google. I've had much more luck with onboarding non-technical people into a yubikey vs a password manager. Platform authenticators tend to trip people up. However, the process of adding a new key is getting much more consistent, and legible to people over time, and things will settle on platform authenticators rather than external physical keys for most use cases.
  • AJRF
    I keep seeing people working on Passkeys get real defensive when told they don't make sense to people.I've worked in tech 12+ years and I _hate_ when a Passkey prompt comes up, its only ever slowed me down.But the devs who work on them are quite rabid, and keep dismissing real criticism of their implementation.
  • gchamonlive
    I really don't get passkeys and how they are supposed to be safer.Currently I save all login tuples to Bitwarden and store OTP secrets onto Aegis. Could have been 1password and authy, it's irrelevant. The thing is, I only get pwned if both are compromised.Now with ubiquitous passkeys in Bitwarden if someone has access to my vault unencrypted it's already endgame.
  • brachkow
    Passkeys work well when you have password managers with multi-device sync. While it is indeed trivial to get one, consumers don't like password managers in first place. And it is very hard to make person use password manager, instead of his john1988 type of password
  • beaker52
    Passkeys are a political play aimed at bolstering government support. They’re the privacy sabotaging arm of Digital ID. They go hand in hand with “age” verification. It’s all the same play. Get your identity, get your access credentials, give it to the prying eyes.
  • joshstrange
    My biggest issues with Passkeys is how inconsistently they are implemented and how opaque they attempt to be.I understand SSH keys, I've been using them for decades, I know where they live, I know how to secure them.Passkeys are murky as fuck. Is your PW manager supported? Do they sync? Where are they stored? How can I move to another PW manager if I want to in the future? Can I have more than 1 passkey per site? And the list goes on.I _know_ some of you out there can answer some/all of the questions above but it's mostly on a per-site basis. Passkeys take too much of the control out of my hands and I don't like that.Even more than that, I hate how they are trying to be pushed on me at every turn. Login -> Want to save a passkey (but they never call it that, they use some other confusing euphemism)? I click "No" and then it proceeds to pop 1Password's UI, then I dismiss that and it opens Chrome's passkey save UI, I dismiss that, and then it opens the OS's passkey UI. It's incredibly disrespectful and unclear.I never use anything but 1Password but somehow everyone (OS and Browser) try to reach their grubby hands in. This is what scares me, I don't like having to be on high-alert to not accidentally save a passkey in Chrome or Safari and not realize until I'm on a different device and notice it's not in 1Password.Lastly I trust the developers implementing passkeys... none, I trust them none, zero, zilch. I don't trust them to pick the right defaults, I don't trust their recovery options, and I know they will always pick the configuration that benefits them and not me.No, for now I'll stick with my as-long-as-you-let-me-make-my-password random passwords which I never copy/paste into random website and be perfectly safe, thank you.
  • coldpie
    Passkeys are a vector for locking your logins to Big Tech ecosystems. They support device attestation, which means the service you are logging in to can require you to only use certain Passkey clients such as those provided by Google, Apple or Microsoft. The Passkey spec authors also maintain a list of "naughty clients"[1], which are clients that allow the user to manage their own data how they want. Services could choose to block those clients for "security reasons," justifying the decision to force you to use one of the Big Tech providers.Until device attestation is removed or strongly curtailed in the spec, I suggest you do not create any Passkeys. Which sucks, because it's otherwise a pretty cool tech.[1] https://passkeys.dev/docs/reference/known-issues/More sources here: https://www.smokingonabike.com/2025/01/04/passkey-marketing-...
  • modeless
    I find Google Password Manager makes passkeys pretty easy to use. As long as you don't accidentally create a passkey some other way. Hopefully websites will adapt to the reality of how people use passkeys in practice and some of the UX weirdness around them will disappear over time.One annoying thing though is that while they recently added password sharing, they don't allow sharing passkeys. Basic passkey sharing would be nice, but it also seems possible to implement fancy sharing features that wouldn't be possible with password sharing. Things like sharing one time use passkeys or time limited passkeys or limited access passkeys or secure revocation of shared passkeys. I hope people are thinking about this.
  • TitaRusell
    Security people don't care about usability. They genuinely think we are all CIA field agents.Look I remember my PIN everything else is in Firefox password manager.
  • MBCook
    I will never understand how a small group of tech savvy people are heavily confused and against a simple and more secure system.You want anecdotes? Ok. I’ve had elderly adult relatives who aren’t good with their devices tell me unprompted they’re using them and like them when I mentioned the word out loud to myself using my phone around them.These are people who don’t know the difference between apps and the web. Who have 200 tabs open because they don’t know what tabs are so a new one just gets opened automatically all the time. Can’t tell some websites apart. Who change their passwords on every login to some sites because they can’t get sign in right.Yeah if you want to write them down or refuse to save passwords outside text files or demand they live on a security key on your keychain you’ll have a hard time. You’re being 0.0000001% of the user population. You’re not representative.They are a MASSIVE UX win. A MASSIVE security win.I’ve logged into my work computer with a passkey on my personal phone, no issue. It’s fine. They’re backed up locally. It’s fine.The biggest problem, which is getting better and somewhat a transition problem, is sites using terrible UX to trigger the workflow. Those that follow the suggestions or close to it are great.I love passkeys. I just don’t get the confusion.
  • apparent
    I don't use passkeys because I can't tell if they're a one-way door. If I use it once, can I still use passwords to log in in the future?I also don't understand how the system works when things go wrong (someone hacks your account, etc.). I don't even understand all the ways things could go wrong with passkeys.Seeing the comments here makes me realize I'm not stupid or ignorant for not understanding these things. Some people do understand them much better than me, but there is no universal answer that emerges after sufficient study.I will continue to stay away from passkeys.
  • mnls
    I’ve read all the answers. I still don’t get it. I find it WAY more complicated than copy/paste or a browser extension that does that for me.I hope it won’t become mandatory. (I honestly doubt).
  • epistasis
    I think the problem was that there wasn't a "Best Practices" way of using them when they were launched, which really prevented describing them in a consumer-friendly way.And web site implementors couldn't follow that golden path, or describe the golden path, so there's fragmentation in usage and meanings and practices, making it far more confusing.I love passkeys, I want to eliminate any and all password-based logins and switch entirely to passkeys. It's such a better experience, it's a "physical" key that can be backed up to multiple devices, and thinking of it like a key for a physical lock really gets at the core of its capabilities. But locks can be used in many many ways! Maybe you need to open the lock and still tell the guard a password, which is weird, but how most websites still operate.
  • rglover
    This is mostly a complaint about bad copy/explainers in Google's UI. Passkeys, properly implemented, can be perfectly consumer friendly (e.g., Apple Touch ID is delightful).
  • EPWN3D
    I don't know everything there is to know about passkeys or anything, but my reaction to most of these comments is "You're passing yourself off as someone who has relevant opinions about security, and you can't possibly imagine how these things work or how they're useful? Come the fuck on."Passkeys are basically session cookies that are signed by a secure element in one of your devices at the time you log in. That's it. They cannot be phished because there is no password to steal. If I had to guess, the basic flow is something like this:1. When the passkey is created, the device's secure element coughs up a public key or something to the server representing itself as a trusted device2. When a user logs in, the server issues a challenge (basically a random number) to the device and says "sign this with a private key that corresponds to one of the trusted public keys I have"3. The secure element signs the challenge and sends it back4. The server goes through its list of trusted device public keys until it finds one that verifies the challenge response. If it finds one, it logs you in. If it doesn't, you don't log inStep (1) is probably bootstrapped with a username/password and second factor like SMS 2FA, OTP, or email 2FA.Even if this isn't exactly how they work, it's a plausible implementation. Nothing about this requires vendor lock-in. The various secure elements that can produce passkeys come from many different places, so I'm sure sufficiently motivated open source people could create a firmware TPM that is certified for use with passkeys or something if they cared enough.
  • lrvick
    At Caution we -exclusively- allow passkeys. The entire database is user ids and public keys. If it leaks, it would only be mildly annoying.If you are confused about digital passkeys, you can use a physical yubikey or nitrokey and tap it when it blinks. You can treat them like a credit card or house keys.Asking people to keep up with and remember passwords is and always has been the thing that was invented with zero understanding of the consumer brain.
  • Dwedit
    I just stick with TOTP.
  • ghostly_s
    We've all been through at least a couple rounds now of the security industry pressing us to change how we log in, ostensibly in our best interest: impractical complexity requirements, 2FA, "magic links," ridiculously short session expiry, whatever this bullshit is with the username and password on separate pages that make your password manager less convenient.The only observable outcome of each of these changes has been making these products less convenient for us to use. At this point I don't think I am alone in being knee-jerk opposed to any further "improvements." I have yet to see a website make a case for a passkey being more convenient than what it is replacing, so I will continue opting out of them as long as I am allowed to.
  • ElijahLynn
    I only use pass keys by storing them in 1password. Then I don't have to worry about the whole "lose/broke/replace a device" thing, which is inevitable. Then just be really good about keeping your backup codes etc with 1pass solid.
  • luciana1u
    the real achievement of passkeys is making people nostalgic for passwords
  • 827a
    Passkeys are so, so, so bad. One of the worst things our industry invented. The sooner sites start leaving them on the wayside and just go back to TOTP, SMS, and Email codes/links, the better. These work. We solved auth. Its fine.
  • jbombadil
    Another noteworthy annoyance is the increasing number of services that try to aggressively push you towards passkeys, without you ever asking.Every other time I open the Costco app (needed to walk in to the store, since I don't carry my card and they refuse to provide Apple Wallet integration) I get asked to switch to passkey, without a way of saying "don't ask me again".If you're in any position to determine this in your company/software, please stop this pattern. Give users the option to say "stop asking me about passkeys".
  • usernametaken29
    I don’t understand this point at all. I think the author has himself confused with the average consumer. For the first time in a decade or so you can buy a PHYSICAL key and use it to sign into websites. I can explain this to any grandma out there. Likewise, I’m an Apple user. Once you’re in Apple universe passkeys are extremely easy. Tap your thumb on the scanner, done. Now we can put on the tinfoil hat and say how this fosters vendor lock in yadda yadda but the last thing I would say is that it has terrible user ergonomics. LOL
  • mullingitover
    You’d think a head of product at a tech company would embrace a “it’s literally impossible to have your password stolen if you use this” technology.
  • thescriptkiddie
    > Imagine you’re a boomer and you just figured out how to store your passwordsi'm gonna stop you right there
  • varispeed
    I find it difficult to explain how to use password manager to non-IT person. Whatever I say, they say it is not secure. No amount of explanation will change their mind. They prefer to keep their passwords in their physical note book hidden in the safe (yes, they open the safe etc each time they need to log in somewhere when they get logged out).As someone with ADHD a passkey is something I can lose easily and I don't want my accounts to be tied to any specific device. What if I have to upgrade my laptop tomorrow because one I use got bricked? Sounds like an absolute nightmare.Password on the other hand I can remember for dozens of services, each very long.
  • voidmain0001
    It just so happened that Microsoft sent an email today to our M365 tenant administrators that SMS and voice for 2FA is being removed 1-Feb-2027 and that automatic enrollment to passkeys starts 1-Sep-2026. Bring on the passkey overlords. Although, LLMs say that passkeys are superior to passwords since it includes a public/private key setup with the private key saved to a device that requires a PIN or biometric to access the private key.
  • stalfosknight
    I do not understand all of the drama surrounding passkeys. They work flawlessly for me on all my devices. Maybe that’s because I’m all-in on Apple devices, but I have yet to have a single problem with passkeys.
  • ChoGGi
    Passkeys? That shit that's not a password or a crypto key that I never use?
  • otikik
    Ah! Like Pgp
  • dp-hackernews
    Why not use SQRL instead?
  • baking
    I find it annoying that gmail has simply decided that my unlocked phone is more secure than my computer.
  • sergiotapia
    One of the worst technologies I've had the misfortune of being forced to use honestly. It's always confusing and always breaking or not working as I expect across my devices?
  • waffletower
    The cumbersome and poorly designed workflows surrounding passkeys are a significant hindrance to their adoption as well. It surprised me how bad they were when they emerged -- it was as if the UX was intentionally designed to kill passkey adoption.
  • maples37
    I'd like to try passkeys out. I actually tried again on Amazon in response to reading the comments here. But it just.... doesn't work?I'm on a laptop running Ubuntu, I use Firefox as my browser, and I use 1Password as my password manager. I have both the browser extension and native Linux application installed, and they sync/communicate with each other (so if I unlock the native Linux app, the browser extension also unlocks).When I open my Amazon.com item in 1Password, it has a helpful link to https://passkeys.directory/details/amazon which tells you clearly, step-by-step how to set up a passkey. Great! I love clear directions.But when I get to the step when I click the "Set Up" passkey, Firefox gives me an address bar pop-up saying "Touch your security to continue with www.amazon.com".Huh?I don't have a security key. My laptop does have a fingerprint reader, which I use to unlock my screensaver (and it's integrated with some KDE keyring thing), so I tried putting my finger on that. Nothing. I opened the 1Password extension. Nothing there, just normal view of my login info. I opened the 1Password native application. Nothing there either.Maybe it's a Firefox issue, or a Linux issue? So I tried setting it up on my phone (running GrapheneOS and their Chromium-based browser), which has the 1Password app installed. I logged in, and this time got far enough that 1Password brought up a prompt asking "Do you want to save this passkey?" I tapped Yes, and it then immediately told me "Unable to save passkey: For security reasons, 1Password did not save this passkey. The associated URL for this passkey does not match the selected app." So... does that mean 1Password is refusing to touch the passkey because it didn't come from the com.google.chrome Android application?This whole experience has re-affirmed my skepticism of passkeys in practice. I think it would be awesome to have public/private key security on my online accounts. I think it would be great if I could log in without having to copy/paste passwords (when autofill doesn't work, or for TOTP codes). But I have zero confidence that this opaque stream of bytes will actually work to get me logged in to my account. When the 1Password input field detection fails, I sigh, copy/paste my username and password, and then forget about the mild inconvenience after about 30 seconds. I don't even want to think about what would happen to an account if the only way to log in to an account was via passkeys.
  • WesolyKubeczek
    Passkeys do have drawbacks and tradeoffs, as has everything, but my god did I feel the energy of „lol I’m so bad at math” in that tweet and a lot of „lol smelly nerds” in replies.
  • yegle
    I don't know how to rationalize it: is passkey so good that even the banking apps start pushing it, or is it all a big conspiracy theory with a hidden agenda?
  • junaru
    Passkeys were invented so hacked sites could brush off their leaks with "no credentials were leaked" and minimise any regulatory fines. This is the reason why its being pushed by the big players.Additionally this puts the same players in control of your logins - want to sync your passkeys? - enable "iCloud Keychain", or some other 'trust me bro' app that will 'securely store/sync your data' - no thank you.In perfect world users should be able to generate a certificate, upload it to a couple nfc capable ubikey like devices that blow a fuse afterwards preventing from additional writes/reads and use that to login to every app ever. You would buy such devices in packs of 3, upload same cert to all, hide the other, burry the third.
  • inquirerGeneral
    [dead]
  • sehw
    [dead]
  • bflesch
    My tinfoil hat take is that there's significant interest to keep everything digital, always-online and connected to the major providers, so it can easily be snooped by five eyes using their omnipresent backdoors.Passkey biometrics also allow you to confirm certain person is holding the device right in this very moment, and not receiving a TOTP via walkie-talkie. Especially important for kinetic sanctions.If you check out their Terramare group of companies those guys are still using typewriters. Unless you're US/UK millionaire I recommend to stay as analog as possible with physical password book and TOTP/yubikey.Same with the push for "post-quantum crypto" and elliptic curves. I feel my systems get significantly more attention when using 8k RSA than any of its modern replacements. While I love wireguard the transition to ED25519 felt way too smooth..
  • IceHegel
    I think there are probably sinister motives behind some of the push to pass keys, but you'd think that if that were true, they would make it really quite easy to add one and to use.That is not the case. The entire setup/enrollment/add a passkey to your account processing is DMV inspired.
  • justSAYnooo
    Consumer passkeys are just an extension of the OMB Policy Memorandum M-19-17, Enabling Mission Delivery through Improved Identity, Credential, and Access Management (dated May 21, 2019). It is ultimately part of anti terrorism efforts with regard to banking and fraud. Think of this as consumer computer version of the scene in the movie The Baader Meinhof Complex when the cops are discussing a proposal for electronic data processing. "According to a poll by the Allensbach Institute, one in four Germans under 30 sympathizes with the RAF. That's nearly 7 million people. That amounts to an enormous pool of sympathizers, which makes the search for perpetrators extremely difficult." It signals the end of publicly available general computing. This was always inevitable, the mob cannot be trusted with weapons of mass destruction. Computers = Guns
  • ectoloph
    Passkeys are a mitigation against users being bad at password hygiene and phishing being a real issue to users.You can't phish a passkey, and you don't rely on the user providing you 'hunter2' on every site.As for vendor lock in? No. The specs are open. You can run the code on a microcontroller, or, you can keep it in your arm with something like the Vivokey Apex. Note that the FIDO2 for the Apex is an open source Javacard applet.The UX on the other hand is not great. If you have a password manager, your OS may prompt you which target to store the passkey with.