‹ BackHN Continuity

Thread

I don't like passkeys

853 points · 819 comments · ethanhawksley

  1. BoppreH · · focus · HN ↗
    Completely agree. I think the root of many of its issues is the inability to add a key that you don't currently hold. This prevents me from storing a backup key in a safe, for example.

    I proposed an alternative scheme many years ago: <a href="https:&#x2F;&#x2F;www.researchgate.net&#x2F;publication&#x2F;343318317_Privacy-aware_web_authentication_protocol_with_recovery_and_revocation" rel="nofollow">https:&#x2F;&#x2F;www.researchgate.net&#x2F;publication&#x2F;343318317_Privacy-a... . By allowing &quot;offline&quot; keys you can also treat them as higher priority, and use them to revoke any lesser keys from attackers if your account is compromised.

    It would also be nicer to get rid of usernames, but that&#x27;s a fight against the data-gathering powers that we&#x27;re unlikely to win.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.