‹ BackHN Continuity

Thread

I don't like passkeys

853 points · 819 comments · ethanhawksley

  1. kenrick95 · · focus · HN ↗
    Passkeys have a marketing problem where no one is able to describe simply what it is without having to use technical jargon. There's also the problem where each OS tries too hard in pushing this to the face of end-user
    1. cfiggers · · focus · HN ↗
      Imagine a password, but it a) types itself for you and b) detects when it's being sent to an impostor site and blocks them from seeing itself, so it can't be phished.

      Tada, passkeys.

      1. rcxdude · · focus · HN ↗
        Cool, where are they stored? (I know the answer: 'it depends', and that's the big problem with their usability: most users haven't a clue what the answer is and most tech support can't answer that question straightforwardly because it depends on some decisions the user probably didn't even realise they made).
        1. iamnothere · · focus · HN ↗
          On my keychain in a USB hardware token. With a couple of backup tokens in fire safes.
          1. rcxdude · · focus · HN ↗
            If you're using a USB hardware token your knowledge of it is at least an order of magnitude better than the median user's. I know where my passkeys are stored, I don't know where my family member's passkeys are stored and neither do they. The same is true for most of my otherwise fairly technical co-workers.
            1. iamnothere · · focus · HN ↗
              [delayed]
              1. ampersandwhich · · focus · HN ↗
                Absolutely not. If that is required, I will do my damndest to only use implementations that deliberately lie about the hardware status. Your line of reasoning is dangerous.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.