Passkeys have a marketing problem where no one is able to describe simply what it is without having to use technical jargon. There's also the problem where each OS tries too hard in pushing this to the face of end-user
Imagine a password, but it a) types itself for you and b) detects when it's being sent to an impostor site and blocks them from seeing itself, so it can't be phished.
Cool, where are they stored? (I know the answer: 'it depends', and that's the big problem with their usability: most users haven't a clue what the answer is and most tech support can't answer that question straightforwardly because it depends on some decisions the user probably didn't even realise they made).
If you're using a USB hardware token your knowledge of it is at least an order of magnitude better than the median user's. I know where my passkeys are stored, I don't know where my family member's passkeys are stored and neither do they. The same is true for most of my otherwise fairly technical co-workers.
Absolutely not. If that is required, I will do my damndest to only use implementations that deliberately lie about the hardware status. Your line of reasoning is dangerous.
kenrick95 · · focus · HN ↗
cfiggers · · focus · HN ↗
Tada, passkeys.
rcxdude · · focus · HN ↗
iamnothere · · focus · HN ↗
rcxdude · · focus · HN ↗
iamnothere · · focus · HN ↗
ampersandwhich · · focus · HN ↗