‹ BackHN Continuity

Thread

I don't like passkeys

853 points · 819 comments · ethanhawksley

  1. kenrick95 · · focus · HN ↗
    Passkeys have a marketing problem where no one is able to describe simply what it is without having to use technical jargon. There's also the problem where each OS tries too hard in pushing this to the face of end-user
    1. cfiggers · · focus · HN ↗
      Imagine a password, but it a) types itself for you and b) detects when it's being sent to an impostor site and blocks them from seeing itself, so it can't be phished.

      Tada, passkeys.

      1. flerchin · · focus · HN ↗
        But how do I type it into my new phone?
        1. vntok · · focus · HN ↗
          It depends.

          Are you part of the 99.99999% users of one of iOS+Apple or Androidlike+Google/Tencent or HarmonyOS+Huawei? If that's the case, you don't need to as the key is automagically saved by your OS' platform and synced with your new device.

          Otherwise, you're such an extreme outlier that you probably either know what you're doing or can find out by yourself, right?

          1. dspillett · · focus · HN ↗
            > … users of one of … Google …? If that's the case, you don't need to as the key is automagically saved by your OS' platform and synced with your new device.

            This absolutely does not encourage confidence in me. We all know how easy it can be to get locked out of a Google account and have no way of getting back in unless you have enough clout to make a huge noise online so a human there pays attention instead of you being stuck in the 'ol support-bot-run-around loop. It doesn't happen often when you consider how many users there actually are out there, but the potential inconvenience is high enough that “fairly rare in the grand scheme of things” is still enough to be reason enough to be wary.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.