‹ BackHN Continuity

Thread

I don't like passkeys

853 points · 819 comments · ethanhawksley

  1. drtz · · focus · HN ↗
    Passkeys do marginally improve security against MITM and phishing attacks, but they are primarily for protecting the lowest common denominator from themselves: people who re-use passwords and/or don't use a password manager.

    If you use multiple devices throughout the day, registering passkeys in all of these systems becomes a big headache with O(m*n) complexity, so putting the passkeys in a password manager is the only realistic solution. But this still breaks the login flow for a very common use case: how do I log in on a device that I don't own? With a password in a password manager I at least have the option of manually typing the password.

    The biggest problem, though, is how users are pushed into it without any warning or knowledge of what they're signing up for. I've accidentally set up passkeys just by clicking an okay button a few times in the past and had to go back and figure out how to undo it after being blocked from login on another computer (which computer was I on again?).

    1. HaloZero · · focus · HN ↗
      My MIL setup a passkey accidentally on her Google account and now has no idea where it is. Removing it now requires her password which she’s also forgotten. But now for some reason on Google I can’t initiate any type of forgot your password flow because of how Google sets up things and I have zero clue where she stored the passkey.
      1. brandon272 · · focus · HN ↗
        Ran into the same issue with my dad the other day. Has a passkey set up on his Google account. Bear in mind that he doesn’t know what a passkey is, so Google obviously sent him through a pattern at one point to get him to create one.

        He didn’t have access to it the other day and we needed access to his account. He didn’t remember his password, and we were unable to reset it because you need the passkey! No other options to authenticate for a reset were available.

        Add in the fact that I was trying to help him with this by long distance call and you can imagine the frustration.

        1. psunavy03 · · focus · HN ↗
          As someone with elderly parents, the Googles and the Microsofts of the world really don't seem to give a shit about the elderly anymore, if they ever did. Random UI updates and workflow changes with no announcements, thinking they're "intuitive."

          One of these days the product managers who push these things thinking "oh, it's easy, you just . . ." are either going to be explaining it to confused Mom or Dad, or they're going to be elderly and irritated themselves. Until then I hope they stub their toe or step on random Legos regularly.

          1. hedgehog · · focus · HN ↗
            I'm not even elderly but I would really like an e-mail client with a stable UI. I used to like Apple Mail but it's been a buggy mess since Catalina. It doesn't even sort or search mail reliably any more. It's basically a trope at this point but a robot-rewrite-in-Rust seems inevitable at this point.
            1. Terr_ · · focus · HN ↗
              A while ago I helped an elderly relative migrate off off a copy of Eudora that they'd been using for many years. (To Thunderbird.)

              Originally it was about difficulty migrating to a new laptop with a different version of Windows, but I was quite firm about it because when I realized it wasn't able to do secure connections for some reason, so the instant they took their laptop to public Wi-Fi...

              1. Terr_ · · focus · HN ↗
                [delayed]
        2. [deleted] · · focus · HN ↗

          [deleted]

        3. lokar · · focus · HN ↗
          I set my father (late 70s) up with a physical passkey (yubikey), and a backup key. He uses it for the important accounts (google, apple, bank, etc).

          It’s been fine.

          1. ChoGGi · · focus · HN ↗
            Yep, I've never had Google, PayPal, or Amazon ask me about a passkey with a yubikey.
            1. lokar · · focus · HN ↗
              The current ones are passkeys
          2. bootlooped · · focus · HN ↗
            This is why I've always been a fan of these. They are easy for laypeople to understand.
          3. jesseendahl · · focus · HN ↗
            Yubikeys generally have much worse recovery scenarios than passkeys do, for consumers. In enterprise if you lose your yubikey, an IT admin can help you get back into your account. If you lose a security key as a consumer, you're generally in a much tougher account recovery situation.
            1. lokar · · focus · HN ↗
              You need extra backup keys in a safe place. They don’t explain that well.
              1. 0cf8612b2e1e · · focus · HN ↗
                Not all services let you enroll multiple keys. Amazon, with all the money in the world, was guilty of this for a long time.

                Practically, it is a huge challenge. I would want my day to day fob, an onsite backup, and an offsite backup. That’s a lot of hassle and potential for mistakes. To even register the offsite backup means I need access to it. Remotely copying a password database is so much reliable

                1. atanasi · · focus · HN ↗
                  If you use a security key only for the most important accounts like Apple or Google, keys are set up once and then unchanged for years.
        4. jesseendahl · · focus · HN ↗
          >He didn’t remember his password, and we were unable to reset it because you need the passkey! No other options to authenticate for a reset were available.

          Google treats both a password and a passkey as a primary factor, and if you forget either of them you have to go through their account recovery flow: <a href="https:&#x2F;&#x2F;support.google.com&#x2F;accounts&#x2F;answer&#x2F;7682439?hl=en" rel="nofollow">https:&#x2F;&#x2F;support.google.com&#x2F;accounts&#x2F;answer&#x2F;7682439?hl=en

          AFAIK there&#x27;s nothing different about the recovery scenario for a Google account in that state regardless of whether it has a password in use as its primary cred, a passkey in use as primary credential, or both.

          1. brandon272 · · focus · HN ↗
            Thanks. Upon further investigation we could have hit “Try another way” on the account recovery process UI a few times to get to a workable account recovery method.

            Would be nice if Google would lay your recovery options out for you (which I am used to it doing in regard to 2FA if you are doing a regular log in) instead of having to hammer the “Try another way” link repeatedly as it cycles through options.

            1. ssivark · · focus · HN ↗
              WDYM -- I thought &quot;try another way&quot; is supposed to list all possible options instead of cycling through them!
              1. brandon272 · · focus · HN ↗
                It does when I log in. You click &quot;Try another way&quot; and then it brings up a menu of options you have for 2FA. For some reason they have designed the account recovery flow to be different.

                So, if you are used to the &quot;Try another way&quot; flow on login, it can be confusing to see an entirely different &quot;Try another way&quot; flow on account recovery.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.