‹ BackHN Continuity

Thread

I don't like passkeys

853 points · 819 comments · ethanhawksley

  1. drtz · · focus · HN ↗
    Passkeys do marginally improve security against MITM and phishing attacks, but they are primarily for protecting the lowest common denominator from themselves: people who re-use passwords and/or don't use a password manager.

    If you use multiple devices throughout the day, registering passkeys in all of these systems becomes a big headache with O(m*n) complexity, so putting the passkeys in a password manager is the only realistic solution. But this still breaks the login flow for a very common use case: how do I log in on a device that I don't own? With a password in a password manager I at least have the option of manually typing the password.

    The biggest problem, though, is how users are pushed into it without any warning or knowledge of what they're signing up for. I've accidentally set up passkeys just by clicking an okay button a few times in the past and had to go back and figure out how to undo it after being blocked from login on another computer (which computer was I on again?).

    1. HaloZero · · focus · HN ↗
      My MIL setup a passkey accidentally on her Google account and now has no idea where it is. Removing it now requires her password which she’s also forgotten. But now for some reason on Google I can’t initiate any type of forgot your password flow because of how Google sets up things and I have zero clue where she stored the passkey.
      1. UltraSane · · focus · HN ↗
        Doesn't the passkey have to be on her phone or computer?
        1. HaloZero · · focus · HN ↗
          It should be but haven’t checked her apple vault. I checked Google password manager and her windows password manager and there nothing in either. She might have used her phone and it’s in her iOS vault which I’ll check next. But this is what makes this entire passkey thing a mess. She’s 75, she didn’t do this on purpose and the ecosystem is just a mess
          1. lukan · · focus · HN ↗
            Everything about it is.

            Also in the process of helping my dad with his phone, 76 and my grandmother 99. Maybe this works better with Apple, but the biggest problem on Android is, that it feels like every update shuffles everything around. Allmost no point in explaining, that they can solve some things on their own.

            And all the time new things on the screen, new features they don't understand, need nor asked for.

            1. UltraSane · · focus · HN ↗
              Apple does seem to have one of the best and most secure passkey implementations.
              1. RHSeeger · · focus · HN ↗
                A little snarky, but...

                It _is_ true that it's more secure when even the people that the passkey was created for can't use it.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.