‹ BackHN Continuity

Thread

I don't like passkeys

853 points · 819 comments · ethanhawksley

  1. elteto · · focus · HN ↗
    While the technology itself may be great (I don't really know since I don't use them) it has been co-opted by the tech conglomerates as another form of isolating and walling off users into their ecosystems.

    And honestly, nowadays, if tech companies are pushing really hard for something then that is an immediate red flag for me and it bears more scrutiny. One of those "if you see them running that way you run the opposite way".

    1. reddalo · · focus · HN ↗
      Exactly. That's why I'll never use passkeys: they're just another way to force us into a commercial walled garden.

      Passwords with 2FA are simply better and more freedom friendly.

      1. apexalpha · · focus · HN ↗
        I just bought a passkey... It's a USB device, completely separate from any big conglomerates.
        1. reddalo · · focus · HN ↗
          But then you need to phisically carry it along with you everywhere you go, if you want to log into a service :/
          1. apexalpha · · focus · HN ↗
            Yes, it’s like a key. :)

            Though realistically I use a passkey for services I care about and a password manager for the rest.

            1. eikenberry · · focus · HN ↗
              Keys can be copied very easily. It’s one of their primary features. Can you easily copy your USB key?
              1. jazzyjackson · · focus · HN ↗
                Yubikeys are Secure Enclaves designed to not be copyable
                1. eikenberry · · focus · HN ↗
                  Right. That's the flaw I was pointing out.
              2. krupan · · focus · HN ↗
                Physical keys can easily be copied, and physical locks can easily be picked. That might be fine for your house or storage unit, but for your bank account or your car (newer cars no longer have simple physical keys/locks), we've moved beyond that tech.
                1. mrguyorama · · focus · HN ↗
                  That any and all physical security measures can be defeated is a feature, not a bug. Almost no human beings actually need that level of security, and the tradeoffs are absolutely not worth it for those of us without Mossad as a threat.

                  How often do people lock themselves out of their own house? Don't you know anyone with ADHD? Imagine any time that happens it is mathematically verifiably permanent as a fact of reality itself. It doesn't matter that the state still views you as the legal owner, you are never allowed in ever again.

                  1. krupan · · focus · HN ↗
                    No web service is like that. They all offer recovery options. We aren't talking about Bitcoin here.
                    1. EvanAnderson · · focus · HN ↗
                      The trend of companies becoming easier to contact is well-documented.
                    2. Telaneo · · focus · HN ↗
                      Tell that to the people who have lost access to their Google account.
                      1. krupan · · focus · HN ↗
                        Now we aren't talking about a security problem, we're talking about who really owns what. Google can lock you out of your account no matter what kind of authentication they use for that account
                        1. Telaneo · · focus · HN ↗
                          It's a lot easier to be locked out with a passkey than without one.
                          1. krupan · · focus · HN ↗
                            No it's not. Google flips a bit in their database and no matter what kind of authentication you set up with them, you get denied
                            1. Telaneo · · focus · HN ↗
                              This does not reflect my own lived experience.
                              1. krupan · · focus · HN ↗
                                I'm not even sure what your point is anymore. If Google decides they don't want you to log in anymore, you can't log in anymore. It doesn't matter if you try to log in with a passkey, a password, your fingerprint, or sending a secret code in with carrier pidgeon. This has nothing to do with passkeys vs passwords vs anything else.

                                If Google does want you to be able to log in then they will work with you to make that happen, whether you forgot your password, lost your passkey, or your carrier pidgeon died.

                                Passkeys are not special in this regard at all. What does make them special is that nobody can use a phishing attack to steal your passkey and log in to your account. Nobody can guess your passkey and log into your account. Nobody can intercept your passkey in flight and log in as you. That's the important distinction.

              3. apexalpha · · focus · HN ↗
                You can 'copy' it by registering a new one to the service.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.