‹ BackHN Continuity

Thread

I don't like passkeys

853 points · 819 comments · ethanhawksley

  1. elteto · · focus · HN ↗
    While the technology itself may be great (I don't really know since I don't use them) it has been co-opted by the tech conglomerates as another form of isolating and walling off users into their ecosystems.

    And honestly, nowadays, if tech companies are pushing really hard for something then that is an immediate red flag for me and it bears more scrutiny. One of those "if you see them running that way you run the opposite way".

    1. reddalo · · focus · HN ↗
      Exactly. That's why I'll never use passkeys: they're just another way to force us into a commercial walled garden.

      Passwords with 2FA are simply better and more freedom friendly.

      1. Shank · · focus · HN ↗
        I store my passkeys in KeePassXC and I have absolutely no feeling of being walled into any garden, personally.
        1. EvanAnderson · · focus · HN ↗
          Wait until websites start demanding device-bound/attested passkeys. Big tech just needs to get enough adoption to make this change.
          1. nbobko · · focus · HN ↗
            As much as I hate to admit it (because I love passkeys UX), but I do think that device-bound/attested passkeys are going to happen in the future :(
          2. Shank · · focus · HN ↗
            Nobody is going to do this because Apple’s devices don’t support this for the Passwords app out of the box
        2. tonoto · · focus · HN ↗
          but what do passkeys offer in terms of security, when stored in password managers, compared to having a (password manager) generated password and a totp?

          I believe that by allowing password managers to store passkeys, the whole purpose of "device based security" got lost..

          1. flumpcakes · · focus · HN ↗
            Yes. I use hardware based passkeys and absolutely love them. I think it was a giant mistake having them 'software' based. It some ways it kind of defeats the entire purpose...
          2. qlte · · focus · HN ↗
            They are 100% immune to credentials phishing. You literally cannot authenticate to an impersonator site based on cryptographic guarantees.

            And yes, I know the happy path of password managers uses host-based autofill which does add some friction to phishing attempts, but given the prevalence of unexpected but legitimate urls with weird alternate subdomains/SSO/redirects in modern login flows, you have to manually autofill/add an exception often enough that it's possible to let your guard down once at the wrong time.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.