‹ BackHN Continuity

Thread

I don't like passkeys

853 points · 819 comments · ethanhawksley

  1. drtz · · focus · HN ↗
    Passkeys do marginally improve security against MITM and phishing attacks, but they are primarily for protecting the lowest common denominator from themselves: people who re-use passwords and/or don't use a password manager.

    If you use multiple devices throughout the day, registering passkeys in all of these systems becomes a big headache with O(m*n) complexity, so putting the passkeys in a password manager is the only realistic solution. But this still breaks the login flow for a very common use case: how do I log in on a device that I don't own? With a password in a password manager I at least have the option of manually typing the password.

    The biggest problem, though, is how users are pushed into it without any warning or knowledge of what they're signing up for. I've accidentally set up passkeys just by clicking an okay button a few times in the past and had to go back and figure out how to undo it after being blocked from login on another computer (which computer was I on again?).

    1. dspillett · · focus · HN ↗
      > The biggest problem, though, is how users are pushed into it without any warning or knowledge of what they're signing up for.

      My irritation is that I know what it is, and I've said no thanks many times, but I'm still asked regularly by the likes of Amazon, and they usually pick a time when I'm trying to order something quick¹. It is one of the growing number of things in life that simply have no “no” option, it is always “yes or later” - I wouldn't mind so much if “later” meant “I know the option exists, I'll ask for it if I change my mind, don't bother me again otherwise”. Call me cynical, but if companies are trying to nag me into something I very much doubt the main benefit is mine. I'm sure there are many people out there who go along with it simply because they are sick of being asked repeatedly.

      I also don't see the real benefit with the way things are often implemented anyway. When the credential recovery process is sending a magic email or text, making SMTP or SMS the weak link of the chain just as it often is for passwords so I'd be giving up my preferred workflows for no better security.

      ----

      [1] A short while ago I actually ordered from somewhere else because of this, bitter twit that I am. “I wonder if I can get this almost certainly drop-shipped item on next day delivery via Prime?”, [goes to Amazon to check], [get passkey prompt], “sod it, I'll go back to the original place”.

      1. Telaneo · · focus · HN ↗
        > My irritation is that I know what it is, and I've said no thanks many times, but I'm still asked regularly by the likes of Amazon

        The people responsible show a distinct lack of understanding when it comes to consent.

        1. ryandrake · · focus · HN ↗
          Silicon Valley has no concept of consent and boundaries. If computing was a night club, "Silicon Valley" is the guy who goes up to every woman saying "Want to dance? [Yes or Maybe Later]?"
          1. pixl97 · · focus · HN ↗
            I don't think you carried on the analogy far enough.

            >Want to dance? [Yes or Maybe Later]?, also drink this [Yes]"

            1. sippingabonedry · · focus · HN ↗
              A better analogy would be slipping something into her drink whilst handing her a 12-page stapled terms of service agreement in which she unknowingly gives full consent.
              1. pixl97 · · focus · HN ↗
                Meta: As you see the anal box as already been checked with unerasable ink.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.