‹ BackHN Continuity

Thread

I don't like passkeys

853 points · 819 comments · ethanhawksley

  1. drtz · · focus · HN ↗
    Passkeys do marginally improve security against MITM and phishing attacks, but they are primarily for protecting the lowest common denominator from themselves: people who re-use passwords and/or don't use a password manager.

    If you use multiple devices throughout the day, registering passkeys in all of these systems becomes a big headache with O(m*n) complexity, so putting the passkeys in a password manager is the only realistic solution. But this still breaks the login flow for a very common use case: how do I log in on a device that I don't own? With a password in a password manager I at least have the option of manually typing the password.

    The biggest problem, though, is how users are pushed into it without any warning or knowledge of what they're signing up for. I've accidentally set up passkeys just by clicking an okay button a few times in the past and had to go back and figure out how to undo it after being blocked from login on another computer (which computer was I on again?).

    1. judge2020 · · focus · HN ↗
      > how do I log in on a device that I don't own?

      This is solved by passkey-implementing software and devices (with Bluetooth) allowing you to log in with a QR code (Webauthn via CTAP hybrid transport). iOS and Android support this, and it’s generally not a locked-down thing if other devices wanted to do it too.

      The only use case left is in “how do I login if all my devices are stolen/fall into a body of water” in which there really isn’t an answer beyond “get (a|your) device back, sign back into your password manager, use that to get back into critical accounts”.

      1. darkwater · · focus · HN ↗
        >This is solved by passkey-implementing software and devices (with Bluetooth) allowing you to log in with a QR code (Webauthn via CTAP hybrid transport).

        Ok but how do I share my Netflix or Spotify accounts for example with those?

        1. judge2020 · · focus · HN ↗
          In general you shouldn’t - Netflix[0] really should get proper invite-based family sharing, and Spotify’s subscriber agreement has a section that defines Premium as a “Single-user Paid Subscription” and thus can’t be used by multiple people, legally (and you might be at risk of getting banned if they detect it)

          However, passkeys can and are available to be shared via password managers. They’re not locked to the secure chip on the device where they live usually. iOS’ Passwords app has a share button and 1Password lets you share passkey-containing items.

          In fact, the QR code login feature makes it even easier to do a one-time sign in to your account for a friend, if you don’t want them to be able to login to your account indefinitely.

          0: Netflix doesn’t support passkeys because their main audience is people signing in via smart TVs and whatnot, which largely don’t support CTAP or Webauthn in general)

          1. pixl97 · · focus · HN ↗
            >In general you shouldn’

            Me to said companies: I will do what I want.

            1. brendoelfrendo · · focus · HN ↗
              Said companies to you: sounds like what you want is to get booted from our service.
              1. pixl97 · · focus · HN ↗
                Me: Invents more new ways of being problematic for the company spreading the ideas to millions of others decreasing their profitability to almost nothing.

                Me to company: Damn, guess you shouldn't have been an asshole about it, kind of backfired on you.

                1. LevGoldstein · · focus · HN ↗
                  The responsible product owners will already have bounced 18 months prior after tweaking the stats to falsify the customer satisfaction rate and grabbing their bonus on the way out.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.