‹ BackHN Continuity

Thread

I don't like passkeys

853 points · 819 comments · ethanhawksley

  1. drtz · · focus · HN ↗
    Passkeys do marginally improve security against MITM and phishing attacks, but they are primarily for protecting the lowest common denominator from themselves: people who re-use passwords and/or don't use a password manager.

    If you use multiple devices throughout the day, registering passkeys in all of these systems becomes a big headache with O(m*n) complexity, so putting the passkeys in a password manager is the only realistic solution. But this still breaks the login flow for a very common use case: how do I log in on a device that I don't own? With a password in a password manager I at least have the option of manually typing the password.

    The biggest problem, though, is how users are pushed into it without any warning or knowledge of what they're signing up for. I've accidentally set up passkeys just by clicking an okay button a few times in the past and had to go back and figure out how to undo it after being blocked from login on another computer (which computer was I on again?).

    1. dspillett · · focus · HN ↗
      > The biggest problem, though, is how users are pushed into it without any warning or knowledge of what they're signing up for.

      My irritation is that I know what it is, and I've said no thanks many times, but I'm still asked regularly by the likes of Amazon, and they usually pick a time when I'm trying to order something quick¹. It is one of the growing number of things in life that simply have no “no” option, it is always “yes or later” - I wouldn't mind so much if “later” meant “I know the option exists, I'll ask for it if I change my mind, don't bother me again otherwise”. Call me cynical, but if companies are trying to nag me into something I very much doubt the main benefit is mine. I'm sure there are many people out there who go along with it simply because they are sick of being asked repeatedly.

      I also don't see the real benefit with the way things are often implemented anyway. When the credential recovery process is sending a magic email or text, making SMTP or SMS the weak link of the chain just as it often is for passwords so I'd be giving up my preferred workflows for no better security.

      ----

      [1] A short while ago I actually ordered from somewhere else because of this, bitter twit that I am. “I wonder if I can get this almost certainly drop-shipped item on next day delivery via Prime?”, [goes to Amazon to check], [get passkey prompt], “sod it, I'll go back to the original place”.

      1. sandeepkd · · focus · HN ↗
        I think this is the biggest reason why these category of discussion happens in the first place, there is a gap between what technology is good for, whats its ideal for and then the products motivation to push it on to the user assuming it would give a good name to the company.

        Passkeys are one of the few protocols that supports against phishing (Accidentally giving away your credential to some rough site) so it has its benefits and more so for enterprise users.

        It becomes challenging and is ill suited when its pushed to general public. A middle ground could have been to give it as an option to user instead of forcing it on the user. For some reason its not cool enough.

        From a company's perspective

          - Authentication is a friction and the discoverable credential (where you just click on username button and log in) reduces the friction for user, making it easier for user to make that purchase decision
        
          - Account take over attempts (ATOs) do take a dip, saves quite a lot of resources on customer support side for the company
        1. tyre · · focus · HN ↗
          IMO it’s well-suited to the general public!

          What is the average person’s threat model? Re-using passwords.

          What is their most common annoyance? They forget their passwords.

          Built-in password managers are great for this. But they’re not universal (e.g. I believe using Apple Passwords on Mac doesn’t carry over to Android.)

          Passkeys are amazing. They’re basically magic to the average person. No typing passwords; no remembering; simply vibing, securely.

          I don’t think people are regularly logging in to a huge number of accounts on other devices. Maybe they are! I doubt it.

          1. sandeepkd · · focus · HN ↗
            I guess it really depends on how one choses to define general public, probably an assumption has been made that everyone has their own personal device.

            > Built-in password managers are great for this. But they’re not universal (e.g. I believe using Apple Passwords on Mac doesn’t carry over to Android.

            1.Only security keys (single device credentials) are what you can use across the device not the regular platform based one

            2.Browser based password managers do provide you with that interoperability across the platforms and in fact the password manager as an supported passkey authenticator allows you do the same

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.