‹ BackHN Continuity

Thread

I don't like passkeys

853 points · 819 comments · ethanhawksley

  1. drtz · · focus · HN ↗
    Passkeys do marginally improve security against MITM and phishing attacks, but they are primarily for protecting the lowest common denominator from themselves: people who re-use passwords and/or don't use a password manager.

    If you use multiple devices throughout the day, registering passkeys in all of these systems becomes a big headache with O(m*n) complexity, so putting the passkeys in a password manager is the only realistic solution. But this still breaks the login flow for a very common use case: how do I log in on a device that I don't own? With a password in a password manager I at least have the option of manually typing the password.

    The biggest problem, though, is how users are pushed into it without any warning or knowledge of what they're signing up for. I've accidentally set up passkeys just by clicking an okay button a few times in the past and had to go back and figure out how to undo it after being blocked from login on another computer (which computer was I on again?).

    1. Latty · · focus · HN ↗
      The offer a strong protection against phishing attacks that would still get plenty of password manager users: fake websites. A passkey is strongly linked to a domain, so a fake site can't get that credential.

      Some password managers will only fill if a domain matches, but IRL the response I've seen from most users when it doesn't match is to assume the integration broke and manually copy/paste it in. I've also seen lots of them do stuff like happily autofill on any prefix of the domain, so your credential for `something.example.com` will autofill into `fake-something.example.com`.

      1. lapcat · · focus · HN ↗
        > Some password managers will only fill if a domain matches, but IRL the response I've seen from most users when it doesn't match is to assume the integration broke and manually copy/paste it in. I've also seen lots of them do stuff like happily autofill on any prefix of the domain, so your credential for `something.example.com` will autofill into `fake-something.example.com`.

        Why would you trust the very same password managers that don't handle passwords properly to handle passkeys properly?

        1. Latty · · focus · HN ↗
          You don't. The browser handles the passkey matching to the domain which is obviously a better place to do it. There could obviously still be bugs as with all things, but it's much more intentionally integrated into the flow which makes it much harder to bypass.
          1. lapcat · · focus · HN ↗
            > The browser handles the passkey matching to the domain which is obviously a better place to do it.

            I'm not sure why you're making a distinction. In many cases the browser is the password manager.

            1. Latty · · focus · HN ↗
              Right, I haven't seen that particular flaw in baked-into-the-browser ones (probably because they already having secure domain matching code ready to use), but the distinction is that doing the domain check is a part of the spec and standard, so e.g: sites aren't going to break it by changing the log-in subdomain routinely, as has been common historically.

              Password managers have had to be permissive enough to work with most websites, and there is no standard for it. There have been sites that blocked the autofilling of passwords and so on as well.

              My point wasn't this one particular flaw in some password managers is the reason to use passkeys (the copy/paste point is the much bigger issue anyway), just that it's an example of how relatively brittle the password manager process is. Having it a core part of the spec gives stronger guarantees.

              1. cruffle_duffle · · focus · HN ↗
                “There have been sites that blocked the autofilling of passwords and so on as well.”

                Sites that do this irritate me so much. Ones that try to block pasting and stuff… like somebody intentionally baked that into the site. Who? And what was their rationale? Are they really so arrogant to think people are going to carefully type in some elaborate password not once but twice?

                That and blocking paste in fields like bank account numbers and stuff.

                Surely somebody here has been asked to implement these mis-features. Please explain what went through the heads of the people responsible for it?

                1. pnw · · focus · HN ↗
                  Blocking bank account numbers from being pasted is considered an error prevention measure. By forcing people to enter it manually at least once, you stop them from blindly pasting the wrong number twice.

                  There's no real regulation requiring blocking paste but it has become an annoying informal standard of sorts.

                  1. kyleee · · focus · HN ↗
                    Thankfully brave’s right click menu has a force paste that works quite well
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.