‹ BackHN Continuity

Thread

I don't like passkeys

853 points · 819 comments · ethanhawksley

  1. elteto · · focus · HN ↗
    While the technology itself may be great (I don't really know since I don't use them) it has been co-opted by the tech conglomerates as another form of isolating and walling off users into their ecosystems.

    And honestly, nowadays, if tech companies are pushing really hard for something then that is an immediate red flag for me and it bears more scrutiny. One of those "if you see them running that way you run the opposite way".

    1. mschuster91 · · focus · HN ↗
      > And honestly, nowadays, if tech companies are pushing really hard for something then that is an immediate red flag for me and it bears more scrutiny.

      The reason is the ever increasing number of hijacks of social media presences and code hosting portals, with the latter being a serious financial threat. Done right, passkeys stay in the Secure Enclave, at least for anything Apple and most of the Android sphere. There is no reasonable way to obtain login credentials for accounts protected by passkeys without physical access to the user's device(s).

      1. iso1631 · · focus · HN ↗
        > There is no reasonable way to obtain login credentials for accounts protected by passkeys without physical access to the user's device(s).

        Click "I lost my device", enter contact, get a reset link via email/sms

        1. terminalbraid · · focus · HN ↗
          Email and SMS are not reasonable and both have an extraordinary number of flaws.
          1. jmbwell · · focus · HN ↗
            So use the recovery codes. Or scan the QR code and auth from another device

            I’d buy that there are too many different confusing ways to recover from this situation, but not that it’s impossible

            1. Barbing · · focus · HN ↗
              >use the recovery codes.

              Fun fact: Google can decide to reject these. Lose access to the original device, try to rely on recovery codes to login with known current password on family member’s device… nope!

              1. hobo123 · · focus · HN ↗
                Wait, so I set up 2FA, printed the codes, but now if I ever lose my phone or it's stolen I'm screwed?
                1. Barbing · · focus · HN ↗
                  I guarantee you this is within the realm of possibility based on one single experience.

                  When you upgrade your phone perhaps keep your old one in a safe and charge it and login to Gmail monthly or something?

                  I’m also quite certain the codes could work instantly with no trouble in some circumstances. Now know it’s risky though. And I’m sure it’s a security measure based on real, deeply painful and costly instances of unauthorized access. Just don’t know what we’re exactly supposed to do…

                2. terminalbraid · · focus · HN ↗
                  Google gives you no guarantee of service for your account. They could arbitrarily decide to lock you out for any reason and you have literally no recourse.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.