Passkeys have a marketing problem where no one is able to describe simply what it is without having to use technical jargon. There's also the problem where each OS tries too hard in pushing this to the face of end-user
Imagine a password, but it a) types itself for you and b) detects when it's being sent to an impostor site and blocks them from seeing itself, so it can't be phished.
Cool, where are they stored? (I know the answer: 'it depends', and that's the big problem with their usability: most users haven't a clue what the answer is and most tech support can't answer that question straightforwardly because it depends on some decisions the user probably didn't even realise they made).
How do I use it on my desktop or laptop then? What if I switch browsers on my phone? What if I get a new phone? What if I change from android to iOS or visa versa? What if I need to log into the site on my Wii U's browser?
You can let Apple sync your passkeys between devices using iCloud Keychain. Then you can create a passkey on one device and have it available on all of your devices.
Nothing wrong with your answer itself, but having to be Apple or Google is a PITA. These account are ultra critical already and you will want maximum security to access them.
This means if you go on a trip somewhere you absolutely need two devices. If you kill your phone and want to buy another one ASAP, you wont be able to do anything with the new device until you can convince the platform it's you. With passkeys you're just SOL. Imagining if you needed a phone to get back from your trip - e.g. etickets, auth needed etc. - it becomes a nightmare scenario.
A third party manager makes it easier, but it's a lot less usable that the first party ones.
Reasonable people make different life choice, having to constantly think about backup strategies whenever I'm away from home would be so stress inducing to me.
No more so than if you lose access to the device that's required for Google/Apple MFA prompts, neither of which use SMS and depend on a proprietary approval flow.
If you lose your phone in 2026 while on a trip to Italy and try to enter your Gmail user/pass from your wallet, there's about a 100.00% chance you'll hit a "let's verify you're you" gate, that's been the case for 5+ years.
With passkeys I'm not stuck clicking Yes in the Gmail app or typing in the numbers on Apple hardware, I can skip the Apple/Google specific MFA nonsense and keep the passkeys in Bitwarden where they sync seamlessly between devices.
It feels truly liberating being able to skip MFA everywhere and login with 1 click, like a throwback to the golden age of using a password manager in 2010. Before passkeys it started to feel like I was spending 5% of my waking hours every day copying 6 digit codes from phone/email/TOTP after twiddling my thumbs for 15-30 seconds.
kenrick95 · · focus · HN ↗
cfiggers · · focus · HN ↗
Tada, passkeys.
rcxdude · · focus · HN ↗
wolvoleo · · focus · HN ↗
malfist · · focus · HN ↗
Johnny555 · · focus · HN ↗
makeitdouble · · focus · HN ↗
This means if you go on a trip somewhere you absolutely need two devices. If you kill your phone and want to buy another one ASAP, you wont be able to do anything with the new device until you can convince the platform it's you. With passkeys you're just SOL. Imagining if you needed a phone to get back from your trip - e.g. etickets, auth needed etc. - it becomes a nightmare scenario.
A third party manager makes it easier, but it's a lot less usable that the first party ones.
Reasonable people make different life choice, having to constantly think about backup strategies whenever I'm away from home would be so stress inducing to me.
qlte · · focus · HN ↗
If you lose your phone in 2026 while on a trip to Italy and try to enter your Gmail user/pass from your wallet, there's about a 100.00% chance you'll hit a "let's verify you're you" gate, that's been the case for 5+ years.
With passkeys I'm not stuck clicking Yes in the Gmail app or typing in the numbers on Apple hardware, I can skip the Apple/Google specific MFA nonsense and keep the passkeys in Bitwarden where they sync seamlessly between devices.
It feels truly liberating being able to skip MFA everywhere and login with 1 click, like a throwback to the golden age of using a password manager in 2010. Before passkeys it started to feel like I was spending 5% of my waking hours every day copying 6 digit codes from phone/email/TOTP after twiddling my thumbs for 15-30 seconds.