Passkeys have a marketing problem where no one is able to describe simply what it is without having to use technical jargon. There's also the problem where each OS tries too hard in pushing this to the face of end-user
Imagine a password, but it a) types itself for you and b) detects when it's being sent to an impostor site and blocks them from seeing itself, so it can't be phished.
Cool, where are they stored? (I know the answer: 'it depends', and that's the big problem with their usability: most users haven't a clue what the answer is and most tech support can't answer that question straightforwardly because it depends on some decisions the user probably didn't even realise they made).
How do I use it on my desktop or laptop then? What if I switch browsers on my phone? What if I get a new phone? What if I change from android to iOS or visa versa? What if I need to log into the site on my Wii U's browser?
You can let Apple sync your passkeys between devices using iCloud Keychain. Then you can create a passkey on one device and have it available on all of your devices.
Nothing wrong with your answer itself, but having to be Apple or Google is a PITA. These account are ultra critical already and you will want maximum security to access them.
This means if you go on a trip somewhere you absolutely need two devices. If you kill your phone and want to buy another one ASAP, you wont be able to do anything with the new device until you can convince the platform it's you. With passkeys you're just SOL. Imagining if you needed a phone to get back from your trip - e.g. etickets, auth needed etc. - it becomes a nightmare scenario.
A third party manager makes it easier, but it's a lot less usable that the first party ones.
Reasonable people make different life choice, having to constantly think about backup strategies whenever I'm away from home would be so stress inducing to me.
I just don't use Google or Apple accounts for everything. I don't want my whole life in the hands of some big tech deciding how I should prove to them that I'm me.
I did use Microsoft 365 (business version) for my email but they also decided I should use their MFA app so I left.
kenrick95 · · focus · HN ↗
cfiggers · · focus · HN ↗
Tada, passkeys.
rcxdude · · focus · HN ↗
wolvoleo · · focus · HN ↗
malfist · · focus · HN ↗
Johnny555 · · focus · HN ↗
makeitdouble · · focus · HN ↗
This means if you go on a trip somewhere you absolutely need two devices. If you kill your phone and want to buy another one ASAP, you wont be able to do anything with the new device until you can convince the platform it's you. With passkeys you're just SOL. Imagining if you needed a phone to get back from your trip - e.g. etickets, auth needed etc. - it becomes a nightmare scenario.
A third party manager makes it easier, but it's a lot less usable that the first party ones.
Reasonable people make different life choice, having to constantly think about backup strategies whenever I'm away from home would be so stress inducing to me.
wolvoleo · · focus · HN ↗
I did use Microsoft 365 (business version) for my email but they also decided I should use their MFA app so I left.