‹ BackHN Continuity

Thread

I don't like passkeys

853 points · 819 comments · ethanhawksley

  1. Liftyee · · focus · HN ↗
    YES. This exactly. I work across multiple devices, some of which are nonstandard/uncommon (Linux, Xiaomi China ROM, ...) and I've NEVER had passkeys work properly - yet everything constantly prompts me to add one. Even if they did work, I'd have to carry around hardware keys or register each computer separately. And the lack of backups if a device is lost/broken is definitely a larger concern for me than being phished of my TOTP keys.
    1. utopiah · · focus · HN ↗
      > lack of backups if a device is lost/broken

      Same as traditional physical keys, you don't have a single key, you have multiple ones precisely so that if you lose/break one, you are not stuck and can go to the local locksmith and get another one in minutes.

      In fact it's even nicer since you can just re-use the backup key with no security loss by revoking the other one, and buying another key.

      1. cpburns2009 · · focus · HN ↗
        It's not like physical keys at all. You can get copies made of those. Passkeys deliberately are not copyable.
        1. utopiah · · focus · HN ↗
          You don't copy the keys themselves, instead you make multiple relationships with different keys. You can get as many or as little keys as you want. The point is the keys themselves are not important.
          1. cpburns2009 · · focus · HN ↗
            The keys are vital, and if you lose them you're SoL. A major hurtle is that you cannot create multiple relationships with different keys. Each key can only be used once.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.