Passkeys do marginally improve security against MITM and phishing attacks, but they are primarily for protecting the lowest common denominator from themselves: people who re-use passwords and/or don't use a password manager.
If you use multiple devices throughout the day, registering passkeys in all of these systems becomes a big headache with O(m*n) complexity, so putting the passkeys in a password manager is the only realistic solution. But this still breaks the login flow for a very common use case: how do I log in on a device that I don't own? With a password in a password manager I at least have the option of manually typing the password.
The biggest problem, though, is how users are pushed into it without any warning or knowledge of what they're signing up for. I've accidentally set up passkeys just by clicking an okay button a few times in the past and had to go back and figure out how to undo it after being blocked from login on another computer (which computer was I on again?).
> how do I log in on a device that I don't own?
This is solved by passkey-implementing software and devices (with Bluetooth) allowing you to log in with a QR code (Webauthn via CTAP hybrid transport). iOS and Android support this, and it’s generally not a locked-down thing if other devices wanted to do it too.
The only use case left is in “how do I login if all my devices are stolen/fall into a body of water” in which there really isn’t an answer beyond “get (a|your) device back, sign back into your password manager, use that to get back into critical accounts”.
The website should display a qr code you can scan with your phone that allows you to then login, unfortunately a lot of sites don't implement this, and some don't implement backup codes. This isn't the fault of passkeys per se, but of poor implementations.
If you're not happy connecting your phone to the network, then how likely is it that you would you be willing to enter your login details on a machine you don't control?
What if you just can't have internet on your phone? Like if the computer is connected via Ethernet and there's no wifi network you can connect to? What if you're abroad and have no roaming? And the ultimate question about a person that the modern world can barely conceptualize - what if you have a dumbphone? Or what if your smartphone is lost or stolen or dead and you need to access some account? That last one has happened to me, and I sure am glad I know the key passwords that I need for survival.
These may seem like nitpicks, but there's probably a thousand rare scenarios like these that exist. You inevitably have to consider them when you're moving from punching in letters and numbers that you remember in the normal, low-tech way to a complex networked two-device workflow.
What? Did you read the thread? I never said passkeys can only exist on phones. The whole conversation is about "how do I log on with passkeys if something happens to my trusted device?". The parent comments talked about just using your phone, I'm saying there's lots of situations where someone might not have access to either a phone or an internet connection for it. And when this happens, you really don't want to be left without a way to access all vital digital services.
> I'm saying there's lots of situations where someone might not have access to either a phone or an internet connection for it. And when this happens, you really don't want to be left without a way to access all vital digital services.
And when that happens I'm usually glad my credential is a passkey on my keyring, as chances are if I don't have my phone and I haven't auth'd on to some computer I almost certainly don't have access to my password vault. But hey, my passkey works just fine without my phone. And I can trust that once I unplug my authenticator and log out of that session, there's no long lasting credentials left behind. I don't get that with passwords.
Wouldn't I have the same problem with passwords? I would lose my phone and be unable to two factor log in to my Gmail account or bank from someone else's device?
With 2FA? Yes. 2FA is almost just as stupid and almost just as bad for regular users as passkeys are, but it got adopted due to historical loophole - by far the most popular form was TOTP delivered via SMS, then "authenticator" apps, both of which keep the code transferable - you can receive it on one device, transfer to yourself or someone else (which is a feature, not a bug) via any channel, and get it to work. Plus, SMS didn't allow for vendor lock-in, which is arguably why they're so hated in security circles (SIM-jacking is real, but doesn't scale anywhere near enough to warrant deprecating it as mechanism for regular users).
I have over 2,000 accounts. The majority of them have unique passwords. I can count the services that have passwords that I know on one hand, with quite a few spare fingers.
> Passkeys were created specifically to close that loophole.
Credential sharing? I have a family share with passwords and passkeys in it. Passkeys most certainly didn't stop this. They did add friction to having a user being duped to share their password to someone claiming to be tech support, since you can no longer request plaintext secrets be sent over arbitrary channels.
> Plus, SMS didn't allow for vendor lock-in, which is arguably why they're so hated in security circles (SIM-jacking is real, but doesn't scale anywhere near enough to warrant deprecating it as mechanism for regular users).
SMS is an ugly user experience and more importantly is expensive. Now a lot of services do emailed codes when they don't have a regulatory reason to require SMS - an even worse user experience, but less expensive.
We have authenticator apps which use a standard OATH setup, and quite a few platforms which have integrated support to try to sand over the worst part of the UX. Unfortunately they just didn't become popular, and OATH fails the same regulatory requirements that emailed codes fail.
No, it's fine. Most common example, I log in to my bank, they send an SMS, I copy the code and paste it into the web site. Works fine and I don't have to pick up my stupid phone, like I would if I used an authenticator app instead.
"and more importantly is expensive."
Not for me. The bank made several billion dollars last quarter, don't think it's a big problem for them, either.
Most common example, I log in to my bank, they say they sent an SMS, I sit there waiting to access my account, then 20 minutes later the SMS finally actually gets delivered after I've given up and left to do something else. Rinse/repeat.
Or another example, someone hijacks my SMS'es, and then they log in as me.
SMS sucks. SMS is insecure.
The amount of times I've experienced customers complaining about SMS 2FA not working well despite it being on their carrier failing to deliver the messages in a timely fashion really showed me how terrible it is.
Dunno what to tell you. Several possible points of failure there. Maybe your bank's system for sending SMS just sucks. Maybe you're in a place with poor mobile network coverage (which is a real problem for SMS 2FA, I agree, having lived in a place with nearly none for several years).
But for me, where I live now, with my bank, and my phone carrier, it works great. Never had a problem that I can think of. Typically, the SMS arrives within seconds. It's the least annoying and most reliable 2FA method I use.
I'm not that worried about potential security issues. Sure, it's a possible problem, but pretty low on the list of things to worry about.
The least annoying and most reliable form of 2FA I use is tapping the touch sensor, doing a biometric face unlock, or typing in my PIN on the device I currently have in my hands. Its miles less annoying and way more reliable.
Glad that works well for you. Does not work well for me. I do not care for laptops except when necessary and have come to loathe my phone. Everything important is done with desktop computers that do not have cameras or touch sensors, so biometrics can't work.
In general, I do not have a "device... currently have in my hands" and having to pick one up and unlock it is annoying.
"Good news then, this also works on desktops, even ones without cameras or touch sensors."
All of the 2FA methods forced on me by my employer and most online services that require it require a phone app. So no, it doesn't work on a desktop.
No, that's not the way it went. I joined the conversation, such as it is, to respond to the guy who said "SMS is an ugly user experience" to say no, it's fine.
I haven't shifted any goalposts: I've basically just reiterated to you that I think it's fine and better than the alternatives. Not a word about passkeys from me.
"SMS is an ugly user experience"...compared to passkeys.
It's not fine that SMS messages get delays. It's not fine that it requires a cell phone plan. It's not fine that it requires you to have cell service. Its not fine because it's insecure.
So many times I've had coworkers and clients frustrated they are pushed to letting their employer force SMS 2FA on their personal numbers. When they could just use passkeys these days baked into their work machines and not have those problems.
Settle down. I responded to the statement "SMS is an ugly user experience and more importantly is expensive" to point out that from my perspective, neither one of those things is true. The "user experience" is fine and to me, the cost is zero.
Then you decided, for some unknown reason, to jump in and... do something, but I'm not sure what. Seems like you're trying to convince me that my own view of my own experience is wrong somehow but — and one might think this would be obvious, but apparently not to you — that's not gonna work.
drtz · · focus · HN ↗
If you use multiple devices throughout the day, registering passkeys in all of these systems becomes a big headache with O(m*n) complexity, so putting the passkeys in a password manager is the only realistic solution. But this still breaks the login flow for a very common use case: how do I log in on a device that I don't own? With a password in a password manager I at least have the option of manually typing the password.
The biggest problem, though, is how users are pushed into it without any warning or knowledge of what they're signing up for. I've accidentally set up passkeys just by clicking an okay button a few times in the past and had to go back and figure out how to undo it after being blocked from login on another computer (which computer was I on again?).
judge2020 · · focus · HN ↗
This is solved by passkey-implementing software and devices (with Bluetooth) allowing you to log in with a QR code (Webauthn via CTAP hybrid transport). iOS and Android support this, and it’s generally not a locked-down thing if other devices wanted to do it too.
The only use case left is in “how do I login if all my devices are stolen/fall into a body of water” in which there really isn’t an answer beyond “get (a|your) device back, sign back into your password manager, use that to get back into critical accounts”.
201984 · · focus · HN ↗
limagnolia · · focus · HN ↗
201984 · · focus · HN ↗
roryirvine · · focus · HN ↗
tavavex · · focus · HN ↗
These may seem like nitpicks, but there's probably a thousand rare scenarios like these that exist. You inevitably have to consider them when you're moving from punching in letters and numbers that you remember in the normal, low-tech way to a complex networked two-device workflow.
vel0city · · focus · HN ↗
tavavex · · focus · HN ↗
vel0city · · focus · HN ↗
And when that happens I'm usually glad my credential is a passkey on my keyring, as chances are if I don't have my phone and I haven't auth'd on to some computer I almost certainly don't have access to my password vault. But hey, my passkey works just fine without my phone. And I can trust that once I unplug my authenticator and log out of that session, there's no long lasting credentials left behind. I don't get that with passwords.
Aren't passkeys great?
pixl97 · · focus · HN ↗
You get mugged.
They take your phone and keyring.
They can't do anything with it since it's locked, but you don't have it.
Aren't passkeys great?
staticman2 · · focus · HN ↗
TeMPOraL · · focus · HN ↗
With 2FA? Yes. 2FA is almost just as stupid and almost just as bad for regular users as passkeys are, but it got adopted due to historical loophole - by far the most popular form was TOTP delivered via SMS, then "authenticator" apps, both of which keep the code transferable - you can receive it on one device, transfer to yourself or someone else (which is a feature, not a bug) via any channel, and get it to work. Plus, SMS didn't allow for vendor lock-in, which is arguably why they're so hated in security circles (SIM-jacking is real, but doesn't scale anywhere near enough to warrant deprecating it as mechanism for regular users).
dwaite · · focus · HN ↗
> Passkeys were created specifically to close that loophole.
Credential sharing? I have a family share with passwords and passkeys in it. Passkeys most certainly didn't stop this. They did add friction to having a user being duped to share their password to someone claiming to be tech support, since you can no longer request plaintext secrets be sent over arbitrary channels.
> Plus, SMS didn't allow for vendor lock-in, which is arguably why they're so hated in security circles (SIM-jacking is real, but doesn't scale anywhere near enough to warrant deprecating it as mechanism for regular users).
SMS is an ugly user experience and more importantly is expensive. Now a lot of services do emailed codes when they don't have a regulatory reason to require SMS - an even worse user experience, but less expensive.
We have authenticator apps which use a standard OATH setup, and quite a few platforms which have integrated support to try to sand over the worst part of the UX. Unfortunately they just didn't become popular, and OATH fails the same regulatory requirements that emailed codes fail.
f30e3dfed1c9 · · focus · HN ↗
No, it's fine. Most common example, I log in to my bank, they send an SMS, I copy the code and paste it into the web site. Works fine and I don't have to pick up my stupid phone, like I would if I used an authenticator app instead.
"and more importantly is expensive."
Not for me. The bank made several billion dollars last quarter, don't think it's a big problem for them, either.
vel0city · · focus · HN ↗
Or another example, someone hijacks my SMS'es, and then they log in as me.
SMS sucks. SMS is insecure.
The amount of times I've experienced customers complaining about SMS 2FA not working well despite it being on their carrier failing to deliver the messages in a timely fashion really showed me how terrible it is.
f30e3dfed1c9 · · focus · HN ↗
But for me, where I live now, with my bank, and my phone carrier, it works great. Never had a problem that I can think of. Typically, the SMS arrives within seconds. It's the least annoying and most reliable 2FA method I use.
I'm not that worried about potential security issues. Sure, it's a possible problem, but pretty low on the list of things to worry about.
vel0city · · focus · HN ↗
f30e3dfed1c9 · · focus · HN ↗
In general, I do not have a "device... currently have in my hands" and having to pick one up and unlock it is annoying.
vel0city · · focus · HN ↗
Good news then, this also works on desktops, even ones without cameras or touch sensors. But sure, keep moving goalposts.
f30e3dfed1c9 · · focus · HN ↗
All of the 2FA methods forced on me by my employer and most online services that require it require a phone app. So no, it doesn't work on a desktop.
vel0city · · focus · HN ↗
Which, while I can't speak to your specific employer, tons are moving to support passkeys. Largely because forcing these apps suck and SMS sucks.
f30e3dfed1c9 · · focus · HN ↗
No, that's not the way it went. I joined the conversation, such as it is, to respond to the guy who said "SMS is an ugly user experience" to say no, it's fine.
I haven't shifted any goalposts: I've basically just reiterated to you that I think it's fine and better than the alternatives. Not a word about passkeys from me.
vel0city · · focus · HN ↗
It's not fine that SMS messages get delays. It's not fine that it requires a cell phone plan. It's not fine that it requires you to have cell service. Its not fine because it's insecure.
So many times I've had coworkers and clients frustrated they are pushed to letting their employer force SMS 2FA on their personal numbers. When they could just use passkeys these days baked into their work machines and not have those problems.
f30e3dfed1c9 · · focus · HN ↗
Then you decided, for some unknown reason, to jump in and... do something, but I'm not sure what. Seems like you're trying to convince me that my own view of my own experience is wrong somehow but — and one might think this would be obvious, but apparently not to you — that's not gonna work.