drtz 16 minutes ago
If you use multiple devices throughout the day, registering passkeys in all of these systems becomes a big headache with O(m*n) complexity, so putting the passkeys in a password manager is the only realistic solution. But this still breaks the login flow for a very common use case: how do I log in on a device that I don't own? With a password in a password manager I at least have the option of manually typing the password.
The biggest problem, though, is how users are pushed into it without any warning or knowledge of what they're signing up for. I've accidentally set up passkeys just by clicking an okay button a few times in the past and had to go back and figure out how to undo it after being blocked from login on another computer (which computer was I on again?).
elteto 28 minutes ago
And honestly, nowadays, if tech companies are pushing really hard for something then that is an immediate red flag for me and it bears more scrutiny. One of those "if you see them running that way you run the opposite way".
brushfoot 10 minutes ago
That said, I don't like passkeys either.
kenrick95 30 minutes ago
elAhmo 10 minutes ago
Probably hundreds of millions or even billion people have devices that support biometric auth. How is that not mature?
F7F7F7 12 minutes ago
As someone who's OpSec puts swiss cheese to shame Passkey has been a godsend. My passwords are actually much better because of it.
Liftyee 22 minutes ago
BoppreH 23 minutes ago
I proposed an alternative scheme many years ago: https://www.researchgate.net/publication/343318317_Privacy-a... . By allowing "offline" keys you can also treat them as higher priority, and use them to revoke any lesser keys from attackers if your account is compromised.
It would also be nicer to get rid of usernames, but that's a fight against the data-gathering powers that we're unlikely to win.
xphos 15 minutes ago
blackdahlia313 12 minutes ago
If you think passkeys aren't ready yet, blame the people implementing it on their platforms.
xyzzy_plugh 24 minutes ago
But they also introduce single points of failure, as the article points out. I can't even remember how many times I've had to help a family member recover their account or get confused when they can't sign in on a new device. It's incredibly frustrating that this flow is promoted as the default for so many services.
1password is the best solution I've found for the average person. It's not perfect (it's definitely more complex than writing down your passwords on a piece of paper or using the same password everywhere) but it's much easier than juggling yubikeys. I know so many non-technical staff members who prefer the OS or browser keys even if it means another account recovery is lurking around the corner.
vanschelven 24 minutes ago
<<ducks>>
wg0 30 minutes ago
hahn-kev 17 minutes ago
kardianos 24 minutes ago
blfr 27 minutes ago
dxjxjdjsssb 22 minutes ago
I can't think of a single time I've had a passkey forced on me, but that nonsense sits at the core of every passkey related post.
micromacrofoot 24 minutes ago
Password managers are great IMO, I can use some absurdly long password, backup is reliable, I can use them across devices. For extra secure stuff 2FA works the same, I've got an app with codes I can easily back up and use from multiple devices.
Passkeys tend to obscure everything and take away a lot of control.
silon42 30 minutes ago
a2tech 33 minutes ago
junaru 30 minutes ago
It's entirely one sided solution.
etatester 22 minutes ago
I can see why they would be problematic for people who otherwise live life with a single love2025 password though.