RU version is available. Content is displayed in original English for accuracy.
Advertisement
Advertisement
⚡ Community Insights
Discussion Sentiment
56% Positive
Analyzed from 13451 words in the discussion.
Trending Topics
#passkeys#password#passkey#don#device#passwords#account#google#manager#phone

Discussion (370 Comments)Read Original on HackerNews
If you use multiple devices throughout the day, registering passkeys in all of these systems becomes a big headache with O(m*n) complexity, so putting the passkeys in a password manager is the only realistic solution. But this still breaks the login flow for a very common use case: how do I log in on a device that I don't own? With a password in a password manager I at least have the option of manually typing the password.
The biggest problem, though, is how users are pushed into it without any warning or knowledge of what they're signing up for. I've accidentally set up passkeys just by clicking an okay button a few times in the past and had to go back and figure out how to undo it after being blocked from login on another computer (which computer was I on again?).
My irritation is that I know what it is, and I've said no thanks many times, but I'm still asked regularly by the likes of Amazon, and they usually pick a time when I'm trying to order something quick¹. It is one of the growing number of things in life that simply have no “no” option, it is always “yes or later” - I wouldn't mind so much if “later” meant “I know the option exists, I'll ask for it if I change my mind, don't bother me again otherwise”. Call me cynical, but if companies are trying to nag me into something I very much doubt the main benefit is mine. I'm sure there are many people out there who go along with it simply because they are sick of being asked repeatedly.
I also don't see the real benefit with the way things are often implemented anyway. When the credential recovery process is sending a magic email or text, making SMTP or SMS the weak link of the chain just as it often is for passwords so I'd be giving up my preferred workflows for no better security.
----
[1] A short while ago I actually ordered from somewhere else because of this, bitter twit that I am. “I wonder if I can get this almost certainly drop-shipped item on next day delivery via Prime?”, [goes to Amazon to check], [get passkey prompt], “sod it, I'll go back to the original place”.
The people responsible show a distinct lack of understanding when it comes to consent.
This is why you use hardware keys which work across devices like yubikeys and the like.
I have two of the old neos and two of the newer usb c + NFC enabled ones.
No issues.
He didn’t have access to it the other day and we needed access to his account. He didn’t remember his password, and we were unable to reset it because you need the passkey! No other options to authenticate for a reset were available.
Add in the fact that I was trying to help him with this by long distance call and you can imagine the frustration.
This is solved by passkey-implementing software and devices (with Bluetooth) allowing you to log in with a QR code (Webauthn via CTAP hybrid transport). iOS and Android support this, and it’s generally not a locked-down thing if other devices wanted to do it too.
The only use case left is in “how do I login if all my devices are stolen/fall into a body of water” in which there really isn’t an answer beyond “get (a|your) device back, sign back into your password manager, use that to get back into critical accounts”.
Ok but how do I share my Netflix or Spotify accounts for example with those?
However, passkeys can and are available to be shared via password managers. They’re not locked to the secure chip on the device where they live usually. iOS’ Passwords app has a share button and 1Password lets you share passkey-containing items.
In fact, the QR code login feature makes it even easier to do a one-time sign in to your account for a friend, if you don’t want them to be able to login to your account indefinitely.
0: Netflix doesn’t support passkeys because their main audience is people signing in via smart TVs and whatnot, which largely don’t support CTAP or Webauthn in general)
They're cheap enough if you lose one it's not the end of the world. Goes on your keyring. Doesn't require esim management. Use NFC swipe/usb-plug-in + pin to use.
This two fatal flaws are what limits their usefulness to enterprise SSO and perhaps some other limited uses where the organization has the ability to replace tokens. (Even in a distributed enterprise, enterprise SSO may not be a good fit for hardware tokens, if they can't get replacements out to employees fast enough).
I suspect that most people that ostensibly do this actually only enroll one for non-critical accounts and then depend on some fallback mechanism.
Sad reality is that such usecase is less and less common, thus, no one cares about it. I think majority of my friends would not be able to access their email, or facebook or alike, if they were forced to use my computer in emergency.
For instance YouTubers usually have a different account for their channel than the one they use privately, and don't want their channel account logged in everywhere.
That means having to log in as a guest when push comes to shove. And similar setups are common for most self-employed keeping a "work" account IMHO.
I've definitely done this, but not sure if the workflow was at the OS or browser level.
I'm honestly confused by all the negativity in the comments. Passkeys are great for convenience. Just leave your password login enabled as a backup. That defeats any security benefit, but oh well.
For people in this position, if they had their phone, they probably wouldn't be logging in on a computer anyway.
And many are moving to virtual wallets like Cashapp rather than banks with a physical presence where you can take out money without a phone.
It’s a bad situation.
Some password managers will only fill if a domain matches, but IRL the response I've seen from most users when it doesn't match is to assume the integration broke and manually copy/paste it in. I've also seen lots of them do stuff like happily autofill on any prefix of the domain, so your credential for `something.example.com` will autofill into `fake-something.example.com`.
Same thing is going to happen with passkeys for non-technical users for exactly the same reason you stated. People will think the integration is busted and manually copy/paste the non-passkey credentials in. In that way, I would argue that passkey is not stronger protection against phishing attacks unless its the only way to login. It is, at best, a convenience for users.
Why would you trust the very same password managers that don't handle passwords properly to handle passkeys properly?
The passkey integration goes the other way, which is much more reliable.
Gell-Mann amnesia effect
https://en.wikipedia.org/wiki/Michael_Crichton#%22Gell-Mann_...
I've seen people do this AFK as well, and I'm always helpfully suggesting them the correct way of solving this: verifying the URL again, and if correct, add it to the password manager so it remembers in the future, and never copy-paste passwords on the web. Basically 50/50 if they take the advice or come back after a week asking if it's safe to copy-paste the password into the website, and I try to inform again.
Shockingly, I saw one developer peer copy-pasting a password into a website, but I guess for these people there is no hope.
Historically I've seen lots of sites do a subdomain shuffle for login pages every now and then which routinely breaks domain matching, introducing false positives that users have to deal with, making them numb to the threat too. Passkeys baking in the domain check with no workaround means that sites can't do that, which is a benefit.
No doubt there exist services that do not offer recovery method for passkey or mfa enabled account. But this is entirely on them (the service), to blame for, not the passkeys or the users. It’s bad implementation.
Oh well.
You scan the qr code from your phone and it logs you in on that device. The experience is pretty amazing, honestly.
The tragedy of passkeys is that they're a step back from the security offered by the likes of Yubikeys.
But because passkeys are pushed by both Google, Microsoft and Apple: there is is simply no fighting these three. It is impossible.
Passkeys won not because they're better (they're not and the entire concept of "secret behind a hardware security module" that can be transferred to another system defeats the whole point of a HSM in the first place) but because the powers-that-be decided that passkeys are to be used.
It's still a win: the commoners are better served with passkeys.
But a secret in control of Google/Apple/Microsoft that can be backed up is not a secret I control: it's a complete step back from yubikeys.
Passkeys won and we better get used to them (and, yup, there are usability issues as you mentioned).
Amazon prompts me to create a passkey everytime I log in, even when I logged in with a passkey, because my passkeys live in Bitwarden rather than my OS or browser.
And the confusing mechanism hurts there too: I'm always a little bit afraid that i'm somehow more in danger because I keep them in a vault that's shared on all my devices rather than a TPM, because whenever the protocol is explained the "it can't leave your device" part is highlighted as the main source of the security, except.... mine obviously do leave my device, with the vault, so.....
Sites can request hardware-bound tokens, which would block any software based password managers. It's an option in the protocol but one not yet widely utilized.
It should not be in the protocol. And I don't trust Apple and Google not to lock it away from me.
I want my own open source manager and if that is attempted I want it to lie about it.
https://developer.android.com/privacy-and-security/security-...
I haaaaaate this. And every time I'm like, "do I not already have one??" Passkey implementation has been half-assed by everyone.
What setup are you using? Because I don't have that problem on Linux + Firefox at all
It's totally possible there's something specific about my situation, or the way it was set up in the first place that enables this, idk, but somebody else replied saying they have the same experience so it's not just me.
And even if it was just me, it's still clearly something wrong on the provider's implementation, because it should not be possible for software to sidetrack the user into a passkey enrollment flow, when that user logged in with a passkey to open the current session.
The option pops up in the middle of a normal log-in flow. I'm guessing most non-techies don't know how it's implemented.
Oddly, some login flows display a normal user/pwd form, but you get the in-browser "use a passkey?" option/popup which further confuses matters.
Thankfully, me, wife, and all our parents are tech-savvy enough to use password managers, so the fallout from lost passkeys hasn't be an issue. But I certainly see how it would be an issue for anybody entering passwords from memory or similar.
And honestly, nowadays, if tech companies are pushing really hard for something then that is an immediate red flag for me and it bears more scrutiny. One of those "if you see them running that way you run the opposite way".
The most flexible, independence preserving thing to do is to use a third party password manager like Bitwarden, and make that the default passkey flow for your devices. If desired, you can self-host something like Vaultwarden so that you can both keep the keys independent of third parties and walled gardens and also propagate them to other client devices.
To be clear I'd much rather not have learned / implemented any of this, and I don't use passkeys unless forced, but this seems like a valid coping strategy.
Passwords with 2FA are simply better and more freedom friendly.
The reason is the ever increasing number of hijacks of social media presences and code hosting portals, with the latter being a serious financial threat. Done right, passkeys stay in the Secure Enclave, at least for anything Apple and most of the Android sphere. There is no reasonable way to obtain login credentials for accounts protected by passkeys without physical access to the user's device(s).
Passkeys could be the savior of all security problems worldwide from a capability point of view and tech companies would still ruin it by trying to force ways it pushes you into their ecosystem instead of just being whats both secure and convenient.
As an example, I have 3 different passkey _APPS_ on my phone and cannot go down to one because of various reasons with each (such as MS authenticator, forced for integrating to Microsoft at work).
Click "I lost my device", enter contact, get a reset link via email/sms
Passkeys have been a massive quality-of-life improvement. Yes, there's the minimal risk of lockout if you lose access to the passkey (though almost every site I've used that implements pk's lays it on top of their traditional user/pass auth flow), but generally speaking most people use iCloud or their Google account to store their passkeys, and because those sync everywhere, this isn't a real risk.
I love not needing to deal with 1Password's autofill being flakey and having to CMD-C/CMD-V passwords/passphrases/OTPs on these sites.
I like Yubikeys as well but they are super inconvenient by comparison when dealing with multiple devices. Setting them up is also very user-unfriendly in general; doubly so compared to passkeys.
Now, what I'd REALLY F'IN LOVE to see go away is the passwordless/magic link auth flow wherein you authenticate by clicking a magic link that gets sent to your email or text message inbox.
"Emails are super easy to hack and we're still not sure whether text messages are safe to send on US carriers, so let's have everyone click on a link sent by email or text so that they don't have to deal with those pesky passwords that iOS or Android will automatically suggest for them." Like, what?
This seems really naive? That's the only flow that's at the basis if you get locked out. What else, do you put people on the phone to verify people by asking their name and date of birth? That's even worse!
Source? And if somebody hacks my Gmail account, won't they be able to access my Google-synced passkeys?
Magic link auth isn't any less secure than any site that has a password-reset flow.
And unfortunately is something I start to see to family members/friends that are not tech experts when they ask me to setup them up a new phone... at least the passwords they would have written them in some notebook that they had at home, or always used the same for everything, but with passkey... and when you tell them that they lost access to their email, possibly the files backed up to Google Drive/Google Photos, etc they are surely not happy.
Also passkeys makes it difficult to get access to your account in an emergency scenario, what if I loose my phone and I'm not signed in to other devices? Maybe I've setup an SMS as a recovery method, but first I have to get to my phone company to request another SIM card, maybe I'm on vacation on the other side of the earth in vacation for 2 weeks, I'm locked out of my Google account, and from all accounts that uses the passkey as a sign-in method (including, for example, the account that I need to use to check in on my return flight, or my banking app that I need to pay stuff!)
Exactly, if you lose your passkey you just sign in with your password like you did previously. I'm yet to find an app/website that has passkeys only and no passwords.
Seems like a total non-issue to me.
If you can still be phished, remind me what the point of any of this was, again?
So no password login, but then you can recover your account by adding an additional passkey by receiving an email.
Do they sync between Android and iPhone devices?
I use 1Password, but passkeys have made things even easier. I'd rather have them than any 2FA method. So many websites make me use a login/password AND then send me an email or text with a code. Every. Single. Time. You're really telling me you would rather do that than have a passkey?!
And, like you said, passwordless email auth is really terrible.
I'm glad to see this view becoming more mainstream. Passkeys are grotesquely insecure.
The only possible way to consider them more secure is if phishing attacks were more common and more damaging than lockout, which is so implausible that I reject the idea that someone could take that position in good faith.
Lockout is a real risk, but there is nothing insecure about passkeys. Private keys stored on the secure enclave + biometrics or passcode before any signature is produced + origin binding mogs a static string and a 6-digit TOTP (often generated with a secret key outside the secure enclave) that can be phished and entered from anywhere. Also, in many (possibly the majority) of scenarios where someone is locked out of their passkeys, they’d also be locked out of TOTPs and passwords.
> The only possible way to consider them more secure is if phishing attacks were more common and more damaging than lockout
You’d be surprised.
This statement is internally contradictory.
Perhaps I missed something or perhaps it really is that user hostile. It wouldn’t surprise me in the slightest.
My annoyance with the prompts is not evenly spread over the sites I use, it just so happens the same sites that think short login periods = security (it does not) are also the same sites that think passkeys are the best thing since sliced bread.
I have such a low opinion of any company that logs me out every time I turn around and those are the same disrespectful companies that think it's appropriate to spam me with passkey requests when I login. My dislike also extends to those companies they have a "Remember me" or "Remember this choice" checkbox that is decorative, as in it doesn't do anything. Often paired with clicking external links in things like a banking website "Warning: You are leaving this site!", yeah, I know how the internet works, I don't need to be babied by a completely ineffectual dialog (if you think normies are reading that and not just clicking through, you are living in a fantasy world).
Same as traditional physical keys, you don't have a single key, you have multiple ones precisely so that if you lose/break one, you are not stuck and can go to the local locksmith and get another one in minutes.
In fact it's even nicer since you can just re-use the backup key with no security loss by revoking the other one, and buying another key.
I have multiple identical ones.
> [...] and can go to the local locksmith and get another one in minutes.
Can I go to the digital equivalent of a locksmith (like a backup software) and duplicate my passkey? Can I do that with only my passkey in hand (without having to do anything to the corresponding lock, or having to contact its issuer), like I recently did with a physical key?
In fact if you have the technical skills to make your own physical key and respect standards, e.g U2F, you don't even need to buy one and it will work with existing devices and services. I can recommend the Precursor for an interesting exploration of that from a verifiable software/hardware perspective.
(At least til I get around to setting up my new usb c yubikeys!)
<<ducks>>
But for regular end users where services are primarily motivated to take money from those users and lock them into their ecosystems, they are a usability disaster and yet another exploitation vector.
It's one solution for two very different usecases, and it just does not work. There is an approach that could work for end users who own their own accounts, but they need to go back to the drawing board and rewrite the protocol with the assumption that the keystore is hostile to the user's interests. That means strong guarantees on key portability so users can migrate away from hostile keystores, and absolutely no ability for services to restrict the user's choice in passkey provider software.
it's all backwards, I agree, even worse that we trust "sync to the cloud" but don't allow users to own their credentials.
My bigger problem with passkeys is how there's no universal way to register more than one device (in case the first one is lost).
Proton Pass is a specific way to do that, but not a universal way. Bitwarden can't use proton pass to move keys around, google can't, firefox can't.
Tada, passkeys.
To your point, I for example would add point c) - Is linked to the device you are using currently. If you want to use another device to log in you are in a world of complexity and pain.
Are you part of the 99.99999% users of one of iOS+Apple or Androidlike+Google/Tencent or HarmonyOS+Huawei? If that's the case, you don't need to as the key is automagically saved by your OS' platform and synced with your new device.
Otherwise, you're such an extreme outlier that you probably either know what you're doing or can find out by yourself, right?
Ironically on macOS we used to have an app called Keychain which unfortunately was effectively renamed to Passwords for non-technical users.
Unlike physical objects they may reside in a TPM, a software vault, an export/backup, or any combination thereof. You may or may not be able to recover or migrate them, depending on where/how they were made.
Therefore you may need multiple per service, or maybe not. Services which only allow one may end up locking you out with no recourse. You get to find out.
None of this is obvious or self explanatory to normies.
As for normies, passkeys or passwords it doesn't make a difference. Either you have people who use love1969 everywhere or those who constantly lose their passwords.
All passkeys accounts for normies require an email or phone number, which is what you can use to recover a password or passkey exactly the same way.
Passkeys really are not any more difficult to explain than 2-factor authentication. Anyone who’s currently been able to actually create an Apple or Google account and successfully navigate their devices up to a passkey screen will be able to grok how it works.
People around here really ought to stop thinking users are complete idiots. Hell, you don’t even to scroll that far to read people calling users “normies” for crying out loud. What is this? High school?
I always operated under the assumption that the passwords app was just a more casual view into the keychain
Maybe that's a bad assumption
That's a pain point in everyone's day that should make the benefit easy to understand.
Logging into a site with your device is like putting your card into the terminal. The site can ask for a password the way the terminal asks for a PIN, but if your device supports Passkeys, that’s like your card having a chip, and it’ll use that instead.
So think of Passkeys like using a chip card.
I dunno how well this analogy works down to the last detail but it has gotten it across to all the parents I’ve used it with
Sure, its explained. But not in a satisfactory way that would reach all users at their level.
This is a bit of an exaggeration and out of proportion, but I think my ideal would be one of the big tech companies should have bought out something like a super bowl ad. Something that actually conveys the idea "hey, we know you've used passwords since you were able to type on a keyboard, but here's new technology that's better and here's why" in plain language that the average person can understand.
Unfortunately, XKCD 2501 continues to be relevant. [1]
[1] https://xkcd.com/2501/
If it's that unclear to me, I can't imagine how it can be to the average user.
The way they explain them is atrociously unclear, borderline negligent for services that nag people to activate it for accounts where they may hold valuable data for their personal lives. And while I don't want to spend much time finding out the details as long as I have the option to decline them, I suppose if they can't explain it and convince people of its advantages, it's because it's just bad tech.
I'm with you 100%.
There will be evil and stupid uses.
The brain-damaged people who think disabling paste on password fields is a security feature will be all over forcing device-attested passkeys as soon as they learn about it.
Evil people will see it as a proxy attestation of humanity.
Either way it will be rammed down our throats if passkeys are widely adopted.
Let's add to that: What if you're on holiday and your phone gets stolen or is suddenly 20 meters under water because it fell off the boat?
What if you are a normal person who only has a phone and it simply dies for one reason or another?
You get a new phone then hire the boat again, go above where your phone fell in and hope it syncs your passkeys?
You either should treat your passkeys with a backup like any data, this can mean multiple hardware keys or a cloud backup of your passkey, like bitwarden or the provider's native backups.
The idea of multiple hardware keys, which have to be enrolled individually to every site, is just not an ordinary end-user friendly activity.
So passkeys may be great for technical users (who are happy doing that) or corporate users (where centralized IT systems can be put in place) but not for standard non-corp users (which realistically, is most people)
Not talking about you. After all passkeys are not there to protect people who have home labs and don't recycle passwords anyway? They're for normal people who only have one device.
> who are happy doing that
You think they're happy? I'd say they grudgingly comply at best.
Suppose you do want a secure solution for the main sites your stuff is on. But every piece of shit content mill also wants to set up a passkey.
Then on top of that there's a whole 2nd factor layer which _also_ typically involves a touchid press but for a totally different reason (as the 2nd factor, not to unlock the password safe storing my passkey.
It's just an ugly inconsistent dance, dozens of times a day.
I know these gripes are mostly about implementation, and partially about user-facing software, and partially about user choices, but it doesn't make it any less ugly for the user.
With the app you use to store those keys (a password/key manager) it's the same - you simply wouldn't have an autofill working. Sure, people can and will circumvent this for the benefits of the scammers, just like they can circumvent passkeys using non-passkey login option, indeed:
> weakest recovery method: SMS
> If a site suffers a data breach, passkeys are asymmetric and cannot be recovered from the server-side details.
Similarly, don't other modern password storage methods have the same property?
> lacks the decades of UX polish towards password autofill.
A lot of years in those "decades" have been wasted polish-wise: you still can't log in with a single button, e.g., many popular sites only fill a username first, then require an extra dealy and action before accepting a password
Sure they work fine on a technical level, but they're frustrating and confusing for the vast majority of people I know.
I worry I am going to get locked out of my Google account, muggles don't. Doesn't stop them from getting locked out.
Apple has a vision where you have an iPhone and a mac at home and a mac at work and a vision pro and an Apple TV and all of that and your passcodes "just work". Doesn't work for the "rest of us", like we're already used to AirPods punishing us for using Windows.
If it works without any issues, great.
But if you ever run into one of the 50 messed up situations, good luck.
I actually prefer non-resident U2F in some ways. You don't have to store anything on your key, you are just signing requests. This is relevant where U2F/FIDO keys have limited slots for 'resident' keys.
In principle, it's great. You have one good password to remember for the average user, and that's enforced by their device's probably good enough security posture.
They are resistant to being phished and they won't reuse the same one everywhere. They then don't end up going from hunter2 to hunter2! everywhere.
But my experience for users is that they worry they are giving their biometrics to Amazon or whoever and so the UX just confuses them.
The certification aspect was new to me too last time passkeys came up. Sites can require that a given passkey has been certified.
The patchy support for them is also frustrating. MacOS does not support NFC FIDO/U2F. iOS does.
And yet you love passkeys? How much will you love them when you're locked out of something you can't do without?
No grandma, don’t use the unphishable one-click passkey setup that syncs across all your devices. Instead, install a third-party password manager (no, no, not the one built in to your device or browser), then another TOTP app on your phone. It’s slower and more susceptible to phishing, but uhhh, what if you’re among the one in a million people that has their Google or Apple account wrongly banned?
At some layer you have be able to access your services with password/totp if only for recovery. Passkeys add a layer for minimum benefit, in my opinion.
Yes, push based totp and passkeys are more phish proof but for non techies, managing them is its own job.
But they also introduce single points of failure, as the article points out. I can't even remember how many times I've had to help a family member recover their account or get confused when they can't sign in on a new device. It's incredibly frustrating that this flow is promoted as the default for so many services.
1password is the best solution I've found for the average person. It's not perfect (it's definitely more complex than writing down your passwords on a piece of paper or using the same password everywhere) but it's much easier than juggling yubikeys. I know so many non-technical staff members who prefer the OS or browser keys even if it means another account recovery is lurking around the corner.
This is, in my opinion, the most serious problem with passkeys. I'd like to adopt them, but this is a blocker.
The same is true for passwords with a password manager.
> If a site suffers a data breach, passkeys are asymmetric and cannot be recovered from the server-side details.
Also not really a problem with randomly generated site-specific passwords in a password manager.
Really all the browser vendors had to do was add an API to make automatically generate a password that is then stored in the user's password manager the low friction option.
I proposed an alternative scheme many years ago: https://www.researchgate.net/publication/343318317_Privacy-a... . By allowing "offline" keys you can also treat them as higher priority, and use them to revoke any lesser keys from attackers if your account is compromised.
It would also be nicer to get rid of usernames, but that's a fight against the data-gathering powers that we're unlikely to win.
It should always have remained a second factor device. It’s not impossible to teach people to use these, European banking did it for years. There’s just no will to do it.
Under this scenario, the first factor can be a short password or even a PIN.
I have physical passkeys, one attached to my keys and another on my desk at home and I absolutely hate software based passkeys. Every single time I'm asked for a passkey it always ask me if I want to use my Apple Keychain first and I wish I could default to physical.
Passkeys just make it harder/riskier.
there's some issues with passkeys, but not being able to memorize them is a feature
same ux, different security properties.
>Except that at least I can memorize a password by heart just in case.
"just in case" should be a thought out recovery flow, rather than hoping that you remember the password of the account you need to access.
For the average user, which doesn’t use a password manager, this is great. It means they can’t get phished. And it’s also great for the average password manager user, who keeps dozens of insecure and reused passwords in their vault because they manually thought of a password when signing up instead of randomly generating one.
If you’re already using a password manager and random passwords, the UX is designed to be the same. It’s just a way to get regular people to do this.
Windows still required entering a local PIN, sometimes 2-3 times. I think the account recovery didn't scale, though haven't really tested/explored with any real users :)
Anyway, companies should be educating users more on passkeys, how they work and where they get stored.
I also don’t love how many websites and apps use them in stupid ways like using them alongside other 2FA or login methods when the passkey alone should be sufficient.
My gripe with passkeys is they are almost always implemented without a second factor.
You’ve mentioned the rare case of 2FA with a passkey as being a bad thing, but in my opinion those few cases are actually doing it RIGHT.
With passwords and 2FA, if someone manages to copy your primary authenticator (password) they will still be locked out because they don’t have your secondary authenticator. This protects you against malware that steals your password database.
But the way most companies implement passkeys (single auth), if someone steals your passkey database they can use it immediately. For all of the true measurable benefits that passkeys bring (not memorizable, higher entropy, automatic storage and use in a database) they are almost always used in a way that has this huge drawback: no 2FA.
This is not an issue with passkeys directly, it’s an issue with how services implement passkeys.
My Yubikey supports passkeys and protects them with a PIN of my choosing. No services need challenge me further.
I must say it's pretty amazing how well-integrated is Bitwarden with iOS now, passkeys, password generation, everything. I have disabled Apple passwords manager, and Bitwarden feels like the native solution.
In fact, I think it's technically possible. But it's true, as of today I don't think anybody supports it.
I was experimenting on solokeys with ios, in principle we could backup Passwords (the ios/mac app) into a solo key, space permitting, including passkeys, regular passwords and totp (not wifi passwords). I believe the same is for Android, but haven't tested yet. This is all experiments I've been doing on my own, there's nothing ready to be released.
0 intermediary yet proper and convenient authentication. If that friend ate the key (which he didn't) I'd just use my backup key, a cheaper non biometric one.
I think it's not more popular because people don't care enough about security to buy actual keys, rely instead of 3rd parties that they don't actually trust, e.g. Microsoft, Google, etc then... complain it's not good enough.
> Phishing through the standard login flow is eliminated by passkeys, but it creates a false sense of security. An account’s security is still dictated by the weakest recovery method: SMS, email links, security questions, and so on.
Passkeys are too strong and may cause account loss.
Passkeys are too weak and can be bypassed by account recovery.
Turns out, given the variety in the ecosystem, both these things are true depending on where you look.
It most definitely isn't. Any 2nd factor that is not the device I am currently using (either a yubikey or my phone) has a non-zero chance of not being near me when I need it, leading to the constant question of "where the fuck did I put that darn thing", only to find out that the cat has decided to believe the yubikey is a mouse and tried to devour it, the phone's battery went dead...
Very odd. I use passkeys extensively with BitWarden and I love it to the point where it's my preferred way of securing things at this point.
The fact that the website presents the question to BitWarden in a structured way (what website, what username) means that I never fight with selecting the right account to get the password for (because I commonly have multiple accounts for a single site) and it generally makes the login flow much smoother.
Environment is MacOS with Brave/Firefox + iOS.
It wanted me to log in for some reason even though it had worked fine for months. Login uses my Google log in.
When I try that, Google asks me for a hardware key to complete the login, even though it's my phone and I'm already logged in.
Eventually I figured out that if you select "log in using another device" and then click cancel when it brings up the qr code, you can select a push notification on "another device", which actually pops up on the same device. Do that once and it fails. Do it a second time and it succeeds.
All to use the tailscale app on my own phone.
GitHub breaks with this, PayPal breaks with this...
As a service provider myself, I've evaluated and said "Nah" to passkeys - because it's simply increased Customer Service contacts I have to invest in, whenever a user changes or loses devices, or any of the hundreds of ways Passkeys are not portable.
And guess what, the Tech companies pushing this have zero liability for user login support or security breaches. It's always me. There is no need for me to work hard and spend CS contacts, to wall off my users to the OS or Browser vendor.
I'll simply do passwordless Email or SMS 2FA / Magic Links and own my users without the overhead of Customer contacts, thank you.
Why you missed the last line of my answer? How did you get an impression to go back to broken passwords?
As someone who's OpSec puts swiss cheese to shame Passkey has been a godsend. My passwords are actually much better because of it.
That said, I don't like passkeys either.
They didn't want to cooperate, and they wanted to make passkeys transferable within you cloud account, while not cooperating with anyone or anything else. The result was that you have no predictable and stable pattern/protocol/interface, or even general description, for how, for instance, a website connects to the passkey or even a hardware key, if you wanted it.
We basically have all the browsers, the operating systems, and the password managers, all fighting over who gets to store and present the passkey. And everybody assumes that they are the only one that exists and actively tries to fight the others is they can.
The basic technology is really good and could work well, but the large asshole tech firms focused on self-interest and walled gardens and made it insufferable.
If the browser supports them and stores them securely you're safe as houses even after a breach.
If you use an untrusted machine, you either revert to the least secure backup method (your master password in Bitwarden) or don't log in.
If your phone is your trusted device and becomes lost/stolen and then replaced, you revert to the least secure backup method e.g. password, security questions, or even waiting to be manually verified. This can be problematic if your online bank requires 2FA so you can purchase the replacement phone.
The QR + Bluetooth thing sounds dumb as hell.
Kiwi Browser doesn't support passkeys even with Bitwarden on my device. I have to choose between an inferior (for my needs) browser or passkeys.
-----
Rather than passkeys, which always rely on a trusted device, my preference is, "I use a password manager and site-specific generated passwords, and when I try to log in with only a password on your site, send me an email (whether pass or fail), plus never require 2FA"
It's unlikely I'll lose access to email notifications at the same time someone tries logging in with a phished password (except, obviously, my email password, which should only be changeable with 2FA) unless I am specifically physically targeted or astonishingly unlucky.
If someone uses a fake website or other MITM method to grab my credentials, I'll be fine because I'll get the "hey PennRobotics you logged in to crabcakes.com just now from a iPhone" and immediately triage that unexpected situation.
If I need to log in to a website in private mode or on a different device, it takes an extra 30 seconds to log in to my password manager.
-----
The passkey problem? You need some hardware or else it's glorified 2FA, and as soon as you lose EITHER the hardware or the "what you are/what you have" part of 2FA you enter a world of trouble.
As many USB-security keys can be used passkeys.
You don't need a phone to do 2FA :
https://github.com/pcarrier/gauth
My company has already responded to multiple breaches where this has been what quickly follows an initial intrusion.
On any site where I create them the login experience gets worse. Sometimes I get a QR code to scan (terrible, almost never works too). Sometimes I am offered to login with passkey which I have and it doesn’t work. Almost always I need to fallback to password and it just sucks.
I hate passkeys. I wish there was a checkbox somewhere to tell all websites that I never want to use them.
1Password everywhere, on iOS, Mac, and Windows. I’ve run into none of the issues elsewhere in the comments. Everything just works, including in-app logins.
Maybe your other password managers are just bad at implementing the right browser/OS hooks?
Probably hundreds of millions or even billion people have devices that support biometric auth. How is that not mature?
Brilliant security: a highly secure high-tech shiny front door that can randomly fail to open, so you still need the low-tech back door, which is the one potential thieves will use.
Mind you, it can work if the back door is old but sturdy (basically, for a bank that will ask for KYC authentication, or in the worst case you can set foot in the brick-and-mortar branch showing your face and ID and ask for access) but for pretty much every other service it introduces risks for very little or no gain.
<sarcasm>On the plus side, this way passkeys can also be tied to age/identity verification.</sarcasm>
People have replied it's possible to extract the private key, but it's not clear to me that that's usable (maybe it is I don't know). It's certainly not in line with what passkey devs want people to do and not do, so I'm not interested in "fighting" against the "flow" so to speak.
I'm happy with TOTP, as I can manage and use the codes where I want, under my control.
(Or since syncing passkeys usually works within ecosystems, you might just need a passkey per OS.)
Password managers are great IMO, I can use some absurdly long password, backup is reliable, I can use them across devices. For extra secure stuff 2FA works the same, I've got an app with codes I can easily back up and use from multiple devices.
Passkeys tend to obscure everything and take away a lot of control.
Ideally optionally followed by a 2FA (naturally, via text, delivered straight to my Mac, even further diluting the questionable security of the whole exercise) and naturally, to be repeated every 2 days or so, since "stay logged in" is the biggest lie after "I've read and accepted the ToS".
Your phone (which is probably what, 80% of relevant traffic these days?) likely has a perfectly fine password manager built in. This "sign in via email" trend must be every scammer and phishers biggest dream come true...
I am looking at a new project that uses magic links sent by texts. I have been there and done that with authentication systems and that's good enough for a low stakes ludic activity.
The purpose of rotating passwords is to cycle out potentially compromised ones, due to phishing attacks, keyloggers, shoulder snoops, etc. But those cannot exist with a passkey.
What kind of compromise are we talking about? Was the device stolen? Then yeah, you need to rotate passkeys (and all your passwords, and remotely cancel all your live sessions, none of which is new).
Was the device hacked from afar and the data read off of it? The passkey is probably fine. You can rotate it if you want to, it's not a bad idea, I probably would to be certain, but you're not pwnd even if a bad guy got a shell for a while, heck even if they got a root shell.
I understood the question to be "should passkeys be rotated regularly" to which the answer is probably no because there's not really a compromise mechanism that periodic rotation defends against as far as I know.
Rotation defends against secrets that leak through normal use and without your knowledge, like a password entered into a phishing page or snooped over your shoulder or cracked from a breached hash. Passkeys aren't vulnerable to those things because they never travel over a network, are never seen by the server, are never seen by their own users.
You change the locks on your house when a key goes missing, or is known to be in the hands of somebody you don't want getting in, it's not something you do every three months just in case. Same with passkeys.
I don't know who designed this or who thinks these are acceptable affordances, but it seem to be part of the same disingenuous push that's behind passkeys in general.
Like, seriously?
Microsoft is especially poorly prepared for this - Often if you have a passkey, it will CONTINUE To ask you to create a passkey (a new and different one), and it may save it in a different place, which is infuriating.
Strong password + MFA is the way, and I don't see that changing.
If you think passkeys aren't ready yet, blame the people implementing it on their platforms.
Of course, at the rate we see security failures everywhere, I'm not entirely convinced writing your passwords on post-it notes wasn't such a bad idea after all.
Passkeys work nicely, and I'll use them, in cases where I want decent security, but I don't consider them the "Philosopher's Stone" of regular end-user security. I think they are still a bit too "fiddly" for your average Joe[line].
It's entirely one sided solution.
Like, no company should be storing anything but a salted hash of their users' passwords.
But, hey, here is the new startup idea for you: make passkeys great!
so much better than fumbling around with a password managers
The author's assertion that the greatest risk to an individual is account lockout versus phishing or password harvesting is just not grounded in reality. I get phishing emails and SMSs daily. The criminal ecosystem running these campaigns is extremely active already and set to become even more so with LLMs. These campaigns are by far the biggest threat to normies.
Whereas account lockout happens most often with multiple failed password entries, which passkeys completely eliminate. I just don't know where this risk evaluation comes from.
The author also points out that even with passkeys, if you're able to also log in with e.g. security questions, you still have a much weaker security footprint for that account. This is true, but it's also true of a TOTP second factor. So I'm not sure what the criticism is here.
The exportability argument is a real weakness and something I'd like to see addressed. Passkeys don't have an equivalent for backup TOTP codes that you can just write down somewhere or trivially store yourself. But it probably wasn't in v1 because the people who designed passkeys figured that websites would not go all in on them immediately and would preserve other authentication methods, which is exactly what's happened.
Attestation already destroyed user freedom in mobile app ecosystem. You can't just implement your version of some mobile banking app or whatever just by using original app's API, because dark overlords of gated app comunities allowed app authors to prevent this on OS level by giving them attestation tools.
And why do the OSes push for this so hard? Because the goal of the execs is lock-in and control. And their lackeys here on HN who implement this stuff and their families are the 1% who are all-in on one ecosystem so they arrogantly believe "this all works great and the masses are just too stupid to get it".
1. Write it down on a piece of paper and put it in a safe deposit box.
2. Read it on one device (or from a piece of paper!) and enter it manually on another device.
Plain text is the ultimate form of cross-platform portability. Passkeys are the ultimate form of vendor lockdown. The passkey vendors won't even allow you to view the private key, unlike with ssh keys, which you can also write down on a piece of paper. It's vendor cabal to destroy computing freedom in the name of "security", always the excuse. Tech company paternalism at its worst.
If passkeys were meant to be user friendly then there'd be a secure optical transfer mode to QR code them from device to device with the screen and camera.
Easy to implement (receiver flashes a public key, sender encrypts to that key and flashes the QR code back).
That it doesn't exist for a protocol meant to work with phones tells you exactly where the thinking was headed.
They provide crappy usability, they're expensive, they're easy to lose, you can't use the physical keys when doing remote desktop access.
My job requires me to use them. I use only for the job and nothing else. For sites requiring 2FA, I use TOTP (time-based one time passwords) from KeePassXC.
Website problems:
* First big problem: you try to kludge them as an "add-on" to a password or SMS "2fa". Just rip the band aide off and let people go 100% passkey by default. It's actually really easy for users. We do a push at the end of their onboarding flow and have a 95% conversion. Users love it and its seamless.
* Don't make people enter a username. Just have a "login with passkey" button first, and thats it. If the HIPPO in your organizations insists a username-password still be available, make the user navigate to a secondary page first to do so. Make the passkey the first-class citizen.
Password Manager problems:
* Google, Apple, Microsoft are trying to lock people in to proprietary password managers. Microsoft's password manager, plus their "microsoft account" experience is a steaming pile of shit. The key here would be portability. An export format exists for the public key (thats how enrollment works): It's a but of digits in ANSI X9.62 format. Not hard. The private key would be an unbelievably simple export.
Protocol problems, and I'm happy to be wrong here:
* The client does not sign the server issued nonce (aka the 'challenge') during the authentication flow. This is kinda weird IMHO. Technically, yes it is secure, but it relies solely on the TLS channel heuristics. It'd be much better to have the client prove the signature on enrollment as layered security.
To address the author fears on attestation: This is a real threat to users... imagine a website "only accepting passkeys from OUR password manager". Luckily, Apple has done us all a favor and outright killed that part of the protocol by refusing to send this required fields there, protecting all users.
Overall, you should use them. We need one tiny change to the protocol and better password managers.
I can see why they would be problematic for people who otherwise live life with a single love2025 password though.
The only part that is very persuasive is the part about storing your passkeys with Google or Apple integrations, and what happens if they ban your account. But the same argument would apply if you’re only storing your passwords in a Google or Apple password manager.
I use passkeys and I always store them in a password manager I control - but usually I also store another one in the OS on Windows, Apple, and Google. Best of all worlds. Also, I appreciate that idiots aren’t forcing me to “change my passkeys” every 90 months like they STILL do with passwords!
Their security is nearly universally undermined by reset mechanisms.
There are virtually no sites where passkeys cannot be bypassed.