108 points ethanhawksley 1 hour ago 76 comments
junaru 43 minutes ago | parent
It's entirely one sided solution.
cbarrick 35 minutes ago | parent
Like, no company should be storing anything but a salted hash of their users' passwords.
kenrick95 43 minutes ago | parent
etatester 37 minutes ago | parent
Ironically on macOS we used to have an app called Keychain which unfortunately was effectively renamed to Passwords for non-technical users.
paulryanrogers 33 minutes ago | parent
Unlike physical objects they may reside in a TPM, a software vault, an export/backup, or any combination thereof. You may or may not be able to recover or migrate them, depending on where/how they were made.
Therefore you may need multiple per service, or maybe not. Services which only allow one may end up locking you out with no recourse. You get to find out.
None of this is obvious or self explanatory to normies.
kskdkwkdkwk 17 minutes ago | parent
Passkeys really are not any more difficult to explain than 2-factor authentication. Anyone who’s currently been able to actually create an Apple or Google account and successfully navigate their devices up to a passkey screen will be able to grok how it works.
People around here really ought to stop thinking users are complete idiots. Hell, you don’t even to scroll that far to read people calling users “normies” for crying out loud. What is this? High school?
arwineap 32 minutes ago | parent
I always operated under the assumption that the passwords app was just a more casual view into the keychain
Maybe that's a bad assumption
joombaga 9 minutes ago | parent
ryan-duve 36 minutes ago | parent
My bigger problem with passkeys is how there's no universal way to register more than one device (in case the first one is lost).
blackdahlia313 21 minutes ago | parent
malfist 4 minutes ago | parent
Proton Pass is a specific way to do that, but not a universal way. Bitwarden can't use proton pass to move keys around, google can't, firefox can't.
cfiggers 30 minutes ago | parent
Tada, passkeys.
rcxdude 26 minutes ago | parent
wolvoleo 24 minutes ago | parent
rcxdude 21 minutes ago | parent
mystifyingpoi 18 minutes ago | parent
malfist 3 minutes ago | parent
Spide_r 22 minutes ago | parent
Sure, its explained. But not in a satisfactory way that would reach all users at their level.
This is a bit of an exaggeration and out of proportion, but I think my ideal would be one of the big tech companies should have bought out something like a super bowl ad. Something that actually conveys the idea "hey, we know you've used passwords since you were able to type on a keyboard, but here's new technology that's better and here's why" in plain language that the average person can understand.
Unfortunately, XKCD 2501 continues to be relevant. [1]
silon42 43 minutes ago | parent
pletnes 41 minutes ago | parent
hannasanarion 26 minutes ago | parent
The purpose of rotating passwords is to cycle out potentially compromised ones, due to phishing attacks, keyloggers, shoulder snoops, etc. But those cannot exist with a passkey.
wg0 43 minutes ago | parent
john_strinlai 31 minutes ago | parent
there's some issues with passkeys, but not being able to memorize them is a feature
blackdahlia313 24 minutes ago | parent
wg0 8 minutes ago | parent
john_strinlai 6 minutes ago | parent
same ux, different security properties.
>Except that at least I can memorize a password by heart just in case.
"just in case" should be a thought out recovery flow, rather than hoping that you remember the password of the account you need to access.
elteto 42 minutes ago | parent
And honestly, nowadays, if tech companies are pushing really hard for something then that is an immediate red flag for me and it bears more scrutiny. One of those "if you see them running that way you run the opposite way".
mschuster91 32 minutes ago | parent
The reason is the ever increasing number of hijacks of social media presences and code hosting portals, with the latter being a serious financial threat. Done right, passkeys stay in the Secure Enclave, at least for anything Apple and most of the Android sphere. There is no reasonable way to obtain login credentials for accounts protected by passkeys without physical access to the user's device(s).
iso1631 16 minutes ago | parent
Click "I lost my device", enter contact, get a reset link via email/sms
reddalo 7 minutes ago | parent
Passwords with 2FA are simply better and more freedom friendly.
blfr 40 minutes ago | parent
mschuster91 29 minutes ago | parent
It most definitely isn't. Any 2nd factor that is not the device I am currently using (either a yubikey or my phone) has a non-zero chance of not being near me when I need it, leading to the constant question of "where the fuck did I put that darn thing", only to find out that the cat has decided to believe the yubikey is a mouse and tried to devour it, the phone's battery went dead...
xyzzy_plugh 37 minutes ago | parent
But they also introduce single points of failure, as the article points out. I can't even remember how many times I've had to help a family member recover their account or get confused when they can't sign in on a new device. It's incredibly frustrating that this flow is promoted as the default for so many services.
1password is the best solution I've found for the average person. It's not perfect (it's definitely more complex than writing down your passwords on a piece of paper or using the same password everywhere) but it's much easier than juggling yubikeys. I know so many non-technical staff members who prefer the OS or browser keys even if it means another account recovery is lurking around the corner.
vanschelven 37 minutes ago | parent
<<ducks>>
kardianos 37 minutes ago | parent
micromacrofoot 37 minutes ago | parent
Password managers are great IMO, I can use some absurdly long password, backup is reliable, I can use them across devices. For extra secure stuff 2FA works the same, I've got an app with codes I can easily back up and use from multiple devices.
Passkeys tend to obscure everything and take away a lot of control.
BoppreH 36 minutes ago | parent
I proposed an alternative scheme many years ago: https://www.researchgate.net/publication/343318317_Privacy-a... . By allowing "offline" keys you can also treat them as higher priority, and use them to revoke any lesser keys from attackers if your account is compromised.
It would also be nicer to get rid of usernames, but that's a fight against the data-gathering powers that we're unlikely to win.
Liftyee 36 minutes ago | parent
girvo 31 minutes ago | parent
(At least til I get around to setting up my new usb c yubikeys!)
etatester 35 minutes ago | parent
I can see why they would be problematic for people who otherwise live life with a single love2025 password though.
kejdkwjdjwj 10 minutes ago | parent
Passkeys are great. The Apple passkey experience is seamless. They just work. Anything else is poppycock of the highest order.
hahn-kev 30 minutes ago | parent
drtz 29 minutes ago | parent
If you use multiple devices throughout the day, registering passkeys in all of these systems becomes a big headache with O(m*n) complexity, so putting the passkeys in a password manager is the only realistic solution. But this still breaks the login flow for a very common use case: how do I log in on a device that I don't own? With a password in a password manager I at least have the option of manually typing the password.
The biggest problem, though, is how users are pushed into it without any warning or knowledge of what they're signing up for. I've accidentally set up passkeys just by clicking an okay button a few times in the past and had to go back and figure out how to undo it after being blocked from login on another computer (which computer was I on again?).
mystifyingpoi 22 minutes ago | parent
Sad reality is that such usecase is less and less common, thus, no one cares about it. I think majority of my friends would not be able to access their email, or facebook or alike, if they were forced to use my computer in emergency.
xphos 28 minutes ago | parent
rcxdude 23 minutes ago | parent
blackdahlia313 25 minutes ago | parent
If you think passkeys aren't ready yet, blame the people implementing it on their platforms.
VCFundedGenYer 6 minutes ago | parent
F7F7F7 25 minutes ago | parent
As someone who's OpSec puts swiss cheese to shame Passkey has been a godsend. My passwords are actually much better because of it.
blackdahlia313 22 minutes ago | parent
brushfoot 24 minutes ago | parent
That said, I don't like passkeys either.
elAhmo 24 minutes ago | parent
Probably hundreds of millions or even billion people have devices that support biometric auth. How is that not mature?
Al-Khwarizmi 10 minutes ago | parent
Brilliant security: a highly secure high-tech shiny front door that can randomly fail to open, so you still need the low-tech back door, which is the one potential thieves will use.
Mind you, it can work if the back door is old but sturdy (basically, for a bank that will ask for KYC authentication, or in the worst case you can set foot in the brick-and-mortar branch showing your face and ID and ask for access) but for pretty much every other service it introduces risks for very little or no gain.
hannasanarion 21 minutes ago | parent
Amazon prompts me to create a passkey everytime I log in, even when I logged in with a passkey, because my passkeys live in Bitwarden rather than my OS or browser.
And the confusing mechanism hurts there too: I'm always a little bit afraid that i'm somehow more in danger because I keep them in a vault that's shared on all my devices rather than a TPM, because whenever the protocol is explained the "it can't leave your device" part is highlighted as the main source of the security, except.... mine obviously do leave my device, with the vault, so.....
jasonjayr 13 minutes ago | parent
Sites can request hardware-bound tokens, which would block any software based password managers. It's an option in the protocol but one not yet widely utilized.
XorNot 7 minutes ago | parent
It should not be in the protocol. And I don't trust Apple and Google not to lock it away from me.
I want my own open source manager and if that is attempted I want it to lie about it.
jeroenhd 2 minutes ago | parent
What setup are you using? Because I don't have that problem on Linux + Firefox at all
Finnucane 21 minutes ago | parent
Of course, at the rate we see security failures everywhere, I'm not entirely convinced writing your passwords on post-it notes wasn't such a bad idea after all.
ectoloph 20 minutes ago | parent
I actually prefer non-resident U2F in some ways. You don't have to store anything on your key, you are just signing requests. This is relevant where U2F/FIDO keys have limited slots for 'resident' keys.
In principle, it's great. You have one good password to remember for the average user, and that's enforced by their device's probably good enough security posture.
They are resistant to being phished and they won't reuse the same one everywhere. They then don't end up going from hunter2 to hunter2! everywhere.
But my experience for users is that they worry they are giving their biometrics to Amazon or whoever and so the UX just confuses them.
The certification aspect was new to me too last time passkeys came up. Sites can require that a given passkey has been certified.
The patchy support for them is also frustrating. MacOS does not support NFC FIDO/U2F. iOS does.
whalesalad 20 minutes ago | parent
juancn 18 minutes ago | parent
Passkeys just make it harder/riskier.
lapcat 10 minutes ago | parent
1. Write it down on a piece of paper and put it in a safe deposit box.
2. Read it on one device (or from a piece of paper!) and enter it manually on another device.
Plain text is the ultimate form of cross-platform portability. Passkeys are the ultimate form of vendor lockdown. The passkey vendors won't even allow you to view the private key, unlike with ssh keys, which you can also write down on a piece of paper. It's vendor cabal to destroy computing freedom in the name of "security", always the excuse. Tech company paternalism at its worst.
VCFundedGenYer 7 minutes ago | parent
Microsoft is especially poorly prepared for this - Often if you have a passkey, it will CONTINUE To ask you to create a passkey (a new and different one), and it may save it in a different place, which is infuriating.
Strong password + MFA is the way, and I don't see that changing.
brettermeier 4 minutes ago | parent
throw7 3 minutes ago | parent
People have replied it's possible to extract the private key, but it's not clear to me that that's usable (maybe it is I don't know). It's certainly not in line with what passkey devs want people to do and not do, so I'm not interested in "fighting" against the "flow" so to speak.
I'm happy with TOTP, as I can manage and use the codes where I want, under my control.