RIP Passwords? Passkey support rolls out to Chrome stable
arstechnica.com
arstechnica.com
These aren't unsolvable problems, but I think this is a point where openness and user control should be a priority, both of which Apple and Google don't have a great track record with.
As an aside, I would like to plug Bulwark Passkey (https://bulwark.id), my open-source passkey manager which I think solves some of these problems. Passkeys have the potential to fix a lot of the problems with passwords, but there are fundamental concerns around user control that I think need to be addressed.
As for adoption, I see a few stumbling blocks. Those who have the mod cons will obviously adopt with little foresight.
IMO, the first to refuse outright, will be the people who've already grown tired of needing to do something on the day, but experienced the service they want to use is down ... worse some third party the site relies on is, very very slow, down or broken, or they are met with some new strange issue the site despite the correct password, had with validating their operating system or the pooled IP your ISP has unwittingly assigned this day, has been abused. (I already shop away from such systems, and it's a dull pain when a once perfectly working online shop, adopts some newfangled clever thinking, oh bother. )
The next on the rung, will have in mind those who take their devices near everywhere ... esp phones with the multitude of apps and their life wrapped up in it. Unless under a rock, we've all heard the horror stories when some people have lost their device. With this in mind, after theft or loss, how does one prove they are in control of their email, sms etc when the have to tackle getting their ship back to normal? [Yes, the service will have asked the user set a password to the passwordless service ... or have a stored fingerprint of a second or third device.]