Does it really matter? I think all of my accounts use 20char autogenerated passwords from google that are unique for each account. So if one is breached, it’s just breached. Seems to have the same protection as a passkey.
Does it really matter? I think all of my accounts use 20char autogenerated passwords from google that are unique for each account. So if one is breached, it’s just breached. Seems to have the same protection as a passkey.
Long strings in password managers was a shim until Passkeys got here, because passwords suck. This is a well worn path in enterprise with PKI. Passkeys are PKI for the Average Joe. Folks here will always have esoteric auth use cases, but you design for the average on this topic (consumer auth).
https://passkeys.2fa.directory/us/
https://bitwarden.com/blog/a-closer-look-at-password-statist...
> 19% of respondents said they used “password” as their password (!!!)
> 52% use easily identifiable information in their passwords, such as company/brand names, well-known song lyrics, pet names, and names of loved ones
> Best practices are still diluted by bad habits, with 85% reusing passwords across multiple sites and 58% relying on memory for their passwords
> A majority (68%) of respondents manage passwords for 10+ sites or apps and yet 84% of respondents reuse passwords
> More than half of respondents forget and reset their passwords on a regular basis
> Around a quarter (20%) were affected by breaches and a majority (80%) were prompted to reset their passwords
> Over half (56%) are excited about passwordless options, and 50% are using or would use ‘something you are’ forms of passwordless authentication
If you have concerns about Big Tech treating Passkeys in an anti competitive fashion, I would strongly encourage you to file a complaint with the FTC when that evidence is observed (as I mention in another comment here [1]). We need these primitives to deliver a better digital experience but also need to defend against fuckery using legal and regulatory mechanisms.
Amazon: https://www.aboutamazon.com/news/retail/amazon-passwordless-...
Uber: https://help.uber.com/riders/article/using-passkeys-to-sign-...
Ebay: https://www.ebay.com/help/account/signing-account/signing-ac...
Github: https://github.blog/2023-09-21-passkeys-are-generally-availa...
Link by Stripe: https://app.link.com/
Docusign: https://www.docusign.com/blog/docusign-customers-can-upgrade...
Tiktok: https://newsroom.tiktok.com/en-us/passkeys-fido-alliance (TikTok has over 1.677 billion users globally, out of which 1.1 billion are its monthly active users)
Google's Titan key now supports Passkeys if you need a secure hardware authenticator: https://www.wired.com/story/google-titan-security-key-passke... | https://store.google.com/us/product/titan_security_key?hl=en...
I like passkeys, they’re nice.
But I think you want to compare passkey users to complex password users.
I know lots of “normies” and they all just accept whatever their iPhone does. Which is creates a high entropy unique password for each site.