The problem is that the UX for this is extra super confusing, and people will end up with passkeys that aren't backed up anywhere and get locked out of their accounts.
The problem is that the UX for this is extra super confusing, and people will end up with passkeys that aren't backed up anywhere and get locked out of their accounts.
In your sleep, your house has burned down. You have zero devices, and your backup keys are stuck in a building you do not have access to for another several hours. You have made it out of your home with: Your wallet, containing $20 cash, a handful of slightly melty credit cards, an ID that is almost readable, and your keys. The credit cards are fucked and will need to be replaced. Your ID is mostly readable.
This is the situation that I pose for most people to try and get undone from. I then amp it up another notch:
you have no job and are unemployed currently. You cannot make use of any insurance system as you have been deemed "impossible to insure" due to your status. You currently live in a cardboard box behind a restaurant in downtown.
And before you go "why would a homeless person need email", it's required for lots of services, as is a phone number that can at least have voicemail at it (this is a service that Futel^1 provides in some places). You can't assume that physical artifacts will continue being in the possession of a dishomed person. One of the common reasons for losing all your personal effects in this situation is the state literally taking everything down to your clothes away^2.
^1 https://futel.net/ ^2 https://www.realchangenews.org/news/2024/06/05/sweeps-triple...
You're traveling in a foreign country without your laptop when your wallet and phone are stolen. You can probably get to a public computer, but how do you get into your email?
This situation strikes me as much more likely than getting hacked. Hence I will never use passkeys unless forced, and if forced I will do everything in my power to switch to another service. Same for forced 2FA as far as I'm concerned.
I have tested this process with my partner. the only thing that I cannot replace is the TOTP token to add new devices (however this is bypassed when recovering from paper). I have legitimately considered etching the recovery data into a small glass (borosilicate) dish using selective laser etching.
Thus, "password recovery material, TOTP QR code, and an SD card with essential documentation" can be passed to next of kin easily.
Ah, so no worries then. I've still got a passkey for all the services I really care about.
If I'm not supposed to have cloud-synced credentials like so many here dislike with those implementations of passkeys, chances are the copies of my password safes and my SSH keys to the VPS are all cooked as well.
Scanning a QR code: https://support.apple.com/en-us/102680
The time investment could even be worth it, since "Signing in with a passkey is three times faster than using a traditional password and eight times faster than a password and traditional MFA", according to the article.
-> I have that turned off
Scanning a QR code:
-> My back-camera lens is shattered. Using the front is dodgy at best. I don't feel like I need fork out for an to upgrade as I use a digital camera if I want to take pictures.
What about those don't use smart phones?
Have a broken phone camera? Cannot scan qr codes.
Lost the phone? Cannot log into vital modern day accounts like email.
Your house burned down, and the passkey device with it? Say goodbye to literally everything.
Homeless (temporary or otherwise) persons, random local government sweep just trashes everything you own. Bye bye to the passkey again.
If my phone explodes like a Samsung surprise, and my laptop turns into a spicy pillow;
I can in the worst case scenario, still log in via the local library PC.
I could borrow a device from a friend, or buy a second hand Thinkpad and use that.
That is to my knowledge, not possible with a passkey device.
If you’re remembering all your passwords there’s a good chance they’re terrible, you frequently re-use them or both. That really helps attackers e.g. when they use leaked passwords to run credential stuffing attacks on your employer.
You just wrote two comments bashing a technology you admit you didn’t properly educate yourself about.
For android, the passkey is clone-able iirc, but again, it's an expensive smart device.
So now I am expected to have at a minimum, two use-able smart phones, per family member. Iphone? Frankly, fuck that shit. Too expensive.
Android, I can manage it. But doing that for all family members is not financially viable.
Also I do use a password manager and an encrypted text file. (Not smart, I know. The file is basically a backup)
But I really cannot expect people like my mother to understand how to set up a passkey. Much less, how to setup multiple for the off chance one is lost. Add onto the fact that Yubikey does not support twins, and many services do not support multiple passkeys.
In terms of computer literacy, using my mother as a baseline (Age:Mid50s) the current passkey system is non-viable.
So just make multiple passkeys on the different platforms/devices.
> So now I am expected to have at a minimum, two use-able smart phones
No, you can have passkeys on laptops and desktops. It doesn't need to be a phone. Hardware tokens can be had for like $20.
Something I know is the only authentication method that can't be physically destroyed. When your customers are the masses every failure mode that can happen will happen, usually at the most inconvenient time.
What sucks about passkeys in abstract is that you want at least two failure modes that are uncorrelated— you're unlikely to forget your password and have your house burn down at the same time. Passkeys consolidate everything into to physical possessions which can be and are destroyed all at once.
Just install a webcam on it and scan the qr code iOS displays.
/s
I don't know why this is such a common misconception about passkeys.
Account recovery flows are generally entirely unaffected by moving from passwords to passkeys. If a user forgets their password or passkey, they generally go through an email recovery flow and generate a new one.
...this is sort of a rhetorical question, but also maybe not? Slack does it, as do some other services I can't think of off the top of my head. I feel like a lot of normal people who don't use password managers basically always use email resets when logging in from a new computer.
The thing is, email was never designed for this purpose. Password managers are. I stay logged into my email client on my computer, but I have to retype my password to open my Bitwarden vault.