My bigger problem with passkeys is how there's no universal way to register more than one device (in case the first one is lost).
Proton Pass is a specific way to do that, but not a universal way. Bitwarden can't use proton pass to move keys around, google can't, firefox can't.
Tada, passkeys.
Yes, if you are edward snowden then not for you. For rest of us - it is useful
Yes, you can afford to host everything locally. Not everyone can.
If you browser vendor has implemented passkey then all good.
Most things are built for the majority users. Most don't change. Most don't debate browser wars in hn. Life is like that.
For Wii etc. You just scan the QR code shown in the TV interface. all just works.
Yes, if you want 100% privacy and will do only your own dovecot server then it is not for you.
>What if I switch browsers on my phone
>What if I get a new phone
You can let Apple sync your passkeys between devices using iCloud Keychain. Then you can create a passkey on one device and have it available on all of your devices. Google also syncs passkeys to the cloud and lets you use them on Windows (with Chrome)
>What if I change from android to iOS or visa versa
I resolve this by storing most of my passkeys in my password manager. I still store the "important" ones (like online banking) in my phone so a password manager breach doesn't make me lose my money.
>What if I need to log into the site on my Wii U's browser?
Passkeys were designed to let you have more than one, so if you have a device that doesn't let you use your password manager, then just set up another passkey.
This means if you go on a trip somewhere you absolutely need two devices. If you kill your phone and want to buy another one ASAP, you wont be able to do anything with the new device until you can convince the platform it's you. With passkeys you're just SOL. Imagining if you needed a phone to get back from your trip - e.g. etickets, auth needed etc. - it becomes a nightmare scenario.
A third party manager makes it easier, but it's a lot less usable that the first party ones.
Reasonable people make different life choice, having to constantly think about backup strategies whenever I'm away from home would be so stress inducing to me.
If you want multi-device redundancy, you have to carry a second device of some type, it's hard to get around that. I almost always travel with an iPad in addition to my phone, so I have a second device.
In addition, my wife (who travels with me so if my iPhone is stolen, hers might be too) is one of my Apple account recovery contacts, plus I've set my sister as an addtional recovery contact, so even if I'm out of the country and I have to activate a new iPhone, I can call her to help with the recovery. So all I have to do is find an Apple store and buy a new phone.
I also carry a USB key tucked into my luggage with the recovery kit (encrypted) for 1Password so I can activate 1Password on any new device and have access to my passwords and whatever passkeys I don't have in iCloud.
> With passkeys you're just SOL.
No more so than if you lose access to the device that's required for Google/Apple MFA prompts, neither of which use SMS and depend on a proprietary approval flow.If you lose your phone in 2026 while on a trip to Italy and try to enter your Gmail user/pass from your wallet, there's about a 100.00% chance you'll hit a "let's verify you're you" gate, that's been the case for 5+ years.
With passkeys I'm not stuck clicking Yes in the Gmail app or typing in the numbers on Apple hardware, I can skip the Apple/Google specific MFA nonsense and keep the passkeys in Bitwarden where they sync seamlessly between devices.
It feels truly liberating being able to skip MFA everywhere and login with 1 click, like a throwback to the golden age of using a password manager in 2010. Before passkeys it started to feel like I was spending 5% of my waking hours every day copying 6 digit codes from phone/email/TOTP after twiddling my thumbs for 15-30 seconds.
I did use Microsoft 365 (business version) for my email but they also decided I should use their MFA app so I left. I did have my yubikey as second factor but they keep pushing their stupid authenticator app.
The fearmongering of losing google account should stop. Yes, some people lose it. There are a larger proportion losing/getting pwned by repeat use. For the majority - just pressing the fingerprint to access an account (like amazon/eBay) via passkey is great.
Fairly technical co-workers - I used to suggest them to buy USB security key few years ago. Now that same fairly technical some how has at least 2 devices with them - so they just skipped the USB security key need - and just use Google (in Android) or iPhone in Apple ecosystem. Everything just works.
Yes, there will be a poor soul that may lost everything with only one device.
It shouldn’t be this way, but it is.
Not everyone has access to server grade hardware.
Until they lose access to that account and then it becomes my problem to solve.
And you need to accept it works for millions.
Yes there are few that used bitwarden and lost everything as their sync using syncthing failed.
I'd love a hardware sold in multi-packs and "born" at the factory with identical internal device key encryption keys (DKEK). I'd love, even more, if a token just allowed you to "commission" new ones w/ a user-specified DKEK on first use.
I'd use one token as a daily driver and store the other(s) in safe location(s), empty of my personal key material. (Or, if I can just commission a new token w/ my DKEK, store a printed copy of my DKEK in a safe location.)
Give the token a mechanism to "type" a backup of its internal state, encrypted with the DKEK, as a USB HID keyboard. That gives me an easy way to backup the token each time I enroll a new website.
If I lose my daily-driver token I just pull a spare from storage, import my last backup, and I'm up and running.
That would kick ass. No "You just need to buy two tokens and enroll them in every website" bullshit.
You would need some out of band way to collect and save your key IDs and publish revocations.
I’m not sure if this would work from a security theoretic perspective, need to think about how the request is signed and transmitted so someone can’t fake a key being “alive” when it’s really “dead”.
I do agree this would be incredibly useful if it can be made to work.
Are there hardware token implementations where mere possession of the token is all that's necessary to use the passkeys stored on it? That's incredibly stupid, and should have been disallowed by the standard, if that's the case.
See my other comment re: the IT industry being fools.
All this hullabaloo taking away user freedom to export keys and backup tokens but physical possession is all that's necessary to use it by default.
We are a ship of fools, the IT industry.
Are you part of the 99.99999% users of one of iOS+Apple or Androidlike+Google/Tencent or HarmonyOS+Huawei? If that's the case, you don't need to as the key is automagically saved by your OS' platform and synced with your new device.
Otherwise, you're such an extreme outlier that you probably either know what you're doing or can find out by yourself, right?
This absolutely does not encourage confidence in me. We all know how easy it can be to get locked out of a Google account and have no way of getting back in unless you have enough clout to make a huge noise online so a human there pays attention instead of you being stuck in the 'ol support-bot-run-around loop. It doesn't happen often when you consider how many users there actually are out there, but the potential inconvenience is high enough that “fairly rare in the grand scheme of things” is still enough to be reason enough to be wary.
To your point, I for example would add point c) - Is linked to the device you are using currently. If you want to use another device to log in you are in a world of complexity and pain.
Logging into a site with your device is like putting your card into the terminal. The site can ask for a password the way the terminal asks for a PIN, but if your device supports Passkeys, that’s like your card having a chip, and it’ll use that instead.
So think of Passkeys like using a chip card.
I dunno how well this analogy works down to the last detail but it has gotten it across to all the parents I’ve used it with
Then again, I doubt most people care to know, which is why that explanation works. They're not going to ask 'where is the passkey in my computer?'.
Ironically on macOS we used to have an app called Keychain which unfortunately was effectively renamed to Passwords for non-technical users.
Unlike physical objects they may reside in a TPM, a software vault, an export/backup, or any combination thereof. You may or may not be able to recover or migrate them, depending on where/how they were made.
Therefore you may need multiple per service, or maybe not. Services which only allow one may end up locking you out with no recourse. You get to find out.
None of this is obvious or self explanatory to normies.
Passkeys really are not any more difficult to explain than 2-factor authentication. Anyone who’s currently been able to actually create an Apple or Google account and successfully navigate their devices up to a passkey screen will be able to grok how it works.
People around here really ought to stop thinking users are complete idiots. Hell, you don’t even to scroll that far to read people calling users “normies” for crying out loud. What is this? High school?
Roughly one per smart-phone that they've ever used. They don't know the passwords or even the email address of any of them, not even the latest.
As for normies, passkeys or passwords it doesn't make a difference. Either you have people who use love1969 everywhere or those who constantly lose their passwords.
All passkeys accounts for normies require an email or phone number, which is what you can use to recover a password or passkey exactly the same way.
People must understand security controls, at least at a surface level, in order to effectively manage and trust them. Passkeys fail that test.
I always operated under the assumption that the passwords app was just a more casual view into the keychain
Maybe that's a bad assumption
That's a pain point in everyone's day that should make the benefit easy to understand.
Sure, its explained. But not in a satisfactory way that would reach all users at their level.
This is a bit of an exaggeration and out of proportion, but I think my ideal would be one of the big tech companies should have bought out something like a super bowl ad. Something that actually conveys the idea "hey, we know you've used passwords since you were able to type on a keyboard, but here's new technology that's better and here's why" in plain language that the average person can understand.
Unfortunately, XKCD 2501 continues to be relevant. [1]
If it's that unclear to me, I can't imagine how it can be to the average user.
The way they explain them is atrociously unclear, borderline negligent for services that nag people to activate it for accounts where they may hold valuable data for their personal lives. And while I don't want to spend much time finding out the details as long as I have the option to decline them, I suppose if they can't explain it and convince people of its advantages, it's because it's just bad tech.
That's what OS level user accounts are for. Tbf
> "what do Ineed do to login from an airport computer?" or "what should do if my phone is stolen?"
Indeed I don't know the answers to these either if I wasn't syncing passkeys in 1password. Honestly we should educate people to use password managers more than any thing. It's also a smaller jump than to passkeys. Passkeys can be more of an advanced convenience feature after they get used to using password managers already.