Article posted to Lobsters community
3 Sep 18 8:52 AM · 5d ago · 1 post · 1 source · development 3 of 3
The critique appeared on Lobsters, another developer-focused platform, continuing amplification of Hawksley's concerns about passkey practicality.
Ethan Hawksley Developer and authorGoogle Tech company promoting passkeysMicrosoft Tech company promoting passwordless authenticationApple Tech company integrating passkey managementFIDO Alliance Standards organization
The whole story articlesposts the bright band is this development · numbered dots are the others · click one to jump
What people said 24 voices · best of 121 · verbatim
-
M
A nice discussion of passkeys. They're for the company's convenience. They don't protect the user. https:// hawksley.dev/blog/i-dont-like- passkeys
-
I love passkeys as an _additional_ login method. My stuff is typically locked behind email and/or password+TOTP, but I like to add passkey on top of that because logging in by just touching the fingerprint scanner is less clicks and faster than going through password manager or "login with X". It's worth emphasizing that disliking passkeys as the…
-
This article touches on something I've been ruminating about the past few months - the lack of control users have over their own security posture.Like many people, I use dozens of online applications a day, from banking through to childcare booking platforms to online shopping. With data breaches becoming ubiquitous and a common occurrence…
-
W
Even though I have my PassKeys portable, and even though I don’t have them locked to one device, this is why I honestly removed some PassKeys for accounts and just increased my password complexity . I don't like passkeys | Ethan Hawksley https:// hawksley.dev/blog/i-dont-like- passkeys # InfoSec # Passkey # Passkeys # Security
-
Part of the problem with passkeys is that websites do not have a consistent philosophy as to whether they are an additional login method or a required second factor.
-
Fake websites pretending to be legitimate websites in order to steal your passwords was considered a HUGE problem. That's why TLS includes website certificates. The implementation is kind of a mess with commercial Certificate Authorities (CAs) being too expensive for small businesses to use, CAs getting hacked, or downright shady CAs that couldn't…
-
N
I don't like passkeys: https:// hawksley.dev/blog/i-dont-like- passkeys Discussion: http:// news.ycombinator.com/item?id=4 9753211
-
> A combination of randomly generated passwords stored inside a third-party password manager, paired with an independent TOTP app, gives control to the user without giving up the flexibility of plain text. For users who previously reused passwords across all their sites, passkeys are a huge step-up. I wish anyone dishing out security system…
-
Very solid points, and I love the focus on the fact that passkeys are addressing threats irrelevant to regular people, while ignoring those that matter. But I think it's still incomplete, because it's missing the biggest blind spot in design:Password sharing is a feature, not a bug.Security industry failed to implement the most basic feature one…
-
I have a work computer. My wife has a desktop computer at home. I have a laptop. A tablet. A phone. The whole family have accounts on the desktop. The whole thing is very many-to-many. The ergonomics of passkeys are not appealing to me.
-
> But this still breaks the login flow for a very common use case: how do I log in on a device that I don't own? With a password in a password manager I at least have the option of manually typing the password.This is meant to be solved by the cross-device flow - a QR code pops up that you scan, and a secure channel is established from that with…
-
I like passkeys because I just think of them as yubikeys that live inside your devices, and I’ve long used yubikeys for everything. I don’t mess with all the various sync thingamabobs. I can’t remember the last time I signed into an account on someone else’s computer, or them mine. Not saying it doesn’t happen or it is an invalid use case. But…
-
> The biggest problem, though, is how users are pushed into it without any warning or knowledge of what they're signing up for.My irritation is that I know what it is, and I've said no thanks many times, but I'm still asked regularly by the likes of Amazon, and they usually pick a time when I'm trying to order something quick¹. It is one of the…
-
Passkeys really seem like a tool best suited for power users. I don't feel that average people - who largely don't use password managers - are going to understand how to use them.
-
I’m convinced that a lot of the passkey hate ultimately stems from the inconsistent and confusing flows that websites have implemented in the name of backwards compatibility with passwords. I have made some apps where passkeys are the only way to log in and it is such a lovely experience. It can be as simple as a single log in button by itself…
-
I use my password manager for managing passkeys across devices. The article covers this as Third-party synced passkeys. For me this works very well in every common case I have. I ALSO want to have a username/password for the edge cases, and I use crazy length random passwords. If my passkeys were tied to my devices I’d hate them, but I don’t have…
-
I respectfully disagree with the author!Passkeys have been a massive quality-of-life improvement. Yes, there's the minimal risk of lockout if you lose access to the passkey (though almost every site I've used that implements pk's lays it on top of their traditional user/pass auth flow), but generally speaking most people use iCloud or their Google…
-
So what you're saying is you suspect users don't understand that their passkey is tied to their hardware and they're going to find out exactly how screwed they are the moment they switch hardware? Because they have no idea what's goin under the hood? "I got a brand new laptop! ...oh no what happened I can't log into anything whyyyyy", or even just…
-
It's the classic "make your problems worse to fix my problems" that you see across tech. Since they don't care if you get locked out or leave their platform, it's designed to make them maximally profitable. It's the same thing you see when sites "offer" to let you do pre-registration work before an event or transaction, even though doing that work…
-
I hate on device passkeys, but I love yubikey
-
Passkeys do marginally improve security against MITM and phishing attacks, but they are primarily for protecting the lowest common denominator from themselves: people who re-use passwords and/or don't use a password manager.If you use multiple devices throughout the day, registering passkeys in all of these systems becomes a big headache with…
-
I don’t really agree, I maintaining a service with a fancy password-less authentication system using passkeys and one-time passwords sent by email, and I think passkeys are nice in this scenario: - About 50% of the users log in with passkeys, as it’s super fast and convenient - For users using a device that does not support passkey, they sign in…
-
I had to mess with this just yesterday.I got a new cell phone and installed Microsoft Swiftkey and tried to login to Microsoft. It said my device's password or security manager would popup, but it never did and it never showed an option to login via password, just a mostly blank screen. I tried logging in from my laptop browser and it immediately…
-
> a poor fit for personal security. To an individual, the greatest risks are instead permanent account lockout, automated account bans, and device loss. By using passkeys, you gain better security against man-in-the-middle attacks but face the higher probability scenario of losing access to your accounts. He's talking about *individuals*; maybe…
All 3 developments of Developer criticizes passkeys as poor fit for personal… →
Hacker NewsMastodonNewswiresLobsters