Developer criticizes passkeys as poor fit for personal security
Ethan Hawksley argues that despite their phishing resistance, passkeys create new risks around account lockout and vendor lock-in.
What to know
- Passkeys solve phishing but introduce new risks: permanent account lockout, device loss, and irreversible account bans from Apple/Google ecosystems could lock users out of all passkey-protected accounts.
- Hardware-based passkey solutions are costly and don't scale: users need multiple keys ($50-300+), and discoverable credential limits (25-300 accounts per key) require buying additional hardware as account numbers grow.
- Cross-platform passkey support remains immature: FIDO interoperability is fragmented, third-party password managers struggle with platform APIs, and export functionality is inconsistent—making passwords more portable.
- The tech industry's aggressive passkey promotion (Google's 'Skip password when possible' setting, Microsoft's passwordless push) frames a corporate-friendly solution as consumer-ready, masking practical limitations for individual users.
The dispute Whether passkeys' anti-phishing benefits outweigh the practical risks of account lockout and vendor lock-in for individual users. · positions read across 126 posts and comments
Passkeys are technically sound but operationally impractical for individuals due to account lockout, device loss, and hardware costs.
-
“Passkeys are a fantastic technology…but a poor fit for personal security.”
Ethan Hawksley · hawksley.dev blog ↗
Big Tech companies are pushing passkeys primarily to lock users into their ecosystems rather than for genuine security benefits.
-
“Both Apple and Google want your identity anchored to their operating systems…If their automated systems decide one day to ban your account, you irreversibly lose access to all your passkeys.”
Ethan Hawksley · hawksley.dev blog ↗
The current fragmentation and immaturity of cross-platform passkey support makes passwords more reliable for users with multiple accounts.
-
“The FIDO alliance has been working to improve interoperability…but currently it is too immature to rely on. Compare with a password, which is just a string you can easily export by hand if necessary.”
Ethan Hawksley · hawksley.dev blog ↗
Ethan Hawksley Developer and authorGoogle Tech company promoting passkeysMicrosoft Tech company promoting passwordless authenticationApple Tech company integrating passkey managementFIDO Alliance Standards organization
How it unfolded 3 developments, newest first · click a bar or a number to jump articlesposts
-
3
Article posted to Lobsters community
The critique appeared on Lobsters, another developer-focused platform, continuing amplification of Hawksley's concerns about passkey practicality.
-
M
A nice discussion of passkeys. They're for the company's convenience. They don't protect the user. https:// hawksley.dev/blog/i-dont-like- passkeys
2 more of the top 3 · 121 posts in this stretch
-
I love passkeys as an _additional_ login method. My stuff is typically locked behind email and/or password+TOTP, but I like to add passkey on top of that because logging in by just touching the fingerprint scanner is less clicks and faster than going through password manager or "login with X". It's worth emphasizing that disliking passkeys as the…
-
This article touches on something I've been ruminating about the past few months - the lack of control users have over their own security posture.Like many people, I use dozens of online applications a day, from banking through to childcare booking platforms to online shopping. With data breaches becoming ubiquitous and a common occurrence…
-
-
2
Post shared across tech communities including Mastodon
The article began circulating on Mastodon and other platforms, extending the discussion beyond Hacker News to broader tech communities.
-
YES. This exactly. I work across multiple devices, some of which are nonstandard/uncommon (Linux, Xiaomi China ROM, ...) and I've NEVER had passkeys work properly - yet everything constantly prompts me to add one. Even if they did work, I'd have to carry around hardware keys or register each computer separately. And the lack of backups if a device…
2 more of the top 3 · 5 posts in this stretch
-
H
I don't like passkeys L: https:// hawksley.dev/blog/i-dont-like- passkeys C: https:// news.ycombinator.com/item?id=4 9753211 posted on 2026.09.18 at 08:06:50 (c=0, p=4)
-
While the technology itself may be great (I don't really know since I don't use them) it has been co-opted by the tech conglomerates as another form of isolating and walling off users into their ecosystems.And honestly, nowadays, if tech companies are pushing really hard for something then that is an immediate red flag for me and it bears more…
-
-
1
Post gains significant traction on Hacker News
The article reached Hacker News frontpage with 67 points and 36 comments within hours of publication, indicating substantial interest from the developer community in the passkey debate.
“Passkeys are a fantastic technology…but a poor fit for personal security. To an individual, the greatest risks are instead permanent account lockout, automated account bans, and device loss.”
— Ethan Hawksley, Developer and author · source -
background
Hawksley publishes detailed critique of passkeys — Developer Ethan Hawksley published a blog post arguing that passkeys, despite being technically superior at preventing phishing attacks, are poorly suited for personal use due to risks of permanent account lockout, automated account bans, device loss, high hardware costs, and vendor lock-in to Apple and Google ecosystems.
Also covered reported alongside — the timeline has no entry for these yet
-
2 outlets I don't like passkeys
first by HN Best, 5d ago · also HN Frontpage
What people are saying 20 voices from 3 sites · best of 126 · verbatim
- Sep 19
-
> But this still breaks the login flow for a very common use case: how do I log in on a device that I don't own? With a password in a password manager I at least have the option of manually typing the password.This is meant to be solved by the cross-device flow - a QR code pops up that you scan, and a secure channel is established from that with…
- Sep 18
-
So what you're saying is you suspect users don't understand that their passkey is tied to their hardware and they're going to find out exactly how screwed they are the moment they switch hardware? Because they have no idea what's goin under the hood? "I got a brand new laptop! ...oh no what happened I can't log into anything whyyyyy", or even just…
-
I’m convinced that a lot of the passkey hate ultimately stems from the inconsistent and confusing flows that websites have implemented in the name of backwards compatibility with passwords. I have made some apps where passkeys are the only way to log in and it is such a lovely experience. It can be as simple as a single log in button by itself…
-
Passkeys really seem like a tool best suited for power users. I don't feel that average people - who largely don't use password managers - are going to understand how to use them.
-
W
Even though I have my PassKeys portable, and even though I don’t have them locked to one device, this is why I honestly removed some PassKeys for accounts and just increased my password complexity . I don't like passkeys | Ethan Hawksley https:// hawksley.dev/blog/i-dont-like- passkeys # InfoSec # Passkey # Passkeys # Security
-
Very solid points, and I love the focus on the fact that passkeys are addressing threats irrelevant to regular people, while ignoring those that matter. But I think it's still incomplete, because it's missing the biggest blind spot in design:Password sharing is a feature, not a bug.Security industry failed to implement the most basic feature one…
-
> A combination of randomly generated passwords stored inside a third-party password manager, paired with an independent TOTP app, gives control to the user without giving up the flexibility of plain text. For users who previously reused passwords across all their sites, passkeys are a huge step-up. I wish anyone dishing out security system…
-
I don’t really agree, I maintaining a service with a fancy password-less authentication system using passkeys and one-time passwords sent by email, and I think passkeys are nice in this scenario: - About 50% of the users log in with passkeys, as it’s super fast and convenient - For users using a device that does not support passkey, they sign in…
-
Fake websites pretending to be legitimate websites in order to steal your passwords was considered a HUGE problem. That's why TLS includes website certificates. The implementation is kind of a mess with commercial Certificate Authorities (CAs) being too expensive for small businesses to use, CAs getting hacked, or downright shady CAs that couldn't…
-
Part of the problem with passkeys is that websites do not have a consistent philosophy as to whether they are an additional login method or a required second factor.
-
It's the classic "make your problems worse to fix my problems" that you see across tech. Since they don't care if you get locked out or leave their platform, it's designed to make them maximally profitable. It's the same thing you see when sites "offer" to let you do pre-registration work before an event or transaction, even though doing that work…
-
I use my password manager for managing passkeys across devices. The article covers this as Third-party synced passkeys. For me this works very well in every common case I have. I ALSO want to have a username/password for the edge cases, and I use crazy length random passwords. If my passkeys were tied to my devices I’d hate them, but I don’t have…
-
I hate on device passkeys, but I love yubikey
-
N
I don't like passkeys: https:// hawksley.dev/blog/i-dont-like- passkeys Discussion: http:// news.ycombinator.com/item?id=4 9753211
-
I had to mess with this just yesterday.I got a new cell phone and installed Microsoft Swiftkey and tried to login to Microsoft. It said my device's password or security manager would popup, but it never did and it never showed an option to login via password, just a mostly blank screen. I tried logging in from my laptop browser and it immediately…
-
I have a work computer. My wife has a desktop computer at home. I have a laptop. A tablet. A phone. The whole family have accounts on the desktop. The whole thing is very many-to-many. The ergonomics of passkeys are not appealing to me.
-
I like passkeys because I just think of them as yubikeys that live inside your devices, and I’ve long used yubikeys for everything. I don’t mess with all the various sync thingamabobs. I can’t remember the last time I signed into an account on someone else’s computer, or them mine. Not saying it doesn’t happen or it is an invalid use case. But…
-
> The biggest problem, though, is how users are pushed into it without any warning or knowledge of what they're signing up for.My irritation is that I know what it is, and I've said no thanks many times, but I'm still asked regularly by the likes of Amazon, and they usually pick a time when I'm trying to order something quick¹. It is one of the…
-
I respectfully disagree with the author!Passkeys have been a massive quality-of-life improvement. Yes, there's the minimal risk of lockout if you lose access to the passkey (though almost every site I've used that implements pk's lays it on top of their traditional user/pass auth flow), but generally speaking most people use iCloud or their Google…
-
Passkeys do marginally improve security against MITM and phishing attacks, but they are primarily for protecting the lowest common denominator from themselves: people who re-use passwords and/or don't use a password manager.If you use multiple devices throughout the day, registering passkeys in all of these systems becomes a big headache with…