conv.

All stories
TechActive today · day 6

Developer criticizes passkeys as poor fit for personal security

Ethan Hawksley argues that despite their phishing resistance, passkeys create new risks around account lockout and vendor lock-in.

What to know

  • Passkeys solve phishing but introduce new risks: permanent account lockout, device loss, and irreversible account bans from Apple/Google ecosystems could lock users out of all passkey-protected accounts.
  • Hardware-based passkey solutions are costly and don't scale: users need multiple keys ($50-300+), and discoverable credential limits (25-300 accounts per key) require buying additional hardware as account numbers grow.
  • Cross-platform passkey support remains immature: FIDO interoperability is fragmented, third-party password managers struggle with platform APIs, and export functionality is inconsistent—making passwords more portable.
  • The tech industry's aggressive passkey promotion (Google's 'Skip password when possible' setting, Microsoft's passwordless push) frames a corporate-friendly solution as consumer-ready, masking practical limitations for individual users.

The dispute Whether passkeys' anti-phishing benefits outweigh the practical risks of account lockout and vendor lock-in for individual users. · positions read across 126 posts and comments

most voices

Passkeys are technically sound but operationally impractical for individuals due to account lockout, device loss, and hardware costs.

  • “Passkeys are a fantastic technology…but a poor fit for personal security.”

    Ethan Hawksley · hawksley.dev blog ↗
many voices

Big Tech companies are pushing passkeys primarily to lock users into their ecosystems rather than for genuine security benefits.

  • “Both Apple and Google want your identity anchored to their operating systems…If their automated systems decide one day to ban your account, you irreversibly lose access to all your passkeys.”

    Ethan Hawksley · hawksley.dev blog ↗
many voices

The current fragmentation and immaturity of cross-platform passkey support makes passwords more reliable for users with multiple accounts.

  • “The FIDO alliance has been working to improve interoperability…but currently it is too immature to rely on. Compare with a password, which is just a string you can easily export by hand if necessary.”

    Ethan Hawksley · hawksley.dev blog ↗

Ethan Hawksley Developer and authorGoogle Tech company promoting passkeysMicrosoft Tech company promoting passwordless authenticationApple Tech company integrating passkey managementFIDO Alliance Standards organization

Developer criticizes passkeys as poor fit for personal security
hawksley.dev

How it unfolded 3 developments, newest first · click a bar or a number to jump articlesposts

Peak 27 pieces in two hours at Sep 18, 8 AM; 130 pieces over 6 days (2 articles · 6 posts · 122 comments) Sep 18, 8 AM — 27 pieces · 2 articles · 3 posts · 22 comments — Hacker News 23, Newswires 2, Lobsters 1, +1 moreSep 18, 10 AM — 8 pieces · 8 comments — Hacker News 6, Lobsters 2Sep 18, 12 PM — 17 pieces · 1 post · 16 comments — Hacker News 11, Lobsters 5, Mastodon 1Sep 18, 2 PM — 21 pieces · 1 post · 20 comments — Hacker News 12, Lobsters 8, Mastodon 1Sep 18, 4 PM — 5 pieces · 5 comments — Lobsters 4, Hacker News 1Sep 18, 6 PM — 2 pieces · 2 comments — Lobsters 2Sep 18, 8 PM — 2 pieces · 2 comments — Hacker News 1, Lobsters 1Sep 18, 10 PM — quietSep 19, 12 AM — 2 pieces · 2 comments — Hacker News 1, Lobsters 1Sep 19, 2 AM — 3 pieces · 3 comments — Lobsters 3Sep 19, 4 AM — 2 pieces · 2 comments — Lobsters 2Sep 19, 6 AM — 7 pieces · 1 post · 6 comments — Lobsters 6, Mastodon 1Sep 19, 8 AM — 4 pieces · 4 comments — Lobsters 4Sep 19, 10 AM — 5 pieces · 5 comments — Lobsters 5Sep 19, 12 PM — 1 piece · 1 comment — Lobsters 1Sep 19, 2 PM — 2 pieces · 2 comments — Lobsters 2Sep 19, 4 PM — 1 piece · 1 comment — Lobsters 1Sep 19, 6 PM — 1 piece · 1 comment — Hacker News 1Sep 19, 8 PM — quietSep 19, 10 PM — quietSep 20, 12 AM — 7 pieces · 7 comments — Lobsters 7Sep 20, 2 AM — quietSep 20, 4 AM — quietSep 20, 6 AM — quietSep 20, 8 AM — 2 pieces · 2 comments — Lobsters 2Sep 20, 10 AM — quietSep 20, 12 PM — 1 piece · 1 comment — Lobsters 1Sep 20, 2 PM — quietSep 20, 4 PM — quietSep 20, 6 PM — quietSep 20, 8 PM — quietSep 20, 10 PM — quietSep 21, 12 AM — quietSep 21, 2 AM — quietSep 21, 4 AM — quietSep 21, 6 AM — quietSep 21, 8 AM — quietSep 21, 10 AM — quietSep 21, 12 PM — quietSep 21, 2 PM — quietSep 21, 4 PM — quietSep 21, 6 PM — quietSep 21, 8 PM — quietSep 21, 10 PM — quietSep 22, 12 AM — quietSep 22, 2 AM — quietSep 22, 4 AM — quietSep 22, 6 AM — quietSep 22, 8 AM — quietSep 22, 10 AM — quietSep 22, 12 PM — quietSep 22, 2 PM — quietSep 22, 4 PM — 1 piece · 1 comment — Lobsters 1Sep 22, 6 PM — 1 piece · 1 comment — Lobsters 1Sep 22, 8 PM — 1 piece · 1 comment — Lobsters 1Sep 22, 10 PM — 1 piece · 1 comment — Lobsters 1Yesterday, 12 AM — 1 piece · 1 comment — Lobsters 1Yesterday, 2 AM — quietYesterday, 4 AM — quietYesterday, 6 AM — quietYesterday, 8 AM — 1 piece · 1 comment — Lobsters 1Yesterday, 10 AM — quietYesterday, 12 PM — quietYesterday, 2 PM — quietYesterday, 4 PM — quietYesterday, 6 PM — 1 piece · 1 comment — Lobsters 1Yesterday, 8 PM — 3 pieces · 3 comments — Lobsters 3Yesterday, 10 PM — quietToday, 12 AM — quiet ◂ 1 earlier2–3
Sep 19Sep 20Sep 21Sep 22yesterdaynow · 2:06 AM ET
  1. 3

    Article posted to Lobsters community

    The critique appeared on Lobsters, another developer-focused platform, continuing amplification of Hawksley's concerns about passkey practicality.

    • mwl@io.mwl.io

      A nice discussion of passkeys. They're for the company's convenience. They don't protect the user. https:// hawksley.dev/blog/i-dont-like- passkeys

      mwl@io.mwl.ioMastodon4d ago175▲view on Mastodon ↗
    2 more of the top 3 · 121 posts in this stretch
    • I love passkeys as an _additional_ login method. My stuff is typically locked behind email and/or password+TOTP, but I like to add passkey on top of that because logging in by just touching the fingerprint scanner is less clicks and faster than going through password manager or "login with X". It's worth emphasizing that disliking passkeys as the…

      matkladsecurity5d ago44▲view on Lobsters ↗
    • This article touches on something I've been ruminating about the past few months - the lack of control users have over their own security posture.Like many people, I use dozens of online applications a day, from banking through to childcare booking platforms to online shopping. With data breaches becoming ubiquitous and a common occurrence…

      publlus_enigmaHacker News5d agoview on Hacker News ↗
    all of them →
  2. 2

    Post shared across tech communities including Mastodon

    The article began circulating on Mastodon and other platforms, extending the discussion beyond Hacker News to broader tech communities.

    • YES. This exactly. I work across multiple devices, some of which are nonstandard/uncommon (Linux, Xiaomi China ROM, ...) and I've NEVER had passkeys work properly - yet everything constantly prompts me to add one. Even if they did work, I'd have to carry around hardware keys or register each computer separately. And the lack of backups if a device…

      LiftyeeHacker News5d agoview on Hacker News ↗
    2 more of the top 3 · 5 posts in this stretch
    • hkrn@mstdn.social

      I don't like passkeys L: https:// hawksley.dev/blog/i-dont-like- passkeys C: https:// news.ycombinator.com/item?id=4 9753211 posted on 2026.09.18 at 08:06:50 (c=0, p=4)

      hkrn@mstdn.socialMastodon5d agoview on Mastodon ↗
    • While the technology itself may be great (I don't really know since I don't use them) it has been co-opted by the tech conglomerates as another form of isolating and walling off users into their ecosystems.And honestly, nowadays, if tech companies are pushing really hard for something then that is an immediate red flag for me and it bears more…

      eltetoHacker News5d agoview on Hacker News ↗
    all of them →
  3. 1

    Post gains significant traction on Hacker News

    The article reached Hacker News frontpage with 67 points and 36 comments within hours of publication, indicating substantial interest from the developer community in the passkey debate.

    “Passkeys are a fantastic technology…but a poor fit for personal security. To an individual, the greatest risks are instead permanent account lockout, automated account bans, and device loss.”
    — Ethan Hawksley, Developer and author · source
  4. background

    Hawksley publishes detailed critique of passkeys — Developer Ethan Hawksley published a blog post arguing that passkeys, despite being technically superior at preventing phishing attacks, are poorly suited for personal use due to risks of permanent account lockout, automated account bans, device loss, high hardware costs, and vendor lock-in to Apple and Google ecosystems.

Also covered reported alongside — the timeline has no entry for these yet

  1. first by HN Best, 5d ago · also HN Frontpage

What people are saying 20 voices from 3 sites · best of 126 · verbatim