Live data from Hacker News

The transition from logins to cryptographic passkeys is getting messy

wired.com

1–10 of 154 posts

Re: The transition from logins to cryptographic passkeys is getting messy

#2
> Another big challenge with establishing consistency and continuity will be the long transition to passkeys alone.

If I wanted passwordless login, why wouldn't I just hit the big 'sign in with facebook' button practically every website has these days?

Re: The transition from logins to cryptographic passkeys is getting messy

#3
post #2

> Another big challenge with establishing consistency and continuity will be the long transition to passkeys alone. If I wanted passwordless login, why wouldn't I just hit the big 'sign in with facebook' button practically every website has these days?

Because passkey is owned by you (as in - whichever software vault you're using) and not Facebook.

It's no different than stored random 32 character passwords in a password manager... it's pretty much the same really, just that you don't have to copy/paste it in a form.

Re: The transition from logins to cryptographic passkeys is getting messy

#4
post #2

> Another big challenge with establishing consistency and continuity will be the long transition to passkeys alone. If I wanted passwordless login, why wouldn't I just hit the big 'sign in with facebook' button practically every website has these days?

and login facebook w/ password

Re: The transition from logins to cryptographic passkeys is getting messy

#5
post #2

> Another big challenge with establishing consistency and continuity will be the long transition to passkeys alone. If I wanted passwordless login, why wouldn't I just hit the big 'sign in with facebook' button practically every website has these days?

If you like Facebook tracking everything you do, and the data breach risk associated with their copy of your entire online life, then go for it.

Re: The transition from logins to cryptographic passkeys is getting messy

#6
Part of the problem is that right now the most convenient use of things like yubikeys is that the most convenient use of them is just leave them in your computer wherever they may be.

That makes them a pretty hard sell for any workplace environment, but also makes them a significant security risk on-par with writing your passwords on a post-it note for anyone looking to burgle... Seems like 2FA is the future...

Re: The transition from logins to cryptographic passkeys is getting messy

#7
post #2

> Another big challenge with establishing consistency and continuity will be the long transition to passkeys alone. If I wanted passwordless login, why wouldn't I just hit the big 'sign in with facebook' button practically every website has these days?

Wouldn't that give somebody having access to your FB account access to every website you used FB login for? At minimum you'd still need 2FA with that to avoid this.

Re: The transition from logins to cryptographic passkeys is getting messy

#9
post #6

Part of the problem is that right now the most convenient use of things like yubikeys is that the most convenient use of them is just leave them in your computer wherever they may be. That makes them a pretty hard sell for any workplace environment, but also makes them a significant security risk on-par with writing your passwords on a post-it note for anyone looking to burgle... Seems like 2FA is the future...

I also decided against yubikey and for Password manager + 2FA (TOTP), for this reason.

Re: The transition from logins to cryptographic passkeys is getting messy

#10
post #6

Part of the problem is that right now the most convenient use of things like yubikeys is that the most convenient use of them is just leave them in your computer wherever they may be. That makes them a pretty hard sell for any workplace environment, but also makes them a significant security risk on-par with writing your passwords on a post-it note for anyone looking to burgle... Seems like 2FA is the future...

Passkey can also use biometrics, if supported by the OS/browser.
Post reply on HN