Live data from Hacker News

Passkeys were invented by engineers with zero understanding of consumer brain

twitter.com

141–150 of 813 posts

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#141

With physical U2F key, I could explain to my 78 year-old-parents "this is a physical key needed to access your account. Think of it like the front door key to your house. Don't lose it or lend it to anyone. We should have a couple of backup keys too." And they got completely understood and added it to all of their accounts. This was not hard. People assumed consumers were too stupid to do this without even giving the…

I still can't even get a physical key anywhere in person. You can certainly get phones just about anywhere, but you can't get any FIDO keys at brick and mortar, last I checked.

Until I can tell Grandma to "go down to Walmart and ask the man at the electronics counter for a Yubikey", we still have a few issues.

(No. Ordering online is *not* a valid option in this scenario. If I want to order a Yubikey to this address at this exact moment in time and space, Amazon won't deliver one to me for at least six days at the earliest, based on their rural delivery estimate. Replacing a key is basically impossible.)

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#142

The website for my HSA required me to set up a passkey last time I logged in. I set it up on my work laptop and my work password manager, which means I can now no longer access my account from my personal computer. This is fantastic, just what I wanted

I think the irony here is missed.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#143

I don’t understand this point at all. I think the author has himself confused with the average consumer. For the first time in a decade or so you can buy a PHYSICAL key and use it to sign into websites. I can explain this to any grandma out there. Likewise, I’m an Apple user. Once you’re in Apple universe passkeys are extremely easy. Tap your thumb on the scanner, done. Now we can put on the tinfoil hat and say how t…

Maybe it is easy to explain, but passkey promoters have clearly failed to do it. I don't think a single person I know in real life uses one.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#144
post #16

Earlier quoted context omitted.

the fact that some nebulous "group of companies" still uses typewriters does not mean that all modern cryptography is flawed

Diversity is resilience; no need to standardize on curves or "post-quantum" IBM bullshit if other approaches still work perfectly fine. And if the pros are using typewriters in 2026 it's not a signal for me to put even more eggs into the US-megacorp dominated basket who treat me like an NPC who can be droned at will.

An important skill to develop is determining whether somebody is bullshitting you. Because it would be impossible for any one human to perfectly understand all of these concepts, right? So when I read this person's blog post, I felt I could trust him, based on what I know about work he's done previously. I'm not saying you should trust me on this, or even blindly trust him, but look at his body of work, and the sources he cites, and make the call for yourself: https://words.filippo.io/crqc-timeline/

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#146
post #16

Earlier quoted context omitted.

the fact that some nebulous "group of companies" still uses typewriters does not mean that all modern cryptography is flawed

Diversity is resilience; no need to standardize on curves or "post-quantum" IBM bullshit if other approaches still work perfectly fine. And if the pros are using typewriters in 2026 it's not a signal for me to put even more eggs into the US-megacorp dominated basket who treat me like an NPC who can be droned at will.

What the hell are you talking about? What pros use typewriters for what (to write code?)?

I get reluctance about being dependent from the US but your reason seems a bit off

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#147

Earlier quoted context omitted.

This is much, much simpler than you think it is. Passkeys are just passwords that require a password manager. If you lose your passkey, you'll reset your passkey the same way you reset your password, probably with a "forgot my password" email. (But you're not going to lose it, because you use a password manager, and the passkey will be stored there and synchronized to all of your other devices.) The weird part is tha…

I am an engineer and have some insights on the discussions and developments around it. ITS NOT SIMPLE AT ALL 1. The idea was to provide a phishing resistant authentication method for enterprise users (companies loose quite a lot of money to phishing). 2. Majority of industry players shared the vision of a credential which is available across the platforms and browsers 3. The vision for collaboration never materialize…

It should have never been a cloud password manager play. It should be hardware device only, and tied to the device. One passkey on each hardware device.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#148
post #8

I do not know how to use a Passkey in a way that won’t impede how I log in to systems. I’ve been in tech for 26 years, and I understand the Public/private key behind what a Passkey is. Here’s what I don’t understand: I access a website through at least four different devices (my iPad, iPhone, Windows Desktop computer, and MacBook Pro) and three different browsers on each device (Brave, Firefox, Safari) , and I use La…

This is much, much simpler than you think it is. Passkeys are just passwords that require a password manager. If you lose your passkey, you'll reset your passkey the same way you reset your password, probably with a "forgot my password" email. (But you're not going to lose it, because you use a password manager, and the passkey will be stored there and synchronized to all of your other devices.) The weird part is tha…

Having to rely on a possibly proprietary password manager app to use a passkey sounds like a nightmare. A lot could go wrong with the password manager like becoming incompatible, becoming subscription based, lack of updates for bugs, etc. I don’t passkeys for the same reason as the original commenter.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#149
post #130

> I run a tech company and I have no idea what a passkey is and at this point I’m too afraid to ask I thought I was the only one!

lol it seems a good technical writing opportunity someone should take on.

also appreciate your attitude, better than "I work in tech for xx year, i don't understand yy, so yy must be bad."

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#150
post #108

Earlier quoted context omitted.

>This is much, much simpler than you think it is. Passkeys are just passwords that require a password manager. The issue isn't what passkeys _are_ (e.g. explaining they are like public/private "ssh keys" and hoping that type of explanation ends the confusion). Instead, it's the workflow around passkeys. The websites show very confusing dialog popups and choices that a lot of normal people will not understand. This is…

I don't think you're giving those seniors good advice. When the banks ask people to "switch" to passkeys, they're not removing the passwords; they're adding passkeys as an alternate login mechanism. If you lose your bank passkey, (e.g. if you put it in the wrong password manager and you can't figure out where it is) you can just sign in with your bank password. In the worst case, banks actually don't make it very har…

> In the worst case, banks actually don't make it very hard for seniors to reset your password/passkey; just show up at a branch with photo ID, your bank card, and your PIN, and a teller will help you reset your credentials. They do it all the time.

Maybe... I just ran into an annoying scenario where the largest bank in Canada made an administrative error where they mislinked an account belonging to me to my wife's profile.

I went to a physical branch to get it fixed and was told that branches don't have that kind of ability so I'd have to call customer support.

I called customer support and failed the verification questions because the expected answers were wrong, based on their own clerical error. After failing the verification questions, I just got a "we have to end this call, no additional information can be provided, please visit a branch."

I was able to get around it by calling back in and providing the incorrect, but expected answers to pass the verification step - I imagine, however, that this could have turned into a real nightmare for seniors, or anyone who wasn't able to deduce what the expected verification answers were.

Post reply on HN