Live data from Hacker News

Passkeys were invented by engineers with zero understanding of consumer brain

twitter.com

211–220 of 813 posts

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#211

Earlier quoted context omitted.

> This makes it impossible to copy and paste your passkey to the wrong person (someone trying to trick you). It also, unfortunately, means it's not possible (via most passkey implementations) to back those passkeys up to paper. Which is quite unfortunate: backing up to paper is one of the most stable and human accessible ways of ensuring redundancy and continuity, an inevitable but also oft-ignored part of credential…

> back those passkeys up to paper Is writing down passwords something people do? I have countless passwords saved over >20 years and I don’t think I’ve ever recorded one to paper. I even checked a couple of popular password management solutions and they don’t seem to have “print” functionality.

[deleted]

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#213
post #177
post #140

Earlier quoted context omitted.

You can use a passkey that's tied to a Yubikey.

The problem here is i want to have more than 1 yubikey, so if i lose it, all is not lost... I can't do that with the current implementations unless i present N yubikeys to every new account i make. Which makes an off-site backup yubikey impossible. With my current yubikey usage with password store, my "offline" yubikey can be brought in whenever i want to decrypt the passwords, including ones inserted while the key w…

Also, where do I store the backup Yubikey, or any other pass key owning device for that matter? It has to be easily accessible to set up the pass keys, but also safe from accidents like house fire.

There's a strange tension where I want to use pass keys because they are easy to use but also they are easy to lose, so I choose a KeePass synced over cloud and deal with a bit of a hassle by having to copy/paste my passwords.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#214
post #108

Earlier quoted context omitted.

This is much, much simpler than you think it is. Passkeys are just passwords that require a password manager. If you lose your passkey, you'll reset your passkey the same way you reset your password, probably with a "forgot my password" email. (But you're not going to lose it, because you use a password manager, and the passkey will be stored there and synchronized to all of your other devices.) The weird part is tha…

>This is much, much simpler than you think it is. Passkeys are just passwords that require a password manager. The issue isn't what passkeys _are_ (e.g. explaining they are like public/private "ssh keys" and hoping that type of explanation ends the confusion). Instead, it's the workflow around passkeys. The websites show very confusing dialog popups and choices that a lot of normal people will not understand. This is…

The what and why make sense. The how is poorly done. People are generally familiar with passwords but passkeys are different.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#215
post #176

I will never understand how a small group of tech savvy people are heavily confused and against a simple and more secure system. You want anecdotes? Ok. I’ve had elderly adult relatives who aren’t good with their devices tell me unprompted they’re using them and like them when I mentioned the word out loud to myself using my phone around them. These are people who don’t know the difference between apps and the web. W…

I've yet to meet a non tech person irl who uses them. I went through the laborious process years ago setting my parents up with 1Password. They find passkeys very confusing addition. I have yet to see the massive UX win. If that were true I don't think we'd be having this conversation. Good UX becomes the natural state of things and we don't even notice. I've had trouble myself setting up passkeys correctly with my 1Password. This never happens with traditional passwords and 1Password

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#216
post #43

Earlier quoted context omitted.

Listening to Yubikey and OnePassword talk about this, they actually say "One Person, One Device". Which really speaks to their failure to understand their users.

That is odd, I regularly use my Yubikey on multiple devices, that was the biggest draw.

The Yubikey is the "one device". But most people don't buy Yubikeys so the "one device" is, in practice, a smartphone.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#217
post #8

I do not know how to use a Passkey in a way that won’t impede how I log in to systems. I’ve been in tech for 26 years, and I understand the Public/private key behind what a Passkey is. Here’s what I don’t understand: I access a website through at least four different devices (my iPad, iPhone, Windows Desktop computer, and MacBook Pro) and three different browsers on each device (Brave, Firefox, Safari) , and I use La…

A potentially good idea got corrupted by vendors, password managers, browsers, etc trying to assert control. I'm also an engineer and I find the UI around passkeys entirely unclear, but it doesn't have to be that way. It seems like everyone wants to be _the_ password manager for all your passkeys. They don't want to make it easy to understand that is what they are doing though, they just happily offer to "handle it for you".

My non-technical friends are extremely confused by passkeys and if they should use them and how to use them and I honestly don't have very good answers. It is a mess. I don't believe an inherit mess, but one created by the companies and projects trying to take advantage of the new system.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#218

Earlier quoted context omitted.

This is much, much simpler than you think it is. Passkeys are just passwords that require a password manager. If you lose your passkey, you'll reset your passkey the same way you reset your password, probably with a "forgot my password" email. (But you're not going to lose it, because you use a password manager, and the passkey will be stored there and synchronized to all of your other devices.) The weird part is tha…

This is not much simpler than they think it is. > But you're not going to lose it, because you use a password manager, and the passkey will be stored there and synchronized to all of your other devices That's just wrong. I use android, my partner uses ios. If he creates the passkey in safari, it's not going to get synced over to my phone. And that's just the first of the family sharing passwords issues. Same person i…

> Every single major password manager supports export.

They all support exporting passwords, but, check your CSV; you won't find any passkeys in the CSV export for Apple, Google, Microsoft, Mozilla, 1Password, or LastPass.

(Bitwarden, Proton Pass, and KeepassXC do support exporting passkeys to CSV, which undermines the phishing protections, at least somewhat. It’s possible to trick you into exporting your passkeys from Bitwarden and sending the file to an attacker. It’s up to you to decide whether protecting yourself from being tricked into exporting your passkeys is worth sacrificing your ability to read them.)

> How useful is your firefox passwords on an iphone?

Did you try it? That's the primary feature of the Firefox app for iPhone.

(Especially since the Firefox app for iPhone is just Safari's WebKit wearing a Firefox disguise.)

> Or Mac OS's keychain I use as a daily driver on my windows gaming desktop?

https://apps.microsoft.com/detail/9pktq5699m62?hl=en-US&gl=U...

> With the iCloud for Windows app, you can access photos, files, passwords, and other important information from your iPhone or other Apple devices on your Windows PC.

When Apple's your password manager, you use Apple's password manager app to synchronize passwords and passkeys.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#219

Earlier quoted context omitted.

This is why I am so concerned about passkeys. They could be a good improvement, but in practice I already see how it's going to result in Google/Apple/Microsoft/whoever seizing even more control. The document there is laughable too, because KeepassXC is listed as "not performing User Verification" when it demands manual authorization per request. But this isn't good enough for the passkey people. Ultimately, I see an…

Yeah they're really trying to solve problems that should be solved at a technical level with soft solutions in porcelain. See also this issue asking keepassxc to disable plaintext exports, which is completely technically feasible https://github.com/keepassxreboot/keepassxc/issues/10407

The author of this ticket seems to come across as an arrogant know-it-all that thinks "the threats i thought of (or personally face) are the only threats that are significant, fuck anyone in a different situation."

I proudly print my entire KDBX file including passkey private keys and I encourage my elderly parents to do so too.

Lightning strikes (and assisting people with cleanup and repair from them) have taught me that there are definitely a class of threats that will leave me with paper but possibly no technology until I can go buy a cheap laptop to restart my digital life, SO BEING ABLE TO BACK EVERYTHING UP IS ABSOLUTELY ESSENTIAL.

His website says he's in Boston, so I seriously doubt he's ever seen what lightning can do or dealt with a hurricane or tornado.

In general, if you're in the FIDO Alliance and had anything to do with the kind of micromanagement that passkeys can allow, FUCK YOU. Go get a job at Walmart as a greeter. We'll all be better off.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#220

Earlier quoted context omitted.

If I'm on someone else's computer and I want to use a passkey on my phone, the computer will display a QR code. I scan the QR code with my phone, the phone signs the login request and posts it to the service's callback. Then I'm logged in on that new device. If my phone's camera is broken but both devices have bluetooth, it can do the handshake over bluetooth. If I'm on someone else's computer and I want to use a pas…

Does the apple passwords app work this way (log in to a public machine by scanning a QR code?)

Passkey on an iPhone, logging into a public-ish terminal by scanning a QR code? Yes.

In fact, if you have your Apple Passwords app set to sync through iCloud, you can:

- Make a passkey on your Mac for a site in the Passwords app

- Go to a different computer (a friend's or whatever)

- Attempt to log in, choose use another device, it'll show the QR code

- Use your iPhone to scan that QR code and sign in, as the iPhone has the passkey synced through iCloud

Note, the same kind of thing is also possible with other password managers as well.

Post reply on HN