Live data from Hacker News

Passkeys were invented by engineers with zero understanding of consumer brain

twitter.com

231–240 of 813 posts

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#231
post #52
post #8

I do not know how to use a Passkey in a way that won’t impede how I log in to systems. I’ve been in tech for 26 years, and I understand the Public/private key behind what a Passkey is. Here’s what I don’t understand: I access a website through at least four different devices (my iPad, iPhone, Windows Desktop computer, and MacBook Pro) and three different browsers on each device (Brave, Firefox, Safari) , and I use La…

> If I accidentally set up a passkey on my phone (let’s say I use Safari one day instead of my go-to, Brave), can I still log in without that passkey on other devices? N=1 and I'm sure I'm holding it wrong, but I can only log in to ADP to request PTO from my personal laptop because I set up an iCloud passkey, work laptop does not allow access to iCloud keychain, and you can't request PTO from mobile.

Although that's more a failure of your workplace's security policy than of the Passkey itself. It makes sense that the passkey doesn't work if you can't access the place the passkey is stored.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#232
post #8

I do not know how to use a Passkey in a way that won’t impede how I log in to systems. I’ve been in tech for 26 years, and I understand the Public/private key behind what a Passkey is. Here’s what I don’t understand: I access a website through at least four different devices (my iPad, iPhone, Windows Desktop computer, and MacBook Pro) and three different browsers on each device (Brave, Firefox, Safari) , and I use La…

I’m 90% certain most of the push for passkeys is to prevent paid account sharing.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#233
post #8

I do not know how to use a Passkey in a way that won’t impede how I log in to systems. I’ve been in tech for 26 years, and I understand the Public/private key behind what a Passkey is. Here’s what I don’t understand: I access a website through at least four different devices (my iPad, iPhone, Windows Desktop computer, and MacBook Pro) and three different browsers on each device (Brave, Firefox, Safari) , and I use La…

Totally in the same boat, passkeys seem to massively increase the risk that I will lose access to my data.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#234

Earlier quoted context omitted.

Answer to almost all of your questions is that it entirely depends on the service what kind of auth implementation they offer. I personally have completely adopted passkeys and use them with every service that allows it. I use ProtonPass and have made it the default password store on every device and browser. This way all passkeys get stored in proton and I can login from any other personal device with proton setup.

> ...it entirely depends on the service what kind of auth implementation they offer. I think that's exactly the problem. These are all answerable questions, but getting those answers is confusing for most people.

Don't think it's any more confusing than e.g. logging in with an email address and password, or logging in with email + code, etc. A website's auth is usually a black box that they don't explain, and the only reason people find passkeys confusing is because they've been conditioned to enter passwords instead.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#235
post #215
post #176

I will never understand how a small group of tech savvy people are heavily confused and against a simple and more secure system. You want anecdotes? Ok. I’ve had elderly adult relatives who aren’t good with their devices tell me unprompted they’re using them and like them when I mentioned the word out loud to myself using my phone around them. These are people who don’t know the difference between apps and the web. W…

I've yet to meet a non tech person irl who uses them. I went through the laborious process years ago setting my parents up with 1Password. They find passkeys very confusing addition. I have yet to see the massive UX win. If that were true I don't think we'd be having this conversation. Good UX becomes the natural state of things and we don't even notice. I've had trouble myself setting up passkeys correctly with my 1…

The win for passkeys is login with faceID. That people actually use.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#236

Earlier quoted context omitted.

That's all I want to know. How do I restore from a backup? Specifically, a backup that I make to a medium I control, like a piece of paper or a burned CD-R in a safe deposit box. If I could get a good answer to that, I could be onboard. But from the conversations that I am getting here, it looks like only certain managers allow it, and with device attestation, they could be banned at any moment by any website with no…

> * and with device attestation, they could be banned at any moment by any website with no recourse.* Isn't this true of any authentication method? It doesn't seem unique to Passkeys.

Now that I think about it, you are right. But if they could ban my use of written passwords as easily as banning my use of a particular passkey device, why go through all the extra hoops to just be as vulnerable as before? This seems like a whole lot of extra work to do that gains me nothing.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#237
post #8

I do not know how to use a Passkey in a way that won’t impede how I log in to systems. I’ve been in tech for 26 years, and I understand the Public/private key behind what a Passkey is. Here’s what I don’t understand: I access a website through at least four different devices (my iPad, iPhone, Windows Desktop computer, and MacBook Pro) and three different browsers on each device (Brave, Firefox, Safari) , and I use La…

This is much, much simpler than you think it is. Passkeys are just passwords that require a password manager. If you lose your passkey, you'll reset your passkey the same way you reset your password, probably with a "forgot my password" email. (But you're not going to lose it, because you use a password manager, and the passkey will be stored there and synchronized to all of your other devices.) The weird part is tha…

I love that you wrote 6 paragraphs and linked to a medium post all without actually answering the question posed by the comment you replied to.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#238
post #8

I do not know how to use a Passkey in a way that won’t impede how I log in to systems. I’ve been in tech for 26 years, and I understand the Public/private key behind what a Passkey is. Here’s what I don’t understand: I access a website through at least four different devices (my iPad, iPhone, Windows Desktop computer, and MacBook Pro) and three different browsers on each device (Brave, Firefox, Safari) , and I use La…

My issue is that they're touted to the consumer as secure, and they're not really doing much more than a complex password. How do you generate a new key if you need one? Same process as a password reset. Does it prevent session stealers? Not at all. Its "benefit" is grandma can't read it to an attacker. OK, well can grandma click a link and have a session stealer bork her life instead? Yeah, and attackers know that a…

There is security value. A passkey will not work anywhere except the actual website. Fake look a like sites can't get the credentials. Evidently they can trick you into authorizing their device.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#239

Earlier quoted context omitted.

This is much, much simpler than you think it is. Passkeys are just passwords that require a password manager. If you lose your passkey, you'll reset your passkey the same way you reset your password, probably with a "forgot my password" email. (But you're not going to lose it, because you use a password manager, and the passkey will be stored there and synchronized to all of your other devices.) The weird part is tha…

This is not much simpler than they think it is. > But you're not going to lose it, because you use a password manager, and the passkey will be stored there and synchronized to all of your other devices That's just wrong. I use android, my partner uses ios. If he creates the passkey in safari, it's not going to get synced over to my phone. And that's just the first of the family sharing passwords issues. Same person i…

>That's just wrong. I use android, my partner uses ios. If he creates the passkey in safari,

There. You just violated the premise of his point, that you use a password manager that syncs to all your devices.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#240
post #54

Earlier quoted context omitted.

> These are all answerable questions, but getting those answers is confusing for most people. It's the same answer when someone asks 'how am I supposed to have a different password for every site' and 'how am I supposed to remember a password of X+ characters.' Use a password manager. Pretty sure every major one supports passkeys by now.

Password managers for passkeys have a huge problem when dealing with any kind of remote support or working on someone else's hardware - you can't just copy/paste or type in the passkey so you're forced to install the password manager on a family member's/stranger's/employer's PC or do what? I'm not even sure. At least SSH keys have forwarding when you ssh to a remote machine, how do you "forward" a passkey?

With Apple's Passwords app, you can create "groups" for passwords and passkeys and share them with people. Once shared, the passkey/password automatically fills as if it was that person's own.

I have a "Family" group in my Passwords app where I share passwords and passkeys with family members for exactly this purpose.

Post reply on HN