Live data from Hacker News

Passkeys were invented by engineers with zero understanding of consumer brain

twitter.com

281–290 of 813 posts

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#281

Earlier quoted context omitted.

> you can ask a bank teller to help you At virtually all banks, the bank tellers cannot help you with login problems. You will have to call the bank's tech support and somehow navigate AI-modulated phone menu hell.

Citation needed. Walk in with photo ID, a bank card, and your PIN, and all the major banks will send you a reset-password email.

I went to my bank with all my ID and my bank card, talked to the teller and was told to call a support line. One of my parents went through the same thing.

I don't have a citation for you just recent experience, do you have a citation?

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#282
post #238

Earlier quoted context omitted.

My issue is that they're touted to the consumer as secure, and they're not really doing much more than a complex password. How do you generate a new key if you need one? Same process as a password reset. Does it prevent session stealers? Not at all. Its "benefit" is grandma can't read it to an attacker. OK, well can grandma click a link and have a session stealer bork her life instead? Yeah, and attackers know that a…

There is security value. A passkey will not work anywhere except the actual website. Fake look a like sites can't get the credentials. Evidently they can trick you into authorizing their device.

Sure? MitM isn't a new kind of attack, and I'd be surprised if the ball-of-wax-and-javascript that is WebAuthn isn't vulnerable to that...

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#283

Earlier quoted context omitted.

If I'm on someone else's computer and I want to use a passkey on my phone, the computer will display a QR code. I scan the QR code with my phone, the phone signs the login request and posts it to the service's callback. Then I'm logged in on that new device. If my phone's camera is broken but both devices have bluetooth, it can do the handshake over bluetooth. If I'm on someone else's computer and I want to use a pas…

This is good in theory but in practice doesn't always work. It isn't just a QR code like I would like it to be, its a QR code and you need bluetooth. Maybe there is a hypothetical world where bluetooth drivers actually work on windows machines and can connect to a mobile device seamlessly but that is not my experience. Across multiple windows machines i often have a problem where windows just decides the machine does…

I use this feature a bunch across dozens of different Windows and Mac devices from various device vendors with multiple Android phones and seemingly never had an issue.

But I'm also a person who generally never experiences the issues some people have with Bluetooth in general. If I ever have an issue with Bluetooth on a computer, I swap out the wireless chipset with an actually good one. Its almost always just bad hardware. I've only had to do that a few times in the last decade though, more modern WiFi/BT chipsets are generally pretty OK. Its the old ones that are near worthless.

Although I will say most of the time I just plug in my USB authenticator. I normally only fall back to the QR code if I don't have my keys on me.

And as an edit, I wasn't aware fully that the QR code is to help assist the BT handshake, I had assumed it was posting a signed request back to the service. My bad, my above comment isn't completely correct. Thanks for cluing me in to the BT requirement for the QR code path.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#285

It’s quite the opposite. Passkeys are phenomenal for a lot of consumers. Based on this thread, it’s the engineers who understand authentication in the first place and have their own system (eg password manager) that are confused. Consider a user in the Apple ecosystem: you are already conditioned to just do Touch ID or Face ID when asked. I was on Amazon the other day, it prompted randomly for “want to set up a passk…

A password manager let's me use my service specific credential from any device, securely and decentralized. Passkeys lock into a specific device and seem easy until you need to use another device. But instead of being a credential you own and control, across what could even be a local password manager, it's one password to everything. Maybe it is more secure than a regular password in some cases but it largely seems…

Passkeys do *not* do that. I use 1Password to manage my passkeys and they are all synced across all my authenticated devices where I installed 1Password.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#286
post #34

Earlier quoted context omitted.

Passkeys basically MITM the 2FA process so that they can track and deplatform you with a single click across all your accounts. The biometric verification also allows to confirm that a certain person is holding the device, and they can easily be matched to existing passport/travel databases. Great system if the good guys have it, a bit problematic if it's abused by nepo kids to hide their crimes.

> Passkeys basically MITM the 2FA process so that they can track and deplatform you with a single click across all your accounts. I use passkeys with a physical authenticator. How do "they" track and deplatform me with a single click? Can you explain?

The service can use the use the attestation feature to block passkey providers that are deemed undesirable for whatever reason. Hard not to see eventually only major providers being accepted, even things like Microsoft services requiring Microsoft Passkeys using the Microsoft Passkey App which you're now required to have on your phone. Or worse you now need Symantec Passkeys to login to Symantec services (using that example since I believe Symantec had a ToTP App you needed to reverse engineer to extract the ToTP seed from if you wanted to use a different Authenticator)

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#287
post #250
post #8

I do not know how to use a Passkey in a way that won’t impede how I log in to systems. I’ve been in tech for 26 years, and I understand the Public/private key behind what a Passkey is. Here’s what I don’t understand: I access a website through at least four different devices (my iPad, iPhone, Windows Desktop computer, and MacBook Pro) and three different browsers on each device (Brave, Firefox, Safari) , and I use La…

In practice, because site owners know users are going to mess up having their passkeys on all devices, I've not seen any insist that a passkey _must_ be used, and you can always log in with your password (or worst case, email magic links) as a fallback. However, this negates the primary stated objective of passkeys, removing the possibility of users being phished, so I'm not sure how long that will remain the case ev…

> I've not seen any insist that a passkey _must_ be used, and you can always log in with your password (or worst case, email magic links) as a fallback.

With the exception of Github, and banks.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#288
post #37

FWIW: I find passkeys to be a very simple and easy to use concept. Simple: it's like a password that I don't have to type in Easy to use: because I use 1Password and just have it installed on everything. On Android, it can be set as the default passkey provider so, even on mobile, I am using passkeys shared across devices. Is this "less secure" because I'm sharing the keys through 1Password. I suppose, at some level.…

I try to use passkeys when possible as I'm also a 1Password user, but this hardly "just works". Firefox on Windows often triggers the Windows password manager for passkeys (some how this is only on some sites), making it impossible to use 1Password.

I've seen the same on Android too, and I think there's a difference in how Chrome and Firefox are handling the requests.

Then you get in to cases like a Microsoft Account. You need to use your account to log in to the device that has the passkeys, so the workflow never works properly and you have to fall back to another method.

Amazon is another one. If an app like Libby redirects to Amazon, I get a different, passkey-less password prompt, so I need to have a password readily available.

It's great when it works, but honestly 1password with straight up username/passwords is probably just a better UX in the end.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#289

Earlier quoted context omitted.

I don't think you're giving those seniors good advice. When the banks ask people to "switch" to passkeys, they're not removing the passwords; they're adding passkeys as an alternate login mechanism. If you lose your bank passkey, (e.g. if you put it in the wrong password manager and you can't figure out where it is) you can just sign in with your bank password. In the worst case, banks actually don't make it very har…

> In the worst case, banks actually don't make it very hard for seniors to reset your password/passkey; just show up at a branch with photo ID, your bank card, and your PIN, and a teller will help you reset your credentials. They do it all the time. Maybe... I just ran into an annoying scenario where the largest bank in Canada made an administrative error where they mislinked an account belonging to me to my wife's p…

> I went to a physical branch to get it fixed and was told that branches don't have that kind of ability so I'd have to call customer support.

What are the branches even for if not customer support?

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#290
post #238

Earlier quoted context omitted.

My issue is that they're touted to the consumer as secure, and they're not really doing much more than a complex password. How do you generate a new key if you need one? Same process as a password reset. Does it prevent session stealers? Not at all. Its "benefit" is grandma can't read it to an attacker. OK, well can grandma click a link and have a session stealer bork her life instead? Yeah, and attackers know that a…

There is security value. A passkey will not work anywhere except the actual website. Fake look a like sites can't get the credentials. Evidently they can trick you into authorizing their device.

That's also how any good password manager works. You'd have to manually copy-paste the password to get around the same-site fill restriction (whether it's autofill or manual fill).
Post reply on HN