Live data from Hacker News

Passkeys were invented by engineers with zero understanding of consumer brain

twitter.com

291–300 of 813 posts

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#291
My biggest issues with Passkeys is how inconsistently they are implemented and how opaque they attempt to be.

I understand SSH keys, I've been using them for decades, I know where they live, I know how to secure them.

Passkeys are murky as fuck. Is your PW manager supported? Do they sync? Where are they stored? How can I move to another PW manager if I want to in the future? Can I have more than 1 passkey per site? And the list goes on.

I _know_ some of you out there can answer some/all of the questions above but it's mostly on a per-site basis. Passkeys take too much of the control out of my hands and I don't like that.

Even more than that, I hate how they are trying to be pushed on me at every turn. Login -> Want to save a passkey (but they never call it that, they use some other confusing euphemism)? I click "No" and then it proceeds to pop 1Password's UI, then I dismiss that and it opens Chrome's passkey save UI, I dismiss that, and then it opens the OS's passkey UI. It's incredibly disrespectful and unclear.

I never use anything but 1Password but somehow everyone (OS and Browser) try to reach their grubby hands in. This is what scares me, I don't like having to be on high-alert to not accidentally save a passkey in Chrome or Safari and not realize until I'm on a different device and notice it's not in 1Password.

Lastly I trust the developers implementing passkeys... none, I trust them none, zero, zilch. I don't trust them to pick the right defaults, I don't trust their recovery options, and I know they will always pick the configuration that benefits them and not me.

No, for now I'll stick with my as-long-as-you-let-me-make-my-password random passwords which I never copy/paste into random website and be perfectly safe, thank you.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#292
post #8

I do not know how to use a Passkey in a way that won’t impede how I log in to systems. I’ve been in tech for 26 years, and I understand the Public/private key behind what a Passkey is. Here’s what I don’t understand: I access a website through at least four different devices (my iPad, iPhone, Windows Desktop computer, and MacBook Pro) and three different browsers on each device (Brave, Firefox, Safari) , and I use La…

I think the intended workflow is you login with your phone and that device is now the authority that allows other devices to issue their own passkeys. In my opinion it's a bad plan, because it elevates certain devices to privileged status, if you lose your phone you are hosed. Passkeys should be allowed to be synced between devices and stored on password managers in the cloud. I am making my own password manager for…

  > Passkeys should be allowed to be synced between devices and stored on password managers in the cloud. I am making my own password manager for my personal use, but have not delved into passkeys.
They are, that’s exactly how I use all my passkeys with Bitwarden. They sync to any device I have Bitwarden installed on when added on one device.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#294
post #287
post #250

Earlier quoted context omitted.

In practice, because site owners know users are going to mess up having their passkeys on all devices, I've not seen any insist that a passkey _must_ be used, and you can always log in with your password (or worst case, email magic links) as a fallback. However, this negates the primary stated objective of passkeys, removing the possibility of users being phished, so I'm not sure how long that will remain the case ev…

> I've not seen any insist that a passkey _must_ be used, and you can always log in with your password (or worst case, email magic links) as a fallback. With the exception of Github, and banks.

Porkbun too

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#295

Like some folks already commented here, even as someone who has been working in tech for 20+ years, I find Passkey confusing. I understand the key aspect in computer science term, but I don't know how to use it across devices. Another big worry is that if I tie that to a physical key, then I might lose it (because it's physical) and never get it back.

a big problem with passkeys is that there is a lot of flexibility in how it is rolled out with a given site or app. Some sites ask your browser for a passkey as soon as you hit the login page. Some sites you need to enter your username/email address first before you're prompted. Some sites a passkey satisfies both password + second factor. Some sites you need to enter your password and the passkey is the second factor. Some sites you don't need a password but do need the passkey + a second factor (usually SMS)

This is on top of the confusion around enrolling passkeys in your device and synchronizing them

I am a big passkeys fan, and use them on every service I can, but they leave a lot to be desired in terms of user experience. Not sure all of them are solvable, either. The platform vendor side can be fixed: vendors can better integrate with each other to make your passkeys available on every device. But, the issues with how they work across sites and applications is probably not solvable

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#296
I don't use passkeys because I can't tell if they're a one-way door. If I use it once, can I still use passwords to log in in the future?

I also don't understand how the system works when things go wrong (someone hacks your account, etc.). I don't even understand all the ways things could go wrong with passkeys.

Seeing the comments here makes me realize I'm not stupid or ignorant for not understanding these things. Some people do understand them much better than me, but there is no universal answer that emerges after sufficient study.

I will continue to stay away from passkeys.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#297
post #108

Earlier quoted context omitted.

>This is much, much simpler than you think it is. Passkeys are just passwords that require a password manager. The issue isn't what passkeys _are_ (e.g. explaining they are like public/private "ssh keys" and hoping that type of explanation ends the confusion). Instead, it's the workflow around passkeys. The websites show very confusing dialog popups and choices that a lot of normal people will not understand. This is…

So you're saying that if you're inside Apple's walled garden, it works really well! Hmm...

> So you're saying that if you're inside Apple's walled garden, it works really well! Hmm...

Or google. If you use android and chrome then it all just works.

But god help you if you want to use a password manager to keep everything in sync; I haven't yet found a way for a mobile app or web page to explicitly signal to the device that the passkey to be created should live in $password_manager and not whatever built-in/on-device key-store exists.

So I only really use pass keys for desktop/web things because that's the only place the "store/read from $password_manager" flow _works_.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#298

The website for my HSA required me to set up a passkey last time I logged in. I set it up on my work laptop and my work password manager, which means I can now no longer access my account from my personal computer. This is fantastic, just what I wanted

Are you also using HealthEquity for your HSA? I'm the same boat, they're forcing passkeys on me. I can still login using my employer's SSO but I've been putting off setting up the passkey until I have to.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#299
post #287
post #250

Earlier quoted context omitted.

In practice, because site owners know users are going to mess up having their passkeys on all devices, I've not seen any insist that a passkey _must_ be used, and you can always log in with your password (or worst case, email magic links) as a fallback. However, this negates the primary stated objective of passkeys, removing the possibility of users being phished, so I'm not sure how long that will remain the case ev…

> I've not seen any insist that a passkey _must_ be used, and you can always log in with your password (or worst case, email magic links) as a fallback. With the exception of Github, and banks.

Did you try it? That’s not correct. I just logged into GitHub with a password (+ 2FA), on an account that also has a passkey.

No major bank revokes your password when you setup a passkey, either.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#300

Earlier quoted context omitted.

I’ve just been operating under the assumption passkeys are gonna lock me out unrecoverably in some way at some point, and have been avoiding them for anything important while allowing them for low-value accounts so they’ll stop nagging me. I hate that I can’t just put a value in a plain text file somewhere (encrypted, let’s say, to preempt the inevitable and low-value response) and rely on that to work when I need it…

I avoid using them altogether for the same reason. I won't use them for low value accounts because it signals that I think they might be acceptable to eventually require for high value ones. And of course low value accounts have no value so I don't even care about phishing on most of those.

Haha, this thread has prompted me to follow some of the discussion about stupid bullshit like requiring "user is present" attestation and banning passkey programs (LOL wut?) if they lie about it, or resistance to allowing exports and portability.

I'm now on team "I am outright anti-passkeys and hope they fail and everyone pushing them cries a whole lot about it and never gets over it".

Post reply on HN