Live data from Hacker News

Passkeys were invented by engineers with zero understanding of consumer brain

twitter.com

381–390 of 813 posts

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#381
post #363

Earlier quoted context omitted.

Did you try it? That’s not correct. I just logged into GitHub with a password (+ 2FA), on an account that also has a passkey. No major bank revokes your password when you setup a passkey, either.

Is "passkey" only supposed to mean devices that implement specifically U2F, WebAuthn, etc.? I would have thought TOTP and challenge-response hardware tokens to count, including cellphones with apps that implement such. As to > No major bank revokes your password when you setup a passkey, either. If we're talking about requiring 2FA via TOTP or challenge-response hardware tokens or banking apps implementing such, that…

"Passkey" refers to a very specific authentication method. TOTP, etc., don't count.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#382

Earlier quoted context omitted.

I am an engineer and have some insights on the discussions and developments around it. ITS NOT SIMPLE AT ALL 1. The idea was to provide a phishing resistant authentication method for enterprise users (companies loose quite a lot of money to phishing). 2. Majority of industry players shared the vision of a credential which is available across the platforms and browsers 3. The vision for collaboration never materialize…

It should have never been a cloud password manager play. It should be hardware device only, and tied to the device. One passkey on each hardware device.

Then I wouldn't use it, and I would probably stop using services that tried to push me in to it.

I use multiple devices and I want to log in to things using only my master password. I also want to be able to back up my credentials to local encrypted storage so I can restore them if my password manager service provider stops operating or becomes untenable.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#383

Earlier quoted context omitted.

I don't think you're giving those seniors good advice. When the banks ask people to "switch" to passkeys, they're not removing the passwords; they're adding passkeys as an alternate login mechanism. If you lose your bank passkey, (e.g. if you put it in the wrong password manager and you can't figure out where it is) you can just sign in with your bank password. In the worst case, banks actually don't make it very har…

> In the worst case, banks actually don't make it very hard for seniors to reset your password/passkey; just show up at a branch with photo ID, your bank card, and your PIN, and a teller will help you reset your credentials. They do it all the time. Maybe... I just ran into an annoying scenario where the largest bank in Canada made an administrative error where they mislinked an account belonging to me to my wife's p…

[dead]

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#384
post #79

Earlier quoted context omitted.

(I might be wrong, please correct me if I am) What I'm gathering from this page is that the Passkey spec can specify whether the app handling the passkey should prompt the user for biometric scan, PIN code, etc. but some apps simply ignore that flag. This makes sense though. I've already logged into my password manager and it hasn't timed out yet, so why would my password manager prompt me again? I'm glad that they d…

Your understanding is correct and I agree with you. The Passkey spec authors, however, think services should be allowed to ban your client for behaving this way: > [When UV is required, KeePassXC must request user verification or not handle the request] > This implementation is not spec compliant and has the potential to be blocked by relying parties. https://github.com/keepassxreboot/keepassxc/issues/10406

> > This implementation is not spec compliant and has the potential to be blocked by relying parties.

The only conclusion I can come to when it comes to this and the earlier kerfuffle regarding being able to export the plain text of passkeys is 'the spec is bad and you should feel bad'.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#386
post #280
post #60

Earlier quoted context omitted.

Exactly, I always refuse to add a passkey because I'm afraid I won't be able to easily login again. Also, I don't want to be locked in to a vendor.

use an open source password manager that supports them. as others mentioned, there's BitWarden (cross-platform, self-hostable), but if you want something simple there's KeePassXC (and you can put the store file on a dropbox shared folder)

The cabal of evil behind the passkey project actively have KeePassXC on their naughty list fore deigning to allow users to access their keys, and specifically included in the standard the means to discriminate between different passkey vault providers. It is the opposite of an open system, and cannot, under any circumstances, be trusted. Do not use passkeys, tell other people not to use passkeys, and make sure to not let shills astroturf conversations about passkeys unopposed.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#387
post #298

The website for my HSA required me to set up a passkey last time I logged in. I set it up on my work laptop and my work password manager, which means I can now no longer access my account from my personal computer. This is fantastic, just what I wanted

Are you also using HealthEquity for your HSA? I'm the same boat, they're forcing passkeys on me. I can still login using my employer's SSO but I've been putting off setting up the passkey until I have to.

yep

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#388
post #5

It just so happened that Microsoft sent an email today to our M365 tenant administrators that SMS and voice for 2FA is being removed 1-Feb-2027 and that automatic enrollment to passkeys starts 1-Sep-2026. Bring on the passkey overlords. Although, LLMs say that passkeys are superior to passwords since it includes a public/private key setup with the private key saved to a device that requires a PIN or biometric to acce…

That's if you're using Authenticator.

The use of a passkey doesn’t require Authenticator or other OTP app. Gemini said that an OTP app can be used as a vault for the passkey, but it’s not the mechanism that permits the check of the private key. Rather, that’s the PIN or biometric. Now, perhaps I don’t understand your statement and you can clarify if that’s the case.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#389
post #134

Earlier quoted context omitted.

Master password to password vault stored on metal, buried in my backyard and I tell a family member where it is in case I ever get brain damage

Family member gossips "that crazy [deejaaymac] always burying secrets in the backyard..." Or straight up betrays you (you slighted them at some family event)

If you marry someone you don’t trust, you’re going to have a lot more problems than password compromise.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#390
post #67
post #37

FWIW: I find passkeys to be a very simple and easy to use concept. Simple: it's like a password that I don't have to type in Easy to use: because I use 1Password and just have it installed on everything. On Android, it can be set as the default passkey provider so, even on mobile, I am using passkeys shared across devices. Is this "less secure" because I'm sharing the keys through 1Password. I suppose, at some level.…

OK now say you're on a work/library/friend's computer and you want to look up an account in 1password on your phone so you can type in the password. Passkeys don't support this very basic and common workflow. Meanwhile there's no real security benefit over password manager generated complex and not reused passwords.

This is why you should use physical tokens like Yubikey.

But don’t log in to important accounts on a public computer, like ever, unless it’s a dire emergency.

Post reply on HN