Earlier quoted context omitted.
Did you try it? That’s not correct. I just logged into GitHub with a password (+ 2FA), on an account that also has a passkey. No major bank revokes your password when you setup a passkey, either.
Is "passkey" only supposed to mean devices that implement specifically U2F, WebAuthn, etc.? I would have thought TOTP and challenge-response hardware tokens to count, including cellphones with apps that implement such. As to > No major bank revokes your password when you setup a passkey, either. If we're talking about requiring 2FA via TOTP or challenge-response hardware tokens or banking apps implementing such, that…
Passkeys were invented by engineers with zero understanding of consumer brain
381–390 of 813 posts
Re: Passkeys were invented by engineers with zero understanding of consumer brain
#382Earlier quoted context omitted.
I am an engineer and have some insights on the discussions and developments around it. ITS NOT SIMPLE AT ALL 1. The idea was to provide a phishing resistant authentication method for enterprise users (companies loose quite a lot of money to phishing). 2. Majority of industry players shared the vision of a credential which is available across the platforms and browsers 3. The vision for collaboration never materialize…
It should have never been a cloud password manager play. It should be hardware device only, and tied to the device. One passkey on each hardware device.
I use multiple devices and I want to log in to things using only my master password. I also want to be able to back up my credentials to local encrypted storage so I can restore them if my password manager service provider stops operating or becomes untenable.
Re: Passkeys were invented by engineers with zero understanding of consumer brain
#383Earlier quoted context omitted.
I don't think you're giving those seniors good advice. When the banks ask people to "switch" to passkeys, they're not removing the passwords; they're adding passkeys as an alternate login mechanism. If you lose your bank passkey, (e.g. if you put it in the wrong password manager and you can't figure out where it is) you can just sign in with your bank password. In the worst case, banks actually don't make it very har…
> In the worst case, banks actually don't make it very hard for seniors to reset your password/passkey; just show up at a branch with photo ID, your bank card, and your PIN, and a teller will help you reset your credentials. They do it all the time. Maybe... I just ran into an annoying scenario where the largest bank in Canada made an administrative error where they mislinked an account belonging to me to my wife's p…
Re: Passkeys were invented by engineers with zero understanding of consumer brain
#384Earlier quoted context omitted.
(I might be wrong, please correct me if I am) What I'm gathering from this page is that the Passkey spec can specify whether the app handling the passkey should prompt the user for biometric scan, PIN code, etc. but some apps simply ignore that flag. This makes sense though. I've already logged into my password manager and it hasn't timed out yet, so why would my password manager prompt me again? I'm glad that they d…
Your understanding is correct and I agree with you. The Passkey spec authors, however, think services should be allowed to ban your client for behaving this way: > [When UV is required, KeePassXC must request user verification or not handle the request] > This implementation is not spec compliant and has the potential to be blocked by relying parties. https://github.com/keepassxreboot/keepassxc/issues/10406
The only conclusion I can come to when it comes to this and the earlier kerfuffle regarding being able to export the plain text of passkeys is 'the spec is bad and you should feel bad'.
Re: Passkeys were invented by engineers with zero understanding of consumer brain
#385Re: Passkeys were invented by engineers with zero understanding of consumer brain
#386Earlier quoted context omitted.
Exactly, I always refuse to add a passkey because I'm afraid I won't be able to easily login again. Also, I don't want to be locked in to a vendor.
use an open source password manager that supports them. as others mentioned, there's BitWarden (cross-platform, self-hostable), but if you want something simple there's KeePassXC (and you can put the store file on a dropbox shared folder)
Re: Passkeys were invented by engineers with zero understanding of consumer brain
#387The website for my HSA required me to set up a passkey last time I logged in. I set it up on my work laptop and my work password manager, which means I can now no longer access my account from my personal computer. This is fantastic, just what I wanted
Are you also using HealthEquity for your HSA? I'm the same boat, they're forcing passkeys on me. I can still login using my employer's SSO but I've been putting off setting up the passkey until I have to.
Re: Passkeys were invented by engineers with zero understanding of consumer brain
#388It just so happened that Microsoft sent an email today to our M365 tenant administrators that SMS and voice for 2FA is being removed 1-Feb-2027 and that automatic enrollment to passkeys starts 1-Sep-2026. Bring on the passkey overlords. Although, LLMs say that passkeys are superior to passwords since it includes a public/private key setup with the private key saved to a device that requires a PIN or biometric to acce…
That's if you're using Authenticator.
Re: Passkeys were invented by engineers with zero understanding of consumer brain
#389Earlier quoted context omitted.
Master password to password vault stored on metal, buried in my backyard and I tell a family member where it is in case I ever get brain damage
Family member gossips "that crazy [deejaaymac] always burying secrets in the backyard..." Or straight up betrays you (you slighted them at some family event)
Re: Passkeys were invented by engineers with zero understanding of consumer brain
#390FWIW: I find passkeys to be a very simple and easy to use concept. Simple: it's like a password that I don't have to type in Easy to use: because I use 1Password and just have it installed on everything. On Android, it can be set as the default passkey provider so, even on mobile, I am using passkeys shared across devices. Is this "less secure" because I'm sharing the keys through 1Password. I suppose, at some level.…
OK now say you're on a work/library/friend's computer and you want to look up an account in 1password on your phone so you can type in the password. Passkeys don't support this very basic and common workflow. Meanwhile there's no real security benefit over password manager generated complex and not reused passwords.
But don’t log in to important accounts on a public computer, like ever, unless it’s a dire emergency.