Live data from Hacker News

Passkeys were invented by engineers with zero understanding of consumer brain

twitter.com

421–430 of 813 posts

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#421
post #377

Earlier quoted context omitted.

This is the main reason I've avoided passkeys. I have these exact questions and there's no a clear explanation given for these. I don't want to lose access to important accounts.

If you use something like 1Password it's very easy. It stores your Passkey and it syncs cross device. It's another thing but once it's set up it's less of a pain than using authenticator apps or having to find some random iPad that Google popped up an approval prompt on.

This is how I use them but you have to admit that this assumes 3-4 things about a user just to save them the hassle of supplying two factors at login time. It's also unclear to users if passkeys can be migrated from one password manager to another

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#422

Earlier quoted context omitted.

Citation needed. Walk in with photo ID, a bank card, and your PIN, and all the major banks will send you a reset-password email.

I went to my bank with all my ID and my bank card, talked to the teller and was told to call a support line. One of my parents went through the same thing. I don't have a citation for you just recent experience, do you have a citation?

Switch to a better bank.

My credit union has people who can help with any online banking/website login issues. They aren't tellers, but they are there. You just need to ask to speak to a customer service rep.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#423
post #8

I do not know how to use a Passkey in a way that won’t impede how I log in to systems. I’ve been in tech for 26 years, and I understand the Public/private key behind what a Passkey is. Here’s what I don’t understand: I access a website through at least four different devices (my iPad, iPhone, Windows Desktop computer, and MacBook Pro) and three different browsers on each device (Brave, Firefox, Safari) , and I use La…

I get your problem, i don't really accept it as valid. Passkeys were always supposed to be fungible. You have one in your iPhone, a different one on your desktop. A third in your significant other's phone. All stored in the hardware tpm equivalent. You can have 7 passkeys. You can have 14. The real failure of passkeys (emphasis on the s!) is that people think they must only have one.

I don't think that would work either.

Let's say I have a new account and a single Passkey in the TPM of PC1. I want to log in from PC2, too. How can I do that? (I know there is some trickery with Bluetooth, but I haven't seen anything supporting it, and desktop PCs usually doesn't have Bluetooth connectivity.)

AFAIK some browsers can do some magic to use a Passkey from your smartphone on a PC, but you need to log in to the same browser-sync account from both device (which brings back us to the same issue).

Also the whole thing becomes a mess when you change devices. You need to log into all the services you have ever used to delete the Passkeys from devices you no longer have, and you need to add a new passkey from a new device you bought to all the services you use.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#424

Earlier quoted context omitted.

> Major password managers don’t even allow you to export your passkeys to a file that you can read/backup yourself That's a red flag to me. It's enough that phone backup systems go out of their way to prevent you from accessing your own data, too, for unexplained "sekhurity" reasons. > P.S. It's past time to move off of LastPass. LastPass lost all of your passwords again last month, just like they did in 2022. The mo…

Depends on what qualifies as a password "manager", but I've been using pass ( https://www.passwordstore.org/ ) for years on multiple desktops, and have recently added iOS app sepass to my setup ( https://sepass.modiot.com/ ). Quite complicated to get it all setup (definitely not for non-technical users), but both are GPL and I now have all my passwords available with hardware protection (yubikey on desktop, secure en…

It doesn't even have to be something as bare-bones as pass. You can have a full-fledged password manager that is open-source and local-first. KeepassXC (and the OG Keepass) were always OSS and local-first. The original version of Keepass 1.0 for Windows was released long before Lastpass or 1Password[1], so we had an open-source local-first password manager before we had commercial cloud-based managers.

[1] To be more accurate, although it was always proprietary, 1Password was also local-only at first, with syncing only supported by putting it on something like Dropbox. They only added native cloud syncing later and eventually made it cloud-first.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#425
post #21

Earlier quoted context omitted.

Same here, also what if I lose the device? I can safely write down a password on a piece of paper and keep it somewhere phyisically safe. Passkeys and 2FA are a usability nightmare if you need to recover, or all the security vanishes if you put usable recovery mechanisms for the passkey or the second factor.

>Passkeys and 2FA are a usability nightmare if you need to recover, or all the security vanishes if you put usable recovery mechanisms for the passkey or the second factor. Most providers continue to offer email-based recovery in the case that the end-user loses access to their primary factor, regardless of whether the primary factor is a password or a passkey. And email based account recovery does not make the secur…

That doesn't really explain if I can use said website on my phone with a password if I login with a passkey on my computer

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#426
post #92
post #58

Earlier quoted context omitted.

What are you talking about? I can literally export all that data to another OS or password manager. Takes a whopping single click.

Only to other proprietary systems within the FIDO Alliance that you don't own or control. Additionally passkeys allow services to detect and ban specific password managers, so have fun when the only approved managers that works consistently across all services are Google/Apple/Microsoft. There is already a list of "bad" clients here https://passkeys.dev/docs/reference/known-issues/

Again, what are you taking about? There are open source implementations available. I can write my own. They do work. This list just shows some which do not actually implement the spec correctly.

Also moving the goalpost. The post I replied to said I couldn’t export it. I absolutely can, and have, with a single click. To another provider. It’s really not a big deal.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#427

Earlier quoted context omitted.

A potentially good idea got corrupted by vendors, password managers, browsers, etc trying to assert control. I'm also an engineer and I find the UI around passkeys entirely unclear, but it doesn't have to be that way. It seems like everyone wants to be _the_ password manager for all your passkeys. They don't want to make it easy to understand that is what they are doing though, they just happily offer to "handle it f…

> It seems like everyone wants to be _the_ password manager for all your passkeys. Which defeats part of the point of passkeys in the first place in that they are supposed to be device-bound, the private key held in the TPM or secure enclave or whatever other security chip, mathematically non-exportable. Storing all your private keys in a cloud vault still leaves you exposed to potential credential theft if your vaul…

Device-bound would be a nightmare. I don’t want to have to think about different credential for phone vs. laptop, etc.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#428
post #58

Earlier quoted context omitted.

What are you talking about? I can literally export all that data to another OS or password manager. Takes a whopping single click.

I didn't realize this was supported, I'm kind of favoring Apple's Passwords app since you can lockdown your account and they are very on top of someone accessing anything of yours. Any time I power on an iPad I havent used for months they tell me a new device can read my texts type of thing, which is a nice paper trail.

Yes me too. And it works great. I do make a backup of it to another provider once in a while though, just in case.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#429
post #8

I do not know how to use a Passkey in a way that won’t impede how I log in to systems. I’ve been in tech for 26 years, and I understand the Public/private key behind what a Passkey is. Here’s what I don’t understand: I access a website through at least four different devices (my iPad, iPhone, Windows Desktop computer, and MacBook Pro) and three different browsers on each device (Brave, Firefox, Safari) , and I use La…

Same. I'm a tech professional, and I don't set up passkeys for similar reasons. I log in to online services from a lot of different devices and browsers. I use a password manager but the keys to the kingdom (my email password) exists only in my head.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#430

It’s quite the opposite. Passkeys are phenomenal for a lot of consumers. Based on this thread, it’s the engineers who understand authentication in the first place and have their own system (eg password manager) that are confused. Consider a user in the Apple ecosystem: you are already conditioned to just do Touch ID or Face ID when asked. I was on Amazon the other day, it prompted randomly for “want to set up a passk…

A password manager let's me use my service specific credential from any device, securely and decentralized. Passkeys lock into a specific device and seem easy until you need to use another device. But instead of being a credential you own and control, across what could even be a local password manager, it's one password to everything. Maybe it is more secure than a regular password in some cases but it largely seems…

    it's one password to everything
You are entirely mistaken. Passkeys involve a third party storing a public key on their infrastructure, while you hold the private half of the key, somewhere.

Passkeys are never reused. Even for the same person, they are always unique across websites, and across devices.

Post reply on HN