Live data from Hacker News

Passkeys were invented by engineers with zero understanding of consumer brain

twitter.com

431–440 of 813 posts

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#431
Okay, I'm a tech nerd I admit it, but for my personal authentication life I find passkeys to make sense.

All my passwords and SSH key are already in Bitwarden. When a site starts supporting passkeys, I add that to Bitwarden as well. Now, instead of logging in by auto-filling my username and password, I just press the passkey login button (that hopefully exists) and click on the Bitwarden popup to select the account. It's less button presses for me, and I cannot be phished, nor can my passkeys be leaked on the dark web. All thanks to some fancy cryptography.

Okay, sure, if someone steals my Bitwarden vault by snatching my laptop while it's unlocked or something, I end up pretty screwed. That security aspect did not change, so I still use TOTP for all important services.

Also, I've made one invite-only web app where single-use invite codes and passkeys are the only ways to log in. It was not too hard, it was fun, actually. And I get the peace of mind that account sharing is pretty much impossible were a bad actor able to get their hands on an invite, as is hacking other people's accounts.

(Okay, I concede that I've had to help multiple people who find passkeys confusing as a result of this whimsical decision, and that it just might be that nobody is using my web app for real. So I'm just speaking from nerd privilege here... But it works well, trust me!!)

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#432

Earlier quoted context omitted.

Passkeys do *not* do that. I use 1Password to manage my passkeys and they are all synced across all my authenticated devices where I installed 1Password.

You can choose either if your password manager supporte Passkeys

Of course. I was just pointing out that their claim about the lack of portability across devices was untrue.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#433

Earlier quoted context omitted.

> * and with device attestation, they could be banned at any moment by any website with no recourse.* Isn't this true of any authentication method? It doesn't seem unique to Passkeys.

Now that I think about it, you are right. But if they could ban my use of written passwords as easily as banning my use of a particular passkey device, why go through all the extra hoops to just be as vulnerable as before? This seems like a whole lot of extra work to do that gains me nothing.

I think it is important to explain why I and others are so reluctant to this.

In security, you identify reasonable threats. You can't protect against all of them, and some may even be contradictory.

When I get a call on my phone that says "Potential Spam", I have never even once in my life decided to run over to my list of passwords and hand them over to the President of the Spanish National Lottery. Not even once.

But on many, many occasions I have dealt with a simple system that was replaced by a more complicated one and something in that Rube Goldberg machine broke down and deprived me of access to money, email, even a parking permit to my office.

Passkeys seem to protect against the former case that has never happened to me, while increasing the chances of the latter that has happened way too often.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#434
post #63

Earlier quoted context omitted.

You do the same as you do when you lose your SSH key. Restore from backup and move on with your life. Why is there so much misinformation nonsense around passkeys?

How do you use a restored passkey from backup? Aren't they locked to the device?

I login to 1Password on another device and all passkeys are there, and usable.

The OSes I use where that works fine:

- Android - Windows - Linux - macOS - iOS

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#435
post #423

Earlier quoted context omitted.

I get your problem, i don't really accept it as valid. Passkeys were always supposed to be fungible. You have one in your iPhone, a different one on your desktop. A third in your significant other's phone. All stored in the hardware tpm equivalent. You can have 7 passkeys. You can have 14. The real failure of passkeys (emphasis on the s!) is that people think they must only have one.

I don't think that would work either. Let's say I have a new account and a single Passkey in the TPM of PC1. I want to log in from PC2, too. How can I do that? (I know there is some trickery with Bluetooth, but I haven't seen anything supporting it, and desktop PCs usually doesn't have Bluetooth connectivity.) AFAIK some browsers can do some magic to use a Passkey from your smartphone on a PC, but you need to log in…

You generate another passkey is your answer. How do you do that? The exact same way you do today. Why would you need to delete invalid passkeys? You wouldn't.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#436

It’s quite the opposite. Passkeys are phenomenal for a lot of consumers. Based on this thread, it’s the engineers who understand authentication in the first place and have their own system (eg password manager) that are confused. Consider a user in the Apple ecosystem: you are already conditioned to just do Touch ID or Face ID when asked. I was on Amazon the other day, it prompted randomly for “want to set up a passk…

> Passkeys are phenomenal for a lot of consumers.

It already falls apart for regular interactions like "Can you send me the Netflix password?"

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#437

Earlier quoted context omitted.

I get your problem, i don't really accept it as valid. Passkeys were always supposed to be fungible. You have one in your iPhone, a different one on your desktop. A third in your significant other's phone. All stored in the hardware tpm equivalent. You can have 7 passkeys. You can have 14. The real failure of passkeys (emphasis on the s!) is that people think they must only have one.

> [...] people think they must only have one. That's the real failure? I think the real failure is that people must have _more than one_. I thought so hard to add all my credentials to 1Password. Now people tell me I should use a Yubikey (or better two or three of them). What do you think, I'm going to register a couple of hundred accounts times three for something I already have (my password manager)? The real advan…

Again, I'm attracting people who fundamentally fail to grok passkeys . That's cool, but doesn't entitle you to anything

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#438

Earlier quoted context omitted.

I get your problem, i don't really accept it as valid. Passkeys were always supposed to be fungible. You have one in your iPhone, a different one on your desktop. A third in your significant other's phone. All stored in the hardware tpm equivalent. You can have 7 passkeys. You can have 14. The real failure of passkeys (emphasis on the s!) is that people think they must only have one.

Again, is this true for all major sites that support passkeys? And how do you set it up? My passwords are automatically synced between my devices, how to I achieve the same thing if I set up an account with a passkey?

Why would you take one passkey and move it between devices? Generate a new one. They're fungible. You set it ask to the exact same way you do today. It's not a problem.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#439

It’s quite the opposite. Passkeys are phenomenal for a lot of consumers. Based on this thread, it’s the engineers who understand authentication in the first place and have their own system (eg password manager) that are confused. Consider a user in the Apple ecosystem: you are already conditioned to just do Touch ID or Face ID when asked. I was on Amazon the other day, it prompted randomly for “want to set up a passk…

I refuse to be part of an "ecosystem".

KeepassXC is free, open source, and supports passkeys. You can locally store your encrypted password vault wherever you like, and transport it between devices using physical media if you like (or self host your own personal storage synchronization server and sync your passkeys between devices like that).

No need to be a part of an 'ecosystem' to use a password manager or passkeys.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#440
It seems to me like those who like passkeys/consider them simple are those who entrust all their credentials to proprietary cloud software vendors that sync them to all their devices.

Those of us who are not comfortable with that and want to keep our credentials offline and sync/backup them ourselves have questions about how the registration/backup/sharing flows work exactly.

I see this as part of a trend together with remote attestation, age verification, CSAM scanning, restricting sideloading, etc that will lead to most interactions over the internet only being allowed if big tech and/or government can verify the participants, the contents, and the hardware and software used.

Even among techies, many support these developments, so it is just a matter of time before we have no choice but to join the former group.

Post reply on HN