Earlier quoted context omitted.
> I would have thought TOTP and challenge-response hardware tokens to count Those are absolutely not passkeys. Passkeys are just WebAuthn (from what i can tell).
Such a generic word. I imagine there are tons of CLI utilities out there with a --passkey option that refer to simply files with a key inside. Kind of crazy that it's being used to mean specifically devices that implement a specific protocol. Kind of feels like "crypto is a type of currency and not all cryptography", or "SQL Server is a specific product of Microsoft". Wonder if how it happened this time was people re…
Passkeys were invented by engineers with zero understanding of consumer brain
451–460 of 813 posts
Re: Passkeys were invented by engineers with zero understanding of consumer brain
#452Earlier quoted context omitted.
> What are the branches even for if not customer support? Lots of physical locations make the bank seem big/safe/reputable. Beyond that, it's sales and a place to have ATMs. I have sometimes been able to get a replacement card issued at a branch instead of waiting for one to show up in the mail. Some branches will accommodate special requests like "can I withdraw $200... in two dollar bills" / take coin deposits but…
My local branch has had a sign on the front door "our coin counter is broken, sorry for the inconvenience" for the past 6 months. I refuse to believe they don't have a working coin counter in a bank branch; they just don't want customers bringing in a big jars of coins.
Re: Passkeys were invented by engineers with zero understanding of consumer brain
#453Earlier quoted context omitted.
>I haven't yet found a way for a mobile app or web page to explicitly signal to the device that the passkey to be created should live in $password_manager and not whatever built-in/on-device key-store exists. On Android 17 (on Pixel) you can select the password service under Settings -> Passwords and passkeys -> Preferred service. If you have an alternative password manager installed, it will be listed there along wi…
> On Android 17 (on Pixel) you can select the password service under Settings -> Passwords and passkeys -> Preferred service. I have this set to my password manager but I still can't _use_ the pass-keys in my password manager to sign in to most apps.
Setting your preferred password/passkey manager on Android 17 to 1Password works fine in Chrome and Firefox to log in to any site, presenting passkeys managed in 1Password. It also works in all of Meta's native apps. (I'm pretty sure it works the same in Bitwarden.)
Whatever issue you're having, it's not an inherent limitation of Android passkeys. It might be a bug in your passkey manager…?
Re: Passkeys were invented by engineers with zero understanding of consumer brain
#454I do not know how to use a Passkey in a way that won’t impede how I log in to systems. I’ve been in tech for 26 years, and I understand the Public/private key behind what a Passkey is. Here’s what I don’t understand: I access a website through at least four different devices (my iPad, iPhone, Windows Desktop computer, and MacBook Pro) and three different browsers on each device (Brave, Firefox, Safari) , and I use La…
Re: Passkeys were invented by engineers with zero understanding of consumer brain
#455I recently logged into my CVS.com account after not touching it for years, and I couldn't find the password reset..... turns out they no longer use passwords at all; only Passkeys and tokens via email/SMS. Aside from email accounts potentially being compromised or SMS interception, this is honestly the way all sites should be going now. But more seriously, there should be a way to use only Passkeys with a backup iden…
Re: Passkeys were invented by engineers with zero understanding of consumer brain
#456Earlier quoted context omitted.
I use a passkey with discord on my phone. If I want to log in to discord on a computer it shows a QR code on the page/desktop app and I scan it with my phone to log in. I could see this become a pretty common pattern. I like it because I can use discord on even a pretty untrusted computer without providing it any credentials or access to my passkey, and then later when I'm done I can revoke the session.
so you need to have discord installed in your phone. now multiply it with every web site you want to access.
Re: Passkeys were invented by engineers with zero understanding of consumer brain
#457It’s quite the opposite. Passkeys are phenomenal for a lot of consumers. Based on this thread, it’s the engineers who understand authentication in the first place and have their own system (eg password manager) that are confused. Consider a user in the Apple ecosystem: you are already conditioned to just do Touch ID or Face ID when asked. I was on Amazon the other day, it prompted randomly for “want to set up a passk…
I refuse to be part of an "ecosystem".
Re: Passkeys were invented by engineers with zero understanding of consumer brain
#458Earlier quoted context omitted.
> Edit: One final consideration, my spouse and I share user/name passwords for some things (notably Pandora and our Amazon Prime account) since they don’t handle things like family logins well; how do both my wife and I use amazon or Pandora with passkeys? Do we each set up passkeys? How do I get her Pass if that’s not an option? Lets say it is a android phone. Open amazon app. login in the usual user/password + 2FA…
Thanks. One glaring issue I see is that right now police can’t ask you for your password in the USA (a violation of the right against self-incrimination). They can however get a search warrant for your device and your biometrics, and wouldn’t need your password if they can gain access through your pass key.
Re: Passkeys were invented by engineers with zero understanding of consumer brain
#459Earlier quoted context omitted.
This is the main reason I've avoided passkeys. I have these exact questions and there's no a clear explanation given for these. I don't want to lose access to important accounts.
> there's no a clear explanation there's. it depends on how the site implemented passkeys. I'm using multiple devices and passkeys via keepassXC. I haven't lost access or even got locked out of any accounts. but it's like 2FA, and almost all sites have a clean fallback (backup codes) for 2FA.