Live data from Hacker News

Passkeys were invented by engineers with zero understanding of consumer brain

twitter.com

471–480 of 813 posts

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#471
post #52

Earlier quoted context omitted.

> If I accidentally set up a passkey on my phone (let’s say I use Safari one day instead of my go-to, Brave), can I still log in without that passkey on other devices? N=1 and I'm sure I'm holding it wrong, but I can only log in to ADP to request PTO from my personal laptop because I set up an iCloud passkey, work laptop does not allow access to iCloud keychain, and you can't request PTO from mobile.

Although that's more a failure of your workplace's security policy than of the Passkey itself. It makes sense that the passkey doesn't work if you can't access the place the passkey is stored.

yeah but my problem is that I can't fall back to logging in to ADP with a password. Maybe there's some way to fix this? IDK.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#472

Earlier quoted context omitted.

A potentially good idea got corrupted by vendors, password managers, browsers, etc trying to assert control. I'm also an engineer and I find the UI around passkeys entirely unclear, but it doesn't have to be that way. It seems like everyone wants to be _the_ password manager for all your passkeys. They don't want to make it easy to understand that is what they are doing though, they just happily offer to "handle it f…

> It seems like everyone wants to be _the_ password manager for all your passkeys. Which defeats part of the point of passkeys in the first place in that they are supposed to be device-bound, the private key held in the TPM or secure enclave or whatever other security chip, mathematically non-exportable. Storing all your private keys in a cloud vault still leaves you exposed to potential credential theft if your vaul…

Seems like the flow should be:

1. All passwords stored in password manager. 2. Login with password manager when logging in for the first time on a device. 3. Combination of OS and site/app notice that no passkey has been created for this account and offers to create one. This is presented to the user as “setting up the current device for password-less log ins.” 4. OS negotiates with site/app to install the passkey and use it for future log ins on the device.

It’s presented to the user as a convenience clearly tied to this device.

…but you still have your text password stored in the password manager’s servers…

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#473
post #8

I do not know how to use a Passkey in a way that won’t impede how I log in to systems. I’ve been in tech for 26 years, and I understand the Public/private key behind what a Passkey is. Here’s what I don’t understand: I access a website through at least four different devices (my iPad, iPhone, Windows Desktop computer, and MacBook Pro) and three different browsers on each device (Brave, Firefox, Safari) , and I use La…

Notwithstanding the danger of having everything on a single platform, the Apple passkey works great. Sign into one and you’re signed in everywhere and you can share passwords with others.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#474

Earlier quoted context omitted.

Yes, this is exactly the problem. Multiple pieces of software vying to be your passkey provider, often using dark patterns so you don’t realize you’re making a choice, and not using the term “passkey” so people are using the technology without knowing what it is or how to research it. Kind of reflects the state of the web today, where every company wants to be your intermediary in every interaction, from making a pur…

> Multiple pieces of software vying to be your passkey provider, Which entirely defeats the point of using passkeys. There shouldn't be a passkey provider the "provider" is your device's TPM/secure enclave + your biometric challenge. They are supposed to be mathematically non-exportable, device-bound.

The anti-phising benefits are still very much there even if you sync them to pw manager. Yes it introduces single point of failure (pw manager), but at the same time you no longer need to go reset all your passwords to every service you use if you happen to lose that device. Tradeoffs.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#475
I'm probably not the only one to have a deep distrust in passkeys. I've deep-dived in to what they are and how they work and I think I can accept them on their technical merits, but I can't shake the feeling that the adoption has been way faster than we've been used to, for whatever reason. I think it was half a year between the settling down of the specification to being bombarded by a "Get a passkey!" from every goddamn website on this earth. I don't really see what the conspiracy to move the whole world to passkeys would be here, but it certainly feels like there is one.

I think my problem with passkeys is the same as with almost everything today: if I lose my phone, my digital life will be almost as difficult to recover as if I lost my ID and my birth certificate at the same time. Yes, that's why you don't create one passkey (phone), but maybe two or three (browsers), but that's mental load on myself -- I don't even try to explain that stuff to my parents, even something as (somewhat) easy to use as a password manager is out of their scope. Add TOTP and passkeys on top of that and you've got perfect security that no-one in their right minds is using. No idea how to resolve the problem, but it's not by shoving a solution down our throats with a vengeance.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#476
The thing that gets me is that to even use a Passkey I need a browser addon that syncs my entire password vault into browser memory, the same memory that all the adtech JS runs! No thank you! What a ridiculous system. I will continue copying and pasting passwords myself out of KeePassXC.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#477
post #8

I do not know how to use a Passkey in a way that won’t impede how I log in to systems. I’ve been in tech for 26 years, and I understand the Public/private key behind what a Passkey is. Here’s what I don’t understand: I access a website through at least four different devices (my iPad, iPhone, Windows Desktop computer, and MacBook Pro) and three different browsers on each device (Brave, Firefox, Safari) , and I use La…

This is much, much simpler than you think it is. Passkeys are just passwords that require a password manager. If you lose your passkey, you'll reset your passkey the same way you reset your password, probably with a "forgot my password" email. (But you're not going to lose it, because you use a password manager, and the passkey will be stored there and synchronized to all of your other devices.) The weird part is tha…

> This is much, much simpler than you think it is. Passkeys are just passwords that require a password manager

Cool. So can I write down my passkey on a piece of paper and put it in a safe?

> you'll reset your passkey the same way you reset your password, probably with a "forgot my password" email

Cool. But what if I lose the passkey to my email account?

> and the passkey will be stored there and synchronized to all of your other devices

Cool. Surely backups and synchronization never fails.

> The weird part is that password managers provide no way for you to copy and paste your passkeys

Uh oh. So you are saying passkeys are not like passwords? Last time I checked, every password manager lets me copy and paste my passwords just in case.

> To present a passkey, you have to use a password manager

Uh oh. So you are saying passkeys are not like passwords, like at all? Last time I checked, I can just type in my password using a keyboard on all websites I visit.

> This makes it impossible to copy and paste your passkey to the wrong person

Uh oh. So it means I can't just give my password to a family member sitting in the opposite side of the room? Sorry mom, corporate has decided that you are trying to trick me.

> Major password managers don’t even allow you to export your passkeys to a file that you can read/backup yourself

Uh oh. So is there a registry of Major League Password Managers that are guaranteed to implement Corporate Strength Cybersecurity Measurements? Will I be blocked by services if I happen to have landed on a minor password manager?

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#478

It’s quite the opposite. Passkeys are phenomenal for a lot of consumers. Based on this thread, it’s the engineers who understand authentication in the first place and have their own system (eg password manager) that are confused. Consider a user in the Apple ecosystem: you are already conditioned to just do Touch ID or Face ID when asked. I was on Amazon the other day, it prompted randomly for “want to set up a passk…

>"Consider a user in the Apple ecosystem"

Already you're off-base. Of course it works when your devices are homogenized, but very little folks work that way. Some people have a Windows computer using Brave, an iPhone using Safari, an Android device using Chrome, and a work computer with its own hardware/software limitations and partitions.

Of course it works when your ecosystems are not diversified. Problem is, most people are.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#479
post #280
post #60

Earlier quoted context omitted.

Exactly, I always refuse to add a passkey because I'm afraid I won't be able to easily login again. Also, I don't want to be locked in to a vendor.

use an open source password manager that supports them. as others mentioned, there's BitWarden (cross-platform, self-hostable), but if you want something simple there's KeePassXC (and you can put the store file on a dropbox shared folder)

I resent that I need a special app to "manage" them. I want to know where this key is on my filesystem so I can back it up and edit it myself, not have to use some app to access it. My ssh authorized_keys is just a text file. I can "manage" it with something as simple as vim. Maybe KeePassXC and BitWarden give you that simplicity, if so great!

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#480

Earlier quoted context omitted.

> Major password managers don’t even allow you to export your passkeys to a file that you can read/backup yourself That's a red flag to me. It's enough that phone backup systems go out of their way to prevent you from accessing your own data, too, for unexplained "sekhurity" reasons. > P.S. It's past time to move off of LastPass. LastPass lost all of your passwords again last month, just like they did in 2022. The mo…

Apple, Google, Microsoft, Mozilla, and 1Password don’t let you export passkeys to a file that you can read and backup, but Bitwarden, Proton Pass, and KeepassXC do. I think Bitwarden is on HN's current happy list. (I just use Apple iCloud myself.) Allowing passkeys to be exported to a plaintext file undermines the phishing protections, at least somewhat. It’s possible to trick you into exporting your passkeys from Bi…

[deleted]
Post reply on HN