Live data from Hacker News

Passkeys were invented by engineers with zero understanding of consumer brain

twitter.com

561–570 of 813 posts

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#561

Earlier quoted context omitted.

> Which defeats part of the point of passkeys in the first place in that they are supposed to be device-bound If you watch the original Apple WWDC talk presenting passkeys, you will find that they were always intended to sync, at least for the consumer use-case. What you are describing is how the WebAuthn standard had been implemented by Yubico and Google up until the point of the introduction of “passkeys” by Apple.…

> the only possible way to compete with that UX is to sync the private key across the user’s devices This is my issue with passkeys. Either we lessen security to improve UX (syncing across devices implies extracting private keys from secure enclaves, at which point it’s no different to password syncing), or we have a proliferation of different keys per website across devices (assuming the website supports multiple pa…

> at which point it’s no different to password syncing

You still get the phishing resistance, though!

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#562

Earlier quoted context omitted.

People who say users should not be able to export keys are not confused. They believe users should not be able to export keys.

I was referring to confusion experienced by people new to the passkeys creating passkeys for the first time ("Where am I saving this to?", "How do I store this in my password manager?").

dotancohen would not be allowed to store Passkeys private keys in a Keepass database in the case thewebguyd specified. Relying parties would block password managers which allowed this.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#563
post #280

Earlier quoted context omitted.

use an open source password manager that supports them. as others mentioned, there's BitWarden (cross-platform, self-hostable), but if you want something simple there's KeePassXC (and you can put the store file on a dropbox shared folder)

The cabal of evil behind the passkey project actively have KeePassXC on their naughty list fore deigning to allow users to access their keys, and specifically included in the standard the means to discriminate between different passkey vault providers. It is the opposite of an open system, and cannot, under any circumstances, be trusted. Do not use passkeys, tell other people not to use passkeys, and make sure to not…

This is hard to understand without any references. Can you please share a relevant link or two?

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#564

Earlier quoted context omitted.

This is why you should use physical tokens like Yubikey. But don’t log in to important accounts on a public computer, like ever, unless it’s a dire emergency.

You can decide what appetite for risk you are comfortable with, but some people don't have any better option than logging in to accounts on a public computer. The industry is pushing this system as the new universal answer for authentication, it NEEDS to work in every scenario passwords do. (...and I’m pretty sure plugging my yubikey into a locked down public terminal is not going to solve this, either.)

It would let you log in (even though you shouldn’t). Most “locked down” computers still allow things like USB drives and Yubikeys.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#565

Earlier quoted context omitted.

By still having the password the user can still be attacked via phishing

The user can always be attacked via phishing so long as account recovery methods exist (and they need to exist for obvious reasons). Use passkeys, but so long as you can also log in via password, or SMS code, etc., it's phishable, you can get sim swapped. Your master password to your cloud PW manager's vault is also phishable (hence why passkeys were ideally device specific, non-exportable). Its phishing resistant no…

> hence why passkeys were ideally device specific, non-exportable

Not true. The original concept was always for them to be cloud synced.

This has nothing to do with their anti-phishing capabilities. The anti-phishing capabilities come from the fact that the password manager authenticates the application before handing out the passkey. It doesn’t matter if they are synced across devices or not.

You are correct that other login methods might be weaker than passkeys. I’m not sure how that’s related to passkeys though. In real security sensitive applications the recovery process is “go to the bank’s branch and show them your driver’s license”.

> Your master password to your cloud PW manager's vault is also phishable

No, it’s not. You would need to steal my yubikey to get access.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#566
post #108

Earlier quoted context omitted.

>This is much, much simpler than you think it is. Passkeys are just passwords that require a password manager. The issue isn't what passkeys _are_ (e.g. explaining they are like public/private "ssh keys" and hoping that type of explanation ends the confusion). Instead, it's the workflow around passkeys. The websites show very confusing dialog popups and choices that a lot of normal people will not understand. This is…

You're agreeing precisely with the parent commenter that passkeys are, from a user's perspective, just passwords that require the use of a password manager. The difficulties many people have understanding or using passkeys are valid to point out and criticize, but they're precisely the same difficulties people have moving from the paradigm of "memorizing or writing down all my passwords" to "using a password manager.…

> they're precisely the same difficulties people have moving from the paradigm of "memorizing or writing down all my passwords" to "using a password manager."

Errr, no.

You can transfer a password from one manager to another. Those very same password managers won't let you transfer a passkey they hold.

And if you know the password, you can use it anywhere by just typing it in - no complex technology or protocols involved. But using a passkey involves your secure computer talking to another computer, using a complex protocol that can't go via eyeballs and fingers. If you don't have a way to connect the device holding the passkey to the computer wanting your id - say your USB A Yubikey isn't recognised by your phone, then you are out of luck - you can't use that passkey, even though it's sitting in your hand.

And you can't work around that by copying the passkey to a device that can communicate with the service you're using, because you aren't allowed to copy.

It's an unworkable mess. The mess is not created by passkeys themselves, because, as others have said elsewhere the protocol is pure elegance. The mess is created by vendors choosing lock in over transportability. I'm hoping it's a passing phase.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#567
I can't believe these comments - passkeys are pretty easy to understand and most platforms allow you to add multiple. Not enough for truly one-passkey-per-device, but if you use a password manager that syncs passkeys, or hardware passkeys it's fine - it's easy, quick, and more secure than any password can ever be (mitm resistant).

I think the confusion with passkeys comes from that fact that everyone wants to own you so you have to be mindful if this passkey is being stored on the OS, the browser, sync'd between devices through google or apple, etc.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#568
post #548

I’m absolutely floored by some of what I am reading here. Six months before passkeys rolled out there were numerous succinct consumer-friendly write-ups. I sent at least one of these to several non-technical people I knew and they had no problem understanding the benefit and moving to using them where available once they started rolling out.

Would be helpful if you provided at least 1 example

https://www.aarp.org/personal-technology/passkeys-future/

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#569

Earlier quoted context omitted.

By still having the password the user can still be attacked via phishing

The user can always be attacked via phishing so long as account recovery methods exist (and they need to exist for obvious reasons). Use passkeys, but so long as you can also log in via password, or SMS code, etc., it's phishable, you can get sim swapped. Your master password to your cloud PW manager's vault is also phishable (hence why passkeys were ideally device specific, non-exportable). Its phishing resistant no…

Yeah, but it's an order-of-magnitude more complicated. It's no longer "click a link and fill in your creds on a legit-looking website", it turns into "hack someone's email, request a password reset, wait the mandatory 24 hours, do a social attack on the provider to pull off a sim swap, and fill in the 2FA code".

> Your master password to your cloud PW manager's vault is also phishable

... which is why all sensible cloud vaults have a separate enrollment key, requiring an explicit action to grant a new device access.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#570

Earlier quoted context omitted.

> It seems like everyone wants to be _the_ password manager for all your passkeys. Which defeats part of the point of passkeys in the first place in that they are supposed to be device-bound, the private key held in the TPM or secure enclave or whatever other security chip, mathematically non-exportable. Storing all your private keys in a cloud vault still leaves you exposed to potential credential theft if your vaul…

Device-bound would be a nightmare. I don’t want to have to think about different credential for phone vs. laptop, etc.

Easy: it's the token on your physical keyring, right next to your house key and car key.
Post reply on HN