Live data from Hacker News

Passkeys were invented by engineers with zero understanding of consumer brain

twitter.com

571–580 of 813 posts

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#571
post #298

Earlier quoted context omitted.

Are you also using HealthEquity for your HSA? I'm the same boat, they're forcing passkeys on me. I can still login using my employer's SSO but I've been putting off setting up the passkey until I have to.

yep

I've refused to set up an account. I just call them on the phone if I need something special from them, have them send paper statements, and eat the should-be-totally-illegal-because-of-how-obscenely-large-it-is "mail you a paper statement" fee.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#572

Earlier quoted context omitted.

> It seems like everyone wants to be _the_ password manager for all your passkeys. Which defeats part of the point of passkeys in the first place in that they are supposed to be device-bound, the private key held in the TPM or secure enclave or whatever other security chip, mathematically non-exportable. Storing all your private keys in a cloud vault still leaves you exposed to potential credential theft if your vaul…

I do not want my identity to be device-bound. I want it to be me-bound.

How do we verify that you are you? It can't be linked to fingerprints, iris scans, or DNA, as those are trivially leaked, impossible to change, and a privacy nightmare.

Until we find a way to securely implant a Yubikey in people's brains, it isn't going to happen.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#573

Earlier quoted context omitted.

> Instead, the password managers each have their own finicky app-to-app mechanism for transferring passkeys from one password manager to another. (I think all the password managers kinda like that lock in.) It's a nice simplifying step to talk about password managers here, but in the majority of the cases this won't be handled by a password manager, but rather by the device operating system, and the device manufactur…

All of the major operating systems and all of the major browsers are password managers. Apple, Google, Microsoft, and Mozilla are all password managers. They all have apps that let you access their password managers on other operating systems. You're right that all of the major password managers like their lock in. The Credential Exchange Protocol is just barely good enough that OS vendors can say they "support" it,…

> As for attestation, the good news is that Apple always returns 0s for the attestation ID (because Apple, like you, opposes it as a side channel), and so any public site/app that insists on attestation would reject all Apple devices.

The bad news is this could change.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#574

It’s quite the opposite. Passkeys are phenomenal for a lot of consumers. Based on this thread, it’s the engineers who understand authentication in the first place and have their own system (eg password manager) that are confused. Consider a user in the Apple ecosystem: you are already conditioned to just do Touch ID or Face ID when asked. I was on Amazon the other day, it prompted randomly for “want to set up a passk…

A password manager let's me use my service specific credential from any device, securely and decentralized. Passkeys lock into a specific device and seem easy until you need to use another device. But instead of being a credential you own and control, across what could even be a local password manager, it's one password to everything. Maybe it is more secure than a regular password in some cases but it largely seems…

You're arguing against a straw man.

All password managers support passkeys.

Both apple and google allow exporting your existing passkeys to third party password managers too.

Also each website gets it's own unique public key with passkeys. It isn't a single credential

You're literally arguing a strawman

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#575

Earlier quoted context omitted.

Replace the word passkey with password in your comment. What’s the benefit of passkeys again? If you’re not storing the actual private key in the Secure Enclave but only the “access to it” what’s changed from how Apple’s keychain already manages password syncing to iCloud? The only benefit (and it’s still a decent one) is that some random website breach can’t disclose your private key.

A random website breach can't disclose your password either, assuming you use random high-entropy passwords and the website only stores a hash of it. I haven't really seen the benefit to passkeys over passwords. Pretty much everyone is using a password management service that securely syncs both passwords and passkeys across devices. In that context I don't see the difference.

> Pretty much everyone is using a password management service

In the US, only about 34 to 36% of adults use a password manager. Of the ~64% that don't, an alarming 20% reuse the same password across almost every service, and a ton just rely on browser autofill.

If you use a password manager, you are in the minority. Hell, even if you don't use a PW manager and you at least use a different password for different services, you are ahead of most people.

The general population is largely computer illiterate, and have a staggering lack of basic security hygiene.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#576
post #37

FWIW: I find passkeys to be a very simple and easy to use concept. Simple: it's like a password that I don't have to type in Easy to use: because I use 1Password and just have it installed on everything. On Android, it can be set as the default passkey provider so, even on mobile, I am using passkeys shared across devices. Is this "less secure" because I'm sharing the keys through 1Password. I suppose, at some level.…

This. Honestly, most of the arguments I read against passkeys just sound like “old man yells at cloud.” It’s not that difficult. Spend 10 minutes researching the topic and you’re fine. Passkeys are so much more convenient than having to use passwords. When implemented right, it’s literally one click from opening the login page to being signed in. On all of my devices.

It's not difficult. It's undesired. It makes simple things slightly easier and makes difficult things impossible.

Exactly the sort of behavior that will suck in the unsophisticated user, and then leave them with no options when it fails.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#577

Earlier quoted context omitted.

KeepassXC is free, open source, and supports passkeys. You can locally store your encrypted password vault wherever you like, and transport it between devices using physical media if you like (or self host your own personal storage synchronization server and sync your passkeys between devices like that). No need to be a part of an 'ecosystem' to use a password manager or passkeys.

You can sync your vault between devices, but what's the point if the clients on those devices don't support passkeys? As far as I know, no KeePass app on Android has mature passkey support. That's not even mentioning more niche cases, like what if I want to log into a website in a browser on my TV? The cool thing about passwords is that they work on any device. Also, remember when one of the maintainers of the passke…

KeepassDX has pretty good passkey support I think. At least, it works for me.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#578
post #436

It’s quite the opposite. Passkeys are phenomenal for a lot of consumers. Based on this thread, it’s the engineers who understand authentication in the first place and have their own system (eg password manager) that are confused. Consider a user in the Apple ecosystem: you are already conditioned to just do Touch ID or Face ID when asked. I was on Amazon the other day, it prompted randomly for “want to set up a passk…

> Passkeys are phenomenal for a lot of consumers. It already falls apart for regular interactions like "Can you send me the Netflix password?"

At least on Apple devices you can share passkeys with contacts

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#579

Earlier quoted context omitted.

> In the worst case, banks actually don't make it very hard for seniors to reset your password/passkey; just show up at a branch with photo ID, your bank card, and your PIN, and a teller will help you reset your credentials. They do it all the time. Maybe... I just ran into an annoying scenario where the largest bank in Canada made an administrative error where they mislinked an account belonging to me to my wife's p…

> I went to a physical branch to get it fixed and was told that branches don't have that kind of ability so I'd have to call customer support. What are the branches even for if not customer support?

Sales. They are there to talk you into getting the premium mortgage.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#580

Earlier quoted context omitted.

I love that you wrote 6 paragraphs and linked to a medium post all without actually answering the question posed by the comment you replied to.

Yes, I did. When you set up a passkey on your phone in your password manager, you'll transfer it to your other device using your password manager. Either your password manager will automatically synchronize for you, or you can transfer your passkey to another password manager that will do the synchronization, via the finicky app-to-app transfer system (Credential Exchange Protocol). You can transfer from Apple to Bit…

> It’s up to you to decide whether protecting yourself from being tricked into exporting your passkeys is worth sacrificing your ability to read them.

Until a relying party uses attestation to decide this for you.

Post reply on HN