Live data from Hacker News

Passkeys were invented by engineers with zero understanding of consumer brain

twitter.com

661–670 of 813 posts

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#661
I always think back to my grandmother in the '90s. When her old black-and-white TV stopped working, we bought her a new color TV with a remote control. A few weeks later I saw that she had taped over the buttons, leaving only the power button exposed so she wouldn't mess anything up accidentally. I've been programming for 40 years, but even I struggle to grasp sometimes what goes where and why - so what is someone with zero coding background supposed to make of it? I sometimes talk about tech stuff - internet, cookies, security - with my hairdresser, and she just listens with wide eyes. I'm convinced most people have no idea what they're actually doing with their devices, and that's on us developers. It's our job to tailor systems to users by serving them with our knowledge, not confusing them with it. I doubt anyone wants to mess with the ECU settings on their car's dashboard - they just want to press the gas pedal, because that actually makes sense.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#662

Earlier quoted context omitted.

"A better version of password syncing" is exactly what Passkeys are and ought to be. Just like passwords, but unphishable, unguessable, not reusable across sites, not vulnerable to data breaches, and with better UX. Stranding private keys in clone resistant secure enclaves has unacceptably bad UX for the average user, which is why very few implementations try to do that.

So just a password manager?

Passwords are still significantly less secure than passkeys even when using a password manager.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#663
post #402

Earlier quoted context omitted.

> Edit: One final consideration, my spouse and I share user/name passwords for some things (notably Pandora and our Amazon Prime account) since they don’t handle things like family logins well; how do both my wife and I use amazon or Pandora with passkeys? Do we each set up passkeys? How do I get her Pass if that’s not an option? Lets say it is a android phone. Open amazon app. login in the usual user/password + 2FA…

Thanks. One glaring issue I see is that right now police can’t ask you for your password in the USA (a violation of the right against self-incrimination). They can however get a search warrant for your device and your biometrics, and wouldn’t need your password if they can gain access through your pass key.

> wouldn’t need your password if t

Once you talk about privacy/security then - I am not even sure you should do it here in HN - a bastion for encouraging Silicon valley practices.

In principle, you can remove biometrics and still use passkey (by using phone password only).

If you see my text, I wrote clearly - passkeys are great convenience + security - For the majority. People don't need to waste time in searching login names.

TBH, I was in a few Free Software Foundation Europe and linux conferences in the last year - in my view - at least half of them were using - passkey with iPhone or Android (including Playservices). So people have accepted the reality.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#664
post #653
post #561

Earlier quoted context omitted.

> at which point it’s no different to password syncing You still get the phishing resistance, though!

Password managers prevent phishing as they check for the domain name before inputing the password.

Password managers do not architecturally, cryptographically make phishing impossible. Ultimately a user can still be tricked to copy/paste their passwords into fake websites, even when using a password manager. You could blame end-users for this behavior, but attackers don't care about blame. Ultimately, it doesn't matter who's at fault when there are massive phishing attacks happening at scale every single hour of every day. The only real solution to solve this problem for the entire internet is to make credentials architecturally, cryptographically unphishable by design. That's what passkeys give you.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#665
I dislike passkeys because they support remote attestation. It's my key -- why does the website care what app I'm using to host it or if I'm allowed to copy it? Or what operating system I'm using, for that matter.

Because of this, I will not use passkeys. It's a slippery slope. Once we're all on passkeys, website devs won't resist enabling the remote attestation bit, locking out linux users.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#666

Earlier quoted context omitted.

Apple's keychain or google password manager - can hold 2000 passkeys easily.

Nothing in the post you're replying to is about "is 2000 passkeys storable", it's about "if I have 2000 passkeys and I need to move between an Apple device and an Android device, do I need to establish a second set of 2000 passkeys"?

Not at the moment. But if you sign into google account in iPhone then you can use Google's passkeys in iPhone.

At the end, passkeys are built not for the tin-foil, (I hate Google Apple fellows), I want to keep every single locally, RMS fans. No.

A majority will benefit. End of matter.

A majority don't change platforms (I have not seen them do it).

And lets be honest - even if they were portable are you privacy person that is going to do it? No.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#667
post #462

Earlier quoted context omitted.

Apple's keychain or google password manager - can hold 2000 passkeys easily.

Dunno why the downvotes, if you're willing to trust Apple or Google this is a good method for passkey usage. because your touchID/faceid/opticalid auth gate the keyring's on either of these vendors your passkey works without having to migrate them. EDIT: Also ANY device that you add to your iCloud has access to the passkeys you've made... it's a dream for secure access.

Downvotes does not matter. People here that are privacy inclined always find ways to argue about Google or Apple (any major companies). But if you look at their private lives - they adopt tech ASAP. A majority have Apple Pay or Google Pay. Paypal. At the same time use bitwarden also. (And that is fine)

These privacy zealots fail to realise that majority of population does not have time to setup bitwarden server or lineageos or zfs storage etc.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#668
post #462

Earlier quoted context omitted.

Dunno why the downvotes, if you're willing to trust Apple or Google this is a good method for passkey usage. because your touchID/faceid/opticalid auth gate the keyring's on either of these vendors your passkey works without having to migrate them. EDIT: Also ANY device that you add to your iCloud has access to the passkeys you've made... it's a dream for secure access.

What happens when the user decides to move to an Android device, or even is suspended from Apple for a suspected breach of the terms of service, or Apple decides to not support their country anymore? There are countless reasons to prefer to manage one's own access.

True... Theoretically correct but in practical sense?

All these doom mongering of suspension happens so rarely that majority don't care.

There are countless reason to DIY. Agree. But passkeys will help the majority.

Also note that the kind of people - like journalists etc - that need to use DIY/local are the ones that are likely to use passkey. Reality.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#669
post #402

Earlier quoted context omitted.

Thanks. One glaring issue I see is that right now police can’t ask you for your password in the USA (a violation of the right against self-incrimination). They can however get a search warrant for your device and your biometrics, and wouldn’t need your password if they can gain access through your pass key.

If you have it enabled, and you're in custody or at a border or similar, and have biometric auth enabled on your phone/computer, they can hold it up to your face or force you to put your finger on it to unlock it. Search warrant be damned.

According to Google,

> Approximately 90% people never go out of their country...

I am sure > 90% will happily love to have the convenience.

Yes, people like you can setup bitwarden etc. Nothing wrong. Passkey works for majority of people.

BTW, passkey can also be used without biometrics. It needs only the authentication of the device.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#670

The first time I got asked by a site if I wanted to use a passkey I immediately googled what they were and... never really found the answer, not in the 5mins I devoted to being distracting from my task at hand anyway. "magic fairy dust to login to apps." is the most accurate description I've seen. Unlike a password or a TOTP token, I know how those work, I know its my responsibility to keep track of them. If my passk…

Think of it like SSH authorized keys but automated for the web. Instead of storing the keys in a file; it stores them in a hardware security module (yubikey, or TPM). Registration generates an asymmetric key pair between your passkey, and the website. Login is the usual challenge/response process. The biggest step forward is phishing resistance. A fake login page can relay a TOTP code, but not the passkey challenge/r…

Yes, those are the easy parts - but none if that answers GP's questions:

> If my passkey is on my phone what happens if I lose my phone? Do I need a unique passkey per device? How do I rotate them? What if a device gets stolen?

I'd also add: How do I login on a device or browser that I've never logged in before? If I'm on a public computer that I trust enough for quickly logging into my emails but (say, the local library or university PC pool), do I have to install my password manager first and then login with my master password? This seems backwards.

Post reply on HN