Live data from Hacker News

Passkeys are primarily about vendor lock-in

news.ycombinator.com

11–14 of 14 posts

Re: Passkeys are primarily about vendor lock-in

#11
post #5

If you lose your passkey, why can you not reset your account like you would if you lost your password? These conspiracy theories are wild. Passwords suck. People reuse them. They use simple passwords. They are highly vulnerable auth factors. Passkeys are certificate auth for normies. https://www.yubico.com/resources/glossary/what-is-certificat... https://passage.1password.com/post/passkeys-compliance-stand... https:/…

People use simple locks on their doors. Have for hundreds of years. Brute force is easy. Or hell, a five dollar kit on amazon will open the lock without damaging anything. Nobody’s rushing to fix that. What’s the difference? Usually if you enter somewhere you shouldn’t physically be, someone (or some device) will see you. We don’t have that guarantee with digital systems because owners of said systems don’t want the…

Many new home builds come with digital locks now.

Re: Passkeys are primarily about vendor lock-in

#12
post #9
post #7

This surely would have been better as a comment on a passkey story? Re: MFA Password risk: low quality, reuse, malware, leak, phishing, social eng Password+MFA risk: malware, leak, phishing, time-limited social eng Passkey risk: malware The benefit of MFA with a shared secret (aka password) is to defend against a party that has learned or guessed the secret (low quality password, password reuse, user hack/malware, sy…

“never leaves your device(s)” aka “vendor lock-in” :)

That's not what it means? Or certainly not what I meant. As part of the protocol exchange, you do not send the private key. You're free to backup, duplicate to other devices, or write out your keys by hand... but the service has no right or capacity to demand the private key.

Re: Passkeys are primarily about vendor lock-in

#13
If you can't export them to local storage or an HSM of your choosing, can't inspect them, and can't lend them to others, then they're proprietary BS. The problem is the notion of a passkey provider with a "trust us to keep your private key intact and confidential on our servers" cloud-required mindset.
Post reply on HN