Live data from Hacker News

Please, please, please stop using passkeys for encrypting user data

blog.timcappalli.me

11–13 of 13 posts

Re: Please, please, please stop using passkeys for encrypting user data

#11

Earlier quoted context omitted.

Not sure what you mean. In most cases, passkeys sync across your devices.

People with all Apple devices do not consist "most" of users

that seems like an excellent reason to avoid a buggy platform, as if there weren't other adequate reasons...

Re: Please, please, please stop using passkeys for encrypting user data

#12
Maybe I'm not getting it. Doesn't the problem start with ever deleting a passkey? That is: how do you ever know you don't need it anymore?

Also, what is the alternative? Just a password that you store in the vault? Seems like deleting those gets you back to the same place (with all the disadvantage of a plain password).

Re: Please, please, please stop using passkeys for encrypting user data

#13
post #10
post #3

Not to mention the challenges when (gasp!) a single user uses more than one device. Like, yes, some of us have both desktop computers and phones, thanks for asking. This is why I refuse to let most sites set me up with passkeys. I’m considering making exceptions for the ones that usually get this stuff right (like GitHub).

Just add more than one passkey to your account?

Only a small subset of sites seem to support that so far.
Post reply on HN