Live data from Hacker News

Passkeys were invented by engineers with zero understanding of consumer brain

twitter.com

441–450 of 813 posts

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#441
post #8

I do not know how to use a Passkey in a way that won’t impede how I log in to systems. I’ve been in tech for 26 years, and I understand the Public/private key behind what a Passkey is. Here’s what I don’t understand: I access a website through at least four different devices (my iPad, iPhone, Windows Desktop computer, and MacBook Pro) and three different browsers on each device (Brave, Firefox, Safari) , and I use La…

I don't know the exact tech behind it, but for a phone passkey I get a QR code on my laptop screen to scan with my phone, I accept it, and it logs me in.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#442
post #79

Earlier quoted context omitted.

Your understanding is correct and I agree with you. The Passkey spec authors, however, think services should be allowed to ban your client for behaving this way: > [When UV is required, KeePassXC must request user verification or not handle the request] > This implementation is not spec compliant and has the potential to be blocked by relying parties. https://github.com/keepassxreboot/keepassxc/issues/10406

> > This implementation is not spec compliant and has the potential to be blocked by relying parties. The only conclusion I can come to when it comes to this and the earlier kerfuffle regarding being able to export the plain text of passkeys is 'the spec is bad and you should feel bad'.

Yeah, it sucks. It could've been a cool technology but they're so locked in to "my way or nothing" and won't consider other usecases or security trade-offs other than the ones they decided on. It's just a complete non-starter with that attitude.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#443
post #410

I find Google Password Manager makes passkeys pretty easy to use. As long as you don't accidentally create a passkey some other way. Hopefully websites will adapt to the reality of how people use passkeys in practice and some of the UX weirdness around them will disappear over time. One annoying thing though is that while they recently added password sharing, they don't allow sharing passkeys. Basic passkey sharing w…

Considering Google's track record of locking people out of their accounts it'd be very risky to trust them with your password manager.

This is very far from the top of the list of risks I should be concerned about. Basing your security decisions on the frequency with which you hear about something bad happening in the news is not a wise strategy. You have to consider that the user base of Google accounts is in the billions.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#444
I use Apple based passkeys to log into everything I can now. I have given it virtually no thought since all my relevant accounts and rolled out support. My non-technical close friends and family (consumer brains) have also done the same. I imagine it is a different case for non-Apple device users, but in the Apple case, passkeys are zero friction and truly life-enhancing for anyone who logs into things

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#445

Earlier quoted context omitted.

So you're saying that if you're inside Apple's walled garden, it works really well! Hmm...

> So you're saying that if you're inside Apple's walled garden, it works really well! Hmm... Or google. If you use android and chrome then it all just works. But god help you if you want to use a password manager to keep everything in sync; I haven't yet found a way for a mobile app or web page to explicitly signal to the device that the passkey to be created should live in $password_manager and not whatever built-in…

Works fine on iOS. All my passkeys are in 1Password, and every prompt to use or save a passkey goes through 1P. You can also control which password managers are active on iOS (eg, I disable iCloud passwords, and only allow “autofill from” 1Password.)

So yeah, this is cross platform on iOS, macOS, Windows, and Linux.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#446
I recently logged into my CVS.com account after not touching it for years, and I couldn't find the password reset..... turns out they no longer use passwords at all; only Passkeys and tokens via email/SMS.

Aside from email accounts potentially being compromised or SMS interception, this is honestly the way all sites should be going now. But more seriously, there should be a way to use only Passkeys with a backup identification method in case you lose your Passkey.

The new threat? Browser password managers are insecure. Anyone can sit down at my machine if it's unlocked and Passkey their way into any of my accounts. What good is that? Why doesn't Chrome use my Google account password before allowing auto-fill/login? (Obviously I don't use Chrome's password manager, but it's a real concern for everyone else.)

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#447
post #8

I do not know how to use a Passkey in a way that won’t impede how I log in to systems. I’ve been in tech for 26 years, and I understand the Public/private key behind what a Passkey is. Here’s what I don’t understand: I access a website through at least four different devices (my iPad, iPhone, Windows Desktop computer, and MacBook Pro) and three different browsers on each device (Brave, Firefox, Safari) , and I use La…

This is much, much simpler than you think it is. Passkeys are just passwords that require a password manager. If you lose your passkey, you'll reset your passkey the same way you reset your password, probably with a "forgot my password" email. (But you're not going to lose it, because you use a password manager, and the passkey will be stored there and synchronized to all of your other devices.) The weird part is tha…

Oldschool KeePass ftw

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#448

Earlier quoted context omitted.

This is much, much simpler than you think it is. Passkeys are just passwords that require a password manager. If you lose your passkey, you'll reset your passkey the same way you reset your password, probably with a "forgot my password" email. (But you're not going to lose it, because you use a password manager, and the passkey will be stored there and synchronized to all of your other devices.) The weird part is tha…

> This is much, much simpler than you think it is. Passkeys are just passwords that require a password manager. This is not true. There are device bound passkeys where the private key is stored in a HSM (TPM2.0, Android SE, or apple SE) instead of a hosted service (iCloud, Bitwarden.com). You can just add multiple Passkeys to a single site to have another backup device should your other one be unavailable.

Speaking about hardware tokens:

If I have to go get the backup out of "secure" storage each time I want to add a new Passkey it's not really a backup.

The design should have allowed, even if it was just within only the purview of a single manufacturer, a method for the device to export an encrypted dump that could be reloaded onto a factory-new device. Heck, make it a value-added service that the manufacturer has to initiate and tie it to some real-world identity verification.

The idea of having to put backup devices in-hand regularly is a bad design.

Phone apps. get around this idiocy by backing-up the encrypted Passkeys to a hosted service.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#449

It seems to me like those who like passkeys/consider them simple are those who entrust all their credentials to proprietary cloud software vendors that sync them to all their devices. Those of us who are not comfortable with that and want to keep our credentials offline and sync/backup them ourselves have questions about how the registration/backup/sharing flows work exactly. I see this as part of a trend together wi…

I do love the cloud version of passkeys, but I also have a backup YubiKey. I could do two backup YubiKeys, drop the cloud, and keep one YubiKey in a safe deposit box and one elsewhere, but I haven't had much reason to yet.

A passkey doesn't give up anything compared to a password, and is in fact much much easier to handle, IMHO. I have kept all of my private SSH keys in secure hardware for a decade, so perhaps I'm more used to carrying a physical key than others, but IMHO it's all better, all around.

We should eliminate passwords, and that has nothing to do with remote attestation, age verification, or anything like that.

For 20 years, I've only known two to three passwords at any time, and those are login passwords for separate boxes or corporate/home accounts. Beyond that, hardware access should solve everything, and I shouldn't have to type any passwords anywhere. Every account needs granular credentials, not shared credentials, but no user should have to memorize passwords beyond one per work domain.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#450
post #108

Earlier quoted context omitted.

>This is much, much simpler than you think it is. Passkeys are just passwords that require a password manager. The issue isn't what passkeys _are_ (e.g. explaining they are like public/private "ssh keys" and hoping that type of explanation ends the confusion). Instead, it's the workflow around passkeys. The websites show very confusing dialog popups and choices that a lot of normal people will not understand. This is…

sadly it seems like most of the banks I use still enforce antiquated password rules, no MFA and rely on stupid questions most of which can easily be guessed from public records.

You can also just put any answer into the question as long as you will remember it.
Post reply on HN