Live data from Hacker News

Passkeys were invented by engineers with zero understanding of consumer brain

twitter.com

521–530 of 813 posts

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#521

Earlier quoted context omitted.

If I'm on someone else's computer and I want to use a passkey on my phone, the computer will display a QR code. I scan the QR code with my phone, the phone signs the login request and posts it to the service's callback. Then I'm logged in on that new device. If my phone's camera is broken but both devices have bluetooth, it can do the handshake over bluetooth. If I'm on someone else's computer and I want to use a pas…

This is good in theory but in practice doesn't always work. It isn't just a QR code like I would like it to be, its a QR code and you need bluetooth. Maybe there is a hypothetical world where bluetooth drivers actually work on windows machines and can connect to a mobile device seamlessly but that is not my experience. Across multiple windows machines i often have a problem where windows just decides the machine does…

this doesn't sound like the passkey is the issue, is the implementation or the missing implementation issue.

in poland we have similar to passkey implementation for government profile, that is then used to login to most/all government websites or to sign government documents. you point the camera on the qrcode, confirm it on the phone and you are done. this same app has your ID, which can be used in most places (shops, banks, police etc).

and btw im using linux (main box), macos, android and ios - no issues so far with really cross device usage

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#522
post #98

Earlier quoted context omitted.

I never found a comfortable way to ensure all of my accounts had more than one U2F key associated with them. I always wished there was a way to have 2 physical U2F keys, one on me, and by adding one to an account, both would work. As is, I had to either: - Keep both on me, and add both - I am at risk of losing both at the same time - Keep one one me, one in a safe - I have to keep track of which device I've added to…

If you're comfortable with OTP with backups, does a password manager like 1password, with backups, fit your needs? Or would you prefer to self-manage your backups on your own storage? I ask because I'm curious about others' practices and desires here, not with any promise of a better solution!

Yeah, 1password or keepass are both fine solutions for password managers in my mind.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#523
I’m absolutely floored by some of what I am reading here. Six months before passkeys rolled out there were numerous succinct consumer-friendly write-ups. I sent at least one of these to several non-technical people I knew and they had no problem understanding the benefit and moving to using them where available once they started rolling out.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#524

Earlier quoted context omitted.

A potentially good idea got corrupted by vendors, password managers, browsers, etc trying to assert control. I'm also an engineer and I find the UI around passkeys entirely unclear, but it doesn't have to be that way. It seems like everyone wants to be _the_ password manager for all your passkeys. They don't want to make it easy to understand that is what they are doing though, they just happily offer to "handle it f…

> It seems like everyone wants to be _the_ password manager for all your passkeys. Which defeats part of the point of passkeys in the first place in that they are supposed to be device-bound, the private key held in the TPM or secure enclave or whatever other security chip, mathematically non-exportable. Storing all your private keys in a cloud vault still leaves you exposed to potential credential theft if your vaul…

In the Apple ecosystem, passkeys are stored in your iCloud, and access to the passkeys is device bound. So if I generate a passkey on a MacBook, I can then use it from my iPhone as well, because it's encrypted to all my hardware devices.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#526
post #8

I do not know how to use a Passkey in a way that won’t impede how I log in to systems. I’ve been in tech for 26 years, and I understand the Public/private key behind what a Passkey is. Here’s what I don’t understand: I access a website through at least four different devices (my iPad, iPhone, Windows Desktop computer, and MacBook Pro) and three different browsers on each device (Brave, Firefox, Safari) , and I use La…

This is much, much simpler than you think it is. Passkeys are just passwords that require a password manager. If you lose your passkey, you'll reset your passkey the same way you reset your password, probably with a "forgot my password" email. (But you're not going to lose it, because you use a password manager, and the passkey will be stored there and synchronized to all of your other devices.) The weird part is tha…

> This is much, much simpler than you think it is. Passkeys are just passwords that require a password manager. If you lose your passkey, you'll reset your passkey the same way you reset your password, probably with a "forgot my password" email.

This is why I don't bother with these if they have a weaker workaround, which will be open to remote hacking.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#527

Earlier quoted context omitted.

Of course. I was just pointing out that their claim about the lack of portability across devices was untrue.

Perhaps they should’ve said platforms. Because if you wanted to migrate those passkeys off your password manager and into a different platform like Apple Pass or Google how is that accomplished?

https://mobileidworld.com/apple-introduces-cross-platform-pa...

https://support.google.com/chrome/answer/13068232?hl=en&co=G...

https://1password.com/blog/import-autofill-organize-whats-ne...

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#528
I used to think this but once you treat them as another path to get in they become really useful.

Yes, you still have your 2fa and password, but you create a fast path in addition to it when you get in.

It became even more useful once I stopped insisting they have to go into 1password

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#530

Earlier quoted context omitted.

Now that I think about it, you are right. But if they could ban my use of written passwords as easily as banning my use of a particular passkey device, why go through all the extra hoops to just be as vulnerable as before? This seems like a whole lot of extra work to do that gains me nothing.

I think it is important to explain why I and others are so reluctant to this. In security, you identify reasonable threats. You can't protect against all of them, and some may even be contradictory. When I get a call on my phone that says "Potential Spam", I have never even once in my life decided to run over to my list of passwords and hand them over to the President of the Spanish National Lottery. Not even once. B…

It should go without saying that, while you've never given your passwords over to the President of the Spanish National Lottery, there people who do get duped into doing exactly that all the time.
Post reply on HN