Live data from Hacker News

Passkeys were invented by engineers with zero understanding of consumer brain

twitter.com

81–90 of 813 posts

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#81
post #37

FWIW: I find passkeys to be a very simple and easy to use concept. Simple: it's like a password that I don't have to type in Easy to use: because I use 1Password and just have it installed on everything. On Android, it can be set as the default passkey provider so, even on mobile, I am using passkeys shared across devices. Is this "less secure" because I'm sharing the keys through 1Password. I suppose, at some level.…

Everything you said is _also_ true if you use a password manager than can interact with the browser (which you're already doing).

Plus, that doesn't have the negatives/limitations of passkeys.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#82
The website for my HSA required me to set up a passkey last time I logged in. I set it up on my work laptop and my work password manager, which means I can now no longer access my account from my personal computer. This is fantastic, just what I wanted

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#83
post #8

I do not know how to use a Passkey in a way that won’t impede how I log in to systems. I’ve been in tech for 26 years, and I understand the Public/private key behind what a Passkey is. Here’s what I don’t understand: I access a website through at least four different devices (my iPad, iPhone, Windows Desktop computer, and MacBook Pro) and three different browsers on each device (Brave, Firefox, Safari) , and I use La…

If you save it via Passwords app, it'll be iOS / macOS mainly, but you can unlock with any Apple device that supports Passkey / Passwords app (so likely modern + reasonably updated) the easiest. If you want it to work "everywhere" then you CAN use your iOS / MacOS Passkey, it will show you a QR code, some places poorly support this, I believe both devices need bluetooth, and then it will authenticate it. Linux is the…

Windows also has the Apple Password app.

https://support.apple.com/guide/icloud-windows/set-up-icloud...

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#84

I find it difficult to explain how to use password manager to non-IT person. Whatever I say, they say it is not secure. No amount of explanation will change their mind. They prefer to keep their passwords in their physical note book hidden in the safe (yes, they open the safe etc each time they need to log in somewhere when they get logged out). As someone with ADHD a passkey is something I can lose easily and I don'…

I mean, they're right. I wouldn't trust any online password manager even if it was iCloud.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#85
post #6

Passkeys are just SSH keys in how they work. We've been doing this since the 90's. The only people that use SSH keys are the Linux savvy users and those who are forced to via an enterprise solution for vaulting. The average person doesn't know anything about this stuff nor do they care. I also have yet to see a Passkey solution that didn't also have a password on it and a nice little box letting people choose to use…

I can find my ssh keys in `~/.ssh`. No such place exists for passkeys.

I can pull up all my passkeys in 1Password or Bitwarden without issue.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#86
post #70

Earlier quoted context omitted.

Nobody is safe from a nation-state "attack" they'll just go threaten your providers to give up your data. Passwords written on paper are probably safer than a centralized password manager for almost every circumstance other than a government coming after you.

Papers: Safe - yes. Easy to lose/misplace: also yes.

Humanity having millennia of experience securing them: also yes.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#87

Earlier quoted context omitted.

You can store your passkeys in Bitwarden or Keepass vault. Then you can use them through Bitwarden or Keepass apps on any other device. Been using passkeys like this for several years, and it works pretty seamlessly. With Keepass vault, I even have an offline copy as backup.

If you store the key in Bitwarden or Keepass, what makes it different from a password?

The difference is you can't just copy and paste the private key into a phishing website. The login process validates your private key and logs you in.

Also since the service does not store your private key, it is more resistant to data-breaches as that is one less potential breach source.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#88

It just so happened that Microsoft sent an email today to our M365 tenant administrators that SMS and voice for 2FA is being removed 1-Feb-2027 and that automatic enrollment to passkeys starts 1-Sep-2026. Bring on the passkey overlords. Although, LLMs say that passkeys are superior to passwords since it includes a public/private key setup with the private key saved to a device that requires a PIN or biometric to acce…

How is one supposed to let an LLM log in with passkey?

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#89
post #58

Earlier quoted context omitted.

What are you talking about? I can literally export all that data to another OS or password manager. Takes a whopping single click.

I didn't realize this was supported, I'm kind of favoring Apple's Passwords app since you can lockdown your account and they are very on top of someone accessing anything of yours. Any time I power on an iPad I havent used for months they tell me a new device can read my texts type of thing, which is a nice paper trail.

I wouldn't favor an application that is locked to a big player account (Microsoft, Apple, Google) where a ToS violation for something unrelated may lock you out of all services, passwords/keys included.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#90
I think portability is very confusing: they rolled out passkeys with no device portability (device-bound) and only recently added it (CXP). So for anyone with multiple devices it was a relative disaster - why should my Windows PC hold a device-bound passkey to anything? How do I login on Linux or macOS? Picking a password manager to do portability also means another kind of lockin, though maybe you can live with that kind if you really trust the company. Even so, the password managers all seem to be competing to have relaxed security, so that vault and account passwords are the same, or you are asked to type your master password into a webpage - surely we didn't replace per-site passwords with this?
Post reply on HN