Live data from Hacker News

Passkeys were invented by engineers with zero understanding of consumer brain

twitter.com

811–813 of 813 posts

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#811

Earlier quoted context omitted.

A password manager let's me use my service specific credential from any device, securely and decentralized. Passkeys lock into a specific device and seem easy until you need to use another device. But instead of being a credential you own and control, across what could even be a local password manager, it's one password to everything. Maybe it is more secure than a regular password in some cases but it largely seems…

it's one password to everything You are entirely mistaken. Passkeys involve a third party storing a public key on their infrastructure, while you hold the private half of the key, somewhere. Passkeys are never reused. Even for the same person, they are always unique across websites, and across devices.

and to unlock that passkey on my PC uses... my user account password. So now every passkey on my device has a single password.

and I can't use this on any other device by default. My passkey is locked within the browser used to set it up.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#812

Earlier quoted context omitted.

A password manager let's me use my service specific credential from any device, securely and decentralized. Passkeys lock into a specific device and seem easy until you need to use another device. But instead of being a credential you own and control, across what could even be a local password manager, it's one password to everything. Maybe it is more secure than a regular password in some cases but it largely seems…

You're arguing against a straw man. All password managers support passkeys. Both apple and google allow exporting your existing passkeys to third party password managers too. Also each website gets it's own unique public key with passkeys. It isn't a single credential You're literally arguing a strawman

I don't have a password manager. All the passkeys I've been asked to set up are locked within this one browser on this one device.

By single credential, all the passkeys on this browser use my windows user password which is effectively a single key.

Re: Passkeys were invented by engineers with zero understanding of consumer brain

#813

Earlier quoted context omitted.

> Pretty much everyone is using a password management service In the US, only about 34 to 36% of adults use a password manager. Of the ~64% that don't, an alarming 20% reuse the same password across almost every service, and a ton just rely on browser autofill. If you use a password manager, you are in the minority. Hell, even if you don't use a PW manager and you at least use a different password for different servi…

FWIW, browser autofill is a basic password manager.

Chrome password manager and Apple Passwords count, in this context.
Post reply on HN