Live data from Hacker News

Please, please, please stop using passkeys for encrypting user data

blog.timcappalli.me

1–10 of 13 posts

Re: Please, please, please stop using passkeys for encrypting user data

#3
Not to mention the challenges when (gasp!) a single user uses more than one device. Like, yes, some of us have both desktop computers and phones, thanks for asking.

This is why I refuse to let most sites set me up with passkeys. I’m considering making exceptions for the ones that usually get this stuff right (like GitHub).

Re: Please, please, please stop using passkeys for encrypting user data

#4
post #3

Not to mention the challenges when (gasp!) a single user uses more than one device. Like, yes, some of us have both desktop computers and phones, thanks for asking. This is why I refuse to let most sites set me up with passkeys. I’m considering making exceptions for the ones that usually get this stuff right (like GitHub).

Not sure what you mean. In most cases, passkeys sync across your devices.

Re: Please, please, please stop using passkeys for encrypting user data

#5
post #3

Not to mention the challenges when (gasp!) a single user uses more than one device. Like, yes, some of us have both desktop computers and phones, thanks for asking. This is why I refuse to let most sites set me up with passkeys. I’m considering making exceptions for the ones that usually get this stuff right (like GitHub).

Not sure what you mean. In most cases, passkeys sync across your devices.

People with all Apple devices do not consist "most" of users

Re: Please, please, please stop using passkeys for encrypting user data

#6

Earlier quoted context omitted.

Not sure what you mean. In most cases, passkeys sync across your devices.

People with all Apple devices do not consist "most" of users

This is the case in other areas though. I keep some of my passkeys in BitWarden and that is cross device/platform as well.

Re: Please, please, please stop using passkeys for encrypting user data

#9
post #7

What's the difference between keeping a passkey in bitwarden, and just using a password, also in bitwarden?

Mainly that a service can't refuse passwords from Bitwarden, whereas in a few years you'll find yourself reading an article about how a bank in Luseristan has decided to require that their users sign in using Passkeys stored in an attested authenticator (not Bitwarden) running on an attested device (not any current Linux desktop).

Re: Please, please, please stop using passkeys for encrypting user data

#10
post #3

Not to mention the challenges when (gasp!) a single user uses more than one device. Like, yes, some of us have both desktop computers and phones, thanks for asking. This is why I refuse to let most sites set me up with passkeys. I’m considering making exceptions for the ones that usually get this stuff right (like GitHub).

Just add more than one passkey to your account?
Post reply on HN