logoalt Hacker News

crazygringoyesterday at 7:34 PM1 replyview on HN

On the one hand, that seems really important and I'm happy to know it exists.

On the other hand, I thought I had fully researched how passkeys work and literally never came across it.

So it kind of just continues to support my concern that passkeys are just too complicated to understand. If I'm at another device I need to log into, I would have just assumed I couldn't.

There needs to be a simple mental model for users. I'm not saying passkeys can't underlie that, but I think the UX still just hasn't been fully figured out yet.


Replies

timmyc123yesterday at 10:07 PM

I used the technical name for the capability, but you've likely run into it before.

If there is no passkey on the local device, a QR code will appear which you can scan with your phone or tablet, and use the passkey for the account from that device. It just kind of happens, typically without the user having to do anything special.

I will say though, corporate devices can be a bit of a wildcard as they are usually configured and locked down for a specific purpose. But the cross-device flow is generally not blocked by organizations.

show 1 reply