logoalt Hacker News

Passkeys were invented by engineers with zero understanding of consumer brain

362 pointsby ksectoday at 2:25 PM481 commentsview on HN

https://xcancel.com/nikitabier/status/2079787406300266743


Comments

gortoktoday at 2:59 PM

I do not know how to use a Passkey in a way that won’t impede how I log in to systems. I’ve been in tech for 26 years, and I understand the Public/private key behind what a Passkey is. Here’s what I don’t understand:

I access a website through at least four different devices (my iPad, iPhone, Windows Desktop computer, and MacBook Pro) and three different browsers on each device (Brave, Firefox, Safari) , and I use LastPass. If I accidentally set up a passkey on my phone (let’s say I use Safari one day instead of my go-to, Brave), can I still log in without that passkey on other devices? Is there a way to ensure that passkey can be used on other devices? Can I add another passkey on another device? How many passkeys can I set up for a particular site/app? I have at least 6 different combination of browser/devices in use.

I don’t want to use Passkeys because I don’t the answers to those questions, and I don’t know whether each website/app that has set up Passkeys has decided the answers to those questions in the same way as the others. For now, I’m going to stick with LastPass and use Passwords; because no matter whether I lose my device or not or whether I’m on my own devices or not, I can be sure I’ll be able to get into a site/app.

Edit: One final consideration, my spouse and I share user/name passwords for some things (notably Pandora and our Amazon Prime account) since they don’t handle things like family logins well; how do both my wife and I use amazon or Pandora with passkeys? Do we each set up passkeys? How do I get her Pass if that’s not an option?

show 41 replies
christina97today at 5:01 PM

It’s quite the opposite. Passkeys are phenomenal for a lot of consumers. Based on this thread, it’s the engineers who understand authentication in the first place and have their own system (eg password manager) that are confused.

Consider a user in the Apple ecosystem: you are already conditioned to just do Touch ID or Face ID when asked. I was on Amazon the other day, it prompted randomly for “want to set up a passkey to sign in easier”? I set it up and now I can easily sign in to Amazon on my mac or iphone with zero friction.

For the normal consumer this is not a replacement for “dig out my password manager and copy-paste/autofill my password”, it’s a replacement for “oh it’s prompting for my password again” -> proceed to type your shared password for all sites.

show 6 replies
tossitawayplztoday at 5:59 PM

The first time I got asked by a site if I wanted to use a passkey I immediately googled what they were and... never really found the answer, not in the 5mins I devoted to being distracting from my task at hand anyway.

"magic fairy dust to login to apps." is the most accurate description I've seen.

Unlike a password or a TOTP token, I know how those work, I know its my responsibility to keep track of them. If my passkey is on my phone what happens if I lose my phone? Do I need a unique passkey per device? How do I rotate them? What if a device gets stolen?

I'm so glad I'm not alone in thinking these are so poorly explained.

show 3 replies
VCFundedGenYertoday at 8:48 PM

Passkeys bother me because they depend on the availability of another device. That just won't cut it for a lot of folks, especially people that are prone to losing devices. It's also annoying to have to deal with the 50,000 places that are fighting to keep your passkeys, leading to fragmentation and uncertainty as to where these credentials are stored.

Haphazardly implementing passkeys also has big problems - one vendor I use implemented them rather badly and randomly one day, completely removing the previously-solid password/MFA setup they had, replacing it with a "you are required to confirm on your phone with no other alternative" passkey, which was really annoying. I don't like my logins messed with. Passwords/MFA, while not perfect, work very well for most people, myself included. Passkeys still feel like they are in a very immature state.

programmertotetoday at 3:10 PM

Like some folks already commented here, even as someone who has been working in tech for 20+ years, I find Passkey confusing. I understand the key aspect in computer science term, but I don't know how to use it across devices. Another big worry is that if I tie that to a physical key, then I might lose it (because it's physical) and never get it back.

show 2 replies
rsyringtoday at 3:18 PM

FWIW: I find passkeys to be a very simple and easy to use concept.

Simple: it's like a password that I don't have to type in

Easy to use: because I use 1Password and just have it installed on everything. On Android, it can be set as the default passkey provider so, even on mobile, I am using passkeys shared across devices.

Is this "less secure" because I'm sharing the keys through 1Password. I suppose, at some level. But before that, I was simply sharing passwords through 1Password in the exact same way. So, I don't think my security posture has changed any.

What has changed is the UX and IMO for the better. Now I don't have to generate/fill/copy-paste text strings for user names or passwords. 1Password knows what site I'm on and usually responds automatically when I'm in a passkey context. If I have more than one passkey available, because I have multiple accounts (for something like Google Workspace), it shows me options and I pick the one I want.

Honestly, it's mostly a "just works" system and I like it a lot better than passwords.

YMMV, of course.

show 6 replies
exabrialtoday at 3:00 PM

With physical U2F key, I could explain to my 78 year-old-parents "this is a physical key needed to access your account. Think of it like the front door key to your house. Don't lose it or lend it to anyone. We should have a couple of backup keys too." And they got completely understood and added it to all of their accounts. This was not hard. People assumed consumers were too stupid to do this without even giving them a chance.

show 5 replies
Slackwisetoday at 8:14 PM

I recently logged into my CVS.com account after not touching it for years, and I couldn't find the password reset..... turns out they no longer use passwords at all; only Passkeys and tokens via email/SMS.

Aside from email accounts potentially being compromised or SMS interception, this is honestly the way all sites should be going now. But more seriously, there should be a way to use only Passkeys with a backup identification method in case you lose your Passkey.

The new threat? Browser password managers are insecure. Anyone can sit down at my machine if it's unlocked and Passkey their way into any of my accounts. What good is that? Why doesn't Chrome use my Google account password before allowing auto-fill/login? (Obviously I don't use Chrome's password manager, but it's a real concern for everyone else.)

show 1 reply
c7btoday at 5:18 PM

UX is not the problem with Passkeys. Passkeys were designed to align with the interests of BigTech, who are bent on stopping the abomination that is general computing devices in the hands of consumers and forcing them into their walled gardens. The language that is used for taking away freedoms is the same as always, safety. Where we ended up with Passkeys is an operating model that is suitable for corporate devices, i.e. the user can only do what the owners of the device allow them to. Suboptimal UX is downstream from that problem.

mmmpetrichortoday at 8:45 PM

My Health savings account provider is trying to force the use of passkeys. I assumed it was a cynical attempt to force the use of their app, which I never needed or wanted, but now seemingly will be required to use.

unbolted3032today at 8:41 PM

The thing that gets me is that to even use a Passkey I need a browser addon that syncs my entire password vault into browser memory, the same memory that all the adtech JS runs! No thank you! What a ridiculous system. I will continue copying and pasting passwords myself out of KeePassXC.

ranger207today at 3:35 PM

The website for my HSA required me to set up a passkey last time I logged in. I set it up on my work laptop and my work password manager, which means I can now no longer access my account from my personal computer. This is fantastic, just what I wanted

show 4 replies
legitstertoday at 4:47 PM

I think about this a lot when using our corporate SSO tool.

When I hit the button to log into Slack, there are like, 3 popups in succession - the last one ultimately asking for my fingerprint. Then when I give it, there is a flurry of web pages that get loaded and redirects that happen until finally Slack pops up again.

There isn't any realistic world in which I check each window to make sure everything is happening right and I am not being MitM'd.

I'm a fairly technical person, and I would be unable to perceive the difference between a really tight security environment and my computer being hijacked.

show 2 replies
allthetimetoday at 8:14 PM

I use Apple based passkeys to log into everything I can now. I have given it virtually no thought since all my relevant accounts and rolled out support. My non-technical close friends and family (consumer brains) have also done the same. I imagine it is a different case for non-Apple device users, but in the Apple case, passkeys are zero friction and truly life-enhancing for anyone who logs into things

schmichaeltoday at 3:29 PM

I mostly love passkeys to be honest even though I use multiple browsers across multiple devices and OSes (iOS, Chromebook, Linux, macOS, Xbox, etc). Bitwarden’s support is (finally) pretty good.

My problem is that I manage a lot of accounts for my family which makes passkeys a nightmare. If I’m out and a kid gets chucked into a login flow that happens to require a passkey, I can’t text a password and TOTP code to the adult with them. I know that’s terrible opsec but the reality is people share accounts and passkeys are designed to thwart that.

et1337today at 5:39 PM

Throwing my hat in the ring, I think passkeys were also invented by engineers with zero understanding of the average developer: https://etodd.io/2026/04/06/passkeys-are-too-hard/

FireInsighttoday at 7:54 PM

Okay, I'm a tech nerd I admit it, but for my personal authentication life I find passkeys to make sense.

All my passwords and SSH key are already in Bitwarden. When a site starts supporting passkeys, I add that to Bitwarden as well. Now, instead of logging in by auto-filling my username and password, I just press the passkey login button (that hopefully exists) and click on the Bitwarden popup to select the account. It's less button presses for me, and I cannot be phished, nor can my passkeys be leaked on the dark web. All thanks to some fancy cryptography.

Okay, sure, if someone steals my Bitwarden vault by snatching my laptop while it's unlocked or something, I end up pretty screwed. That security aspect did not change, so I still use TOTP for all important services.

Also, I've made one invite-only web app where single-use invite codes and passkeys are the only ways to log in. It was not too hard, it was fun, actually. And I get the peace of mind that account sharing is pretty much impossible were a bad actor able to get their hands on an invite, as is hacking other people's accounts.

(Okay, I concede that I've had to help multiple people who find passkeys confusing as a result of this whimsical decision, and that it just might be that nobody is using my web app for real. So I'm just speaking from nerd privilege here... But it works well, trust me!!)

herftoday at 3:37 PM

I think portability is very confusing: they rolled out passkeys with no device portability (device-bound) and only recently added it (CXP). So for anyone with multiple devices it was a relative disaster - why should my Windows PC hold a device-bound passkey to anything? How do I login on Linux or macOS? Picking a password manager to do portability also means another kind of lockin, though maybe you can live with that kind if you really trust the company. Even so, the password managers all seem to be competing to have relaxed security, so that vault and account passwords are the same, or you are asked to type your master password into a webpage - surely we didn't replace per-site passwords with this?

66fm472tjy7today at 8:09 PM

It seems to me like those who like passkeys/consider them simple are those who entrust all their credentials to proprietary cloud software vendors that sync them to all their devices.

Those of us who are not comfortable with that and want to keep our credentials offline and sync/backup them ourselves have questions about how the registration/backup/sharing flows work exactly.

I see this as part of a trend together with remote attestation, age verification, CSAM scanning, restricting sideloading, etc that will lead to most interactions over the internet only being allowed if big tech and/or government can verify the participants, the contents, and the hardware and software used.

Even among techies, many support these developments, so it is just a matter of time before we have no choice but to join the former group.

show 1 reply
TechRemarkertoday at 5:04 PM

Yes, a bit of a mess. As the only practical way for most to use is with a password manager. So essentially, all your accounts still have a real password, just you enter that into your password manager app. So if your device is every compromised and someone has your master password then you are screwed.

And of course, passkeys on most all sites don't really improve security since someone can just choose to login with user/pass instead since presumably very few sites allow you to have just passkey.

Also if you use a password manager you may get locked into using that platform. Or ideally using a third party one but then having to pay a subscription, or using an open source option that is not ideal for the average person.

If one uses a passkey as intended and without a password manager and the site truly only supports logging in via your passkey, for all the touted benefits of passkeys, that would be a nightmare if a person loses access to their device, etc.

AJRFtoday at 6:21 PM

I keep seeing people working on Passkeys get real defensive when told they don't make sense to people.

I've worked in tech 12+ years and I _hate_ when a Passkey prompt comes up, its only ever slowed me down.

But the devs who work on them are quite rabid, and keep dismissing real criticism of their implementation.

dangtoday at 4:13 PM

> I run a tech company and I have no idea what a passkey is and at this point I’m too afraid to ask

I thought I was the only one!

show 2 replies
datakantoday at 2:56 PM

Passkeys are just SSH keys in how they work. We've been doing this since the 90's. The only people that use SSH keys are the Linux savvy users and those who are forced to via an enterprise solution for vaulting.

The average person doesn't know anything about this stuff nor do they care. I also have yet to see a Passkey solution that didn't also have a password on it and a nice little box letting people choose to use the password instead of the passkey. They just added a new layer on top of all the old ones and created confusion. Now people use password and passkey interchangably in conversations and no one knows what they are talking about.

show 3 replies
f30e3dfed1c9today at 6:45 PM

My take: (1) I've had passwords handled pretty well for a long time now: same password manager for something like 15 years; (2) companies are pushing pretty hard to get me to use passkeys instead.

From (2) I assume that the companies see benefits to themselves. I don't care about benefits to them. I don't see much in the way of benefits to me, so I'm not changing anything if I don't have to.

I'll admit to not having looked into passkeys all that much. Someday, I might. But for the time being, I don't see much point. I imagine that eventually I'll be more or less forced to deal with passkeys in at least some contexts. Will leave that for later.

For now, it's all a big "no thanks" from me.

deauxtoday at 5:52 PM

This comment section is the best example of all time of the arrogance of Big Tech and its employees. Please try to take a second thinking outside of your bubble before commenting ridiculous stuff.

Yes, as a wealthy American, you "live in the Apple ecosystem". 99% of the world doesn't. And guess what, they're affected by passkeys all the same. They use a Windows laptop, and either an Android phone or iPhone. A lot of people even have an Android phone and an iPad. And no laptop at all. But at work or school they have to use Windows.

It's quite simple. Besides people "living in a single ecosystem" (discussed above, this is almost nobody), passkeys are only viable (i.e. not very painful to use) if you use a dedicated cross-platform password manager. Yet people who use those - which too is a globally negligible percentage - are exactly the people who tend to have near nothing to gain from passkeys, and only to lose. The majority of them is tech-savvy and they use auto-generated unique passwords. In that scenario, the minuscule improvement in security is meaningless and not worth it.

Ironically, this comment section shows exactly why passkeys are a shit show. Half the people here are exactly those who are coming up with this shit in their FAANG jobs, happily part of the global 1% (of which their tech-illiterate grandma too is part of), and they have no idea or care in the world for the remaining 99%. Unless of course this was simply a land grab for lock-in, which is about as likely.

proniktoday at 8:40 PM

I'm probably not the only one to have a deep distrust in passkeys. I've deep-dived in to what they are and how they work and I think I can accept them on their technical merits, but I can't shake the feeling that the adoption has been way faster than we've been used to, for whatever reason. I think it was half a year between the settling down of the specification to being bombarded by a "Get a passkey!" from every goddamn website on this earth. I don't really see what the conspiracy to move the whole world to passkeys would be here, but it certainly feels like there is one.

I think my problem with passkeys is the same as with almost everything today: if I lose my phone, my digital life will be almost as difficult to recover as if I lost my ID and my birth certificate at the same time. Yes, that's why you don't create one passkey (phone), but maybe two or three (browsers), but that's mental load on myself -- I don't even try to explain that stuff to my parents, even something as (somewhat) easy to use as a password manager is out of their scope. Add TOTP and passkeys on top of that and you've got perfect security that no-one in their right minds is using. No idea how to resolve the problem, but it's not by shoving a solution down our throats with a vengeance.

randomblock1today at 6:54 PM

Stop thinking of them as alternatives to passwords. That is something they do, incidentally. Really, they are an alternative to normal TOTP 2FA (and shudders SMS 2FA). Those were already dependent on an app on a single device, or a password manager. And now, you can have the security of that, automatically used with biometrics. It is only because they are so secure, due to being a cryptographic key, that they can replace passwords.

They really should come up with a way to transfer them across devices/password managers though.

gchamonlivetoday at 4:40 PM

I really don't get passkeys and how they are supposed to be safer.

Currently I save all login tuples to Bitwarden and store OTP secrets onto Aegis. Could have been 1password and authy, it's irrelevant. The thing is, I only get pwned if both are compromised.

Now with ubiquitous passkeys in Bitwarden if someone has access to my vault unencrypted it's already endgame.

beaker52today at 4:34 PM

Passkeys are a political play aimed at bolstering government support. They’re the privacy sabotaging arm of Digital ID. They go hand in hand with “age” verification. It’s all the same play. Get your identity, get your access credentials, give it to the prying eyes.

johngalttoday at 6:20 PM

If you want a consistent, and seamless authentication experience, then one party has to own that experience. Go federation/SSO. Sign into everything with microsoft, or google as your identity provider, and live with the privacy implications.

Passkeys are great, and they take a significant amount of work away from the user, and make them much less prone to phishing attacks while also not turning their entire online identity into the property of google. I've had much more luck with onboarding non-technical people into a yubikey vs a password manager. Platform authenticators tend to trip people up. However, the process of adding a new key is getting much more consistent, and legible to people over time, and things will settle on platform authenticators rather than external physical keys for most use cases.

coldpietoday at 2:51 PM

Passkeys are a vector for locking your logins to Big Tech ecosystems. They support device attestation, which means the service you are logging in to can require you to only use certain Passkey clients such as those provided by Google, Apple or Microsoft. The Passkey spec authors also maintain a list of "naughty clients"[1], which are clients that allow the user to manage their own data how they want. Services could choose to block those clients for "security reasons," justifying the decision to force you to use one of the Big Tech providers.

Until device attestation is removed or strongly curtailed in the spec, I suggest you do not create any Passkeys. Which sucks, because it's otherwise a pretty cool tech.

[1] https://passkeys.dev/docs/reference/known-issues/

More sources here: https://www.smokingonabike.com/2025/01/04/passkey-marketing-...

joshstrangetoday at 6:08 PM

My biggest issues with Passkeys is how inconsistently they are implemented and how opaque they attempt to be.

I understand SSH keys, I've been using them for decades, I know where they live, I know how to secure them.

Passkeys are murky as fuck. Is your PW manager supported? Do they sync? Where are they stored? How can I move to another PW manager if I want to in the future? Can I have more than 1 passkey per site? And the list goes on.

I _know_ some of you out there can answer some/all of the questions above but it's mostly on a per-site basis. Passkeys take too much of the control out of my hands and I don't like that.

Even more than that, I hate how they are trying to be pushed on me at every turn. Login -> Want to save a passkey (but they never call it that, they use some other confusing euphemism)? I click "No" and then it proceeds to pop 1Password's UI, then I dismiss that and it opens Chrome's passkey save UI, I dismiss that, and then it opens the OS's passkey UI. It's incredibly disrespectful and unclear.

I never use anything but 1Password but somehow everyone (OS and Browser) try to reach their grubby hands in. This is what scares me, I don't like having to be on high-alert to not accidentally save a passkey in Chrome or Safari and not realize until I'm on a different device and notice it's not in 1Password.

Lastly I trust the developers implementing passkeys... none, I trust them none, zero, zilch. I don't trust them to pick the right defaults, I don't trust their recovery options, and I know they will always pick the configuration that benefits them and not me.

No, for now I'll stick with my as-long-as-you-let-me-make-my-password random passwords which I never copy/paste into random website and be perfectly safe, thank you.

qurrentoday at 7:20 PM

Reminds me of Yishan Wong's description of OpenID's failure:

https://www.quora.com/What%E2%80%99s-wrong-with-OpenID-Why-h...

modelesstoday at 4:59 PM

I find Google Password Manager makes passkeys pretty easy to use. As long as you don't accidentally create a passkey some other way. Hopefully websites will adapt to the reality of how people use passkeys in practice and some of the UX weirdness around them will disappear over time.

One annoying thing though is that while they recently added password sharing, they don't allow sharing passkeys. Basic passkey sharing would be nice, but it also seems possible to implement fancy sharing features that wouldn't be possible with password sharing. Things like sharing one time use passkeys or time limited passkeys or limited access passkeys or secure revocation of shared passkeys. I hope people are thinking about this.

show 1 reply
brachkowtoday at 6:43 PM

Passkeys work well when you have password managers with multi-device sync. While it is indeed trivial to get one, consumers don't like password managers in first place. And it is very hard to make person use password manager, instead of his john1988 type of password

apparenttoday at 6:10 PM

I don't use passkeys because I can't tell if they're a one-way door. If I use it once, can I still use passwords to log in in the future?

I also don't understand how the system works when things go wrong (someone hacks your account, etc.). I don't even understand all the ways things could go wrong with passkeys.

Seeing the comments here makes me realize I'm not stupid or ignorant for not understanding these things. Some people do understand them much better than me, but there is no universal answer that emerges after sufficient study.

I will continue to stay away from passkeys.

mnlstoday at 3:41 PM

I’ve read all the answers. I still don’t get it. I find it WAY more complicated than copy/paste or a browser extension that does that for me.

I hope it won’t become mandatory. (I honestly doubt).

techteach00today at 7:05 PM

I like the authenticator option. I literally cannot understand if that's the same thing as passkeys.

TitaRuselltoday at 6:26 PM

Security people don't care about usability. They genuinely think we are all CIA field agents.

Look I remember my PIN everything else is in Firefox password manager.

show 1 reply
epistasistoday at 5:01 PM

I think the problem was that there wasn't a "Best Practices" way of using them when they were launched, which really prevented describing them in a consumer-friendly way.

And web site implementors couldn't follow that golden path, or describe the golden path, so there's fragmentation in usage and meanings and practices, making it far more confusing.

I love passkeys, I want to eliminate any and all password-based logins and switch entirely to passkeys. It's such a better experience, it's a "physical" key that can be backed up to multiple devices, and thinking of it like a key for a physical lock really gets at the core of its capabilities. But locks can be used in many many ways! Maybe you need to open the lock and still tell the guard a password, which is weird, but how most websites still operate.

rglovertoday at 5:07 PM

This is mostly a complaint about bad copy/explainers in Google's UI. Passkeys, properly implemented, can be perfectly consumer friendly (e.g., Apple Touch ID is delightful).

ElijahLynntoday at 3:16 PM

I only use pass keys by storing them in 1password. Then I don't have to worry about the whole "lose/broke/replace a device" thing, which is inevitable. Then just be really good about keeping your backup codes etc with 1pass solid.

ghostly_stoday at 4:49 PM

We've all been through at least a couple rounds now of the security industry pressing us to change how we log in, ostensibly in our best interest: impractical complexity requirements, 2FA, "magic links," ridiculously short session expiry, whatever this bullshit is with the username and password on separate pages that make your password manager less convenient.

The only observable outcome of each of these changes has been making these products less convenient for us to use. At this point I don't think I am alone in being knee-jerk opposed to any further "improvements." I have yet to see a website make a case for a passkey being more convenient than what it is replacing, so I will continue opting out of them as long as I am allowed to.

voidmain0001today at 2:48 PM

It just so happened that Microsoft sent an email today to our M365 tenant administrators that SMS and voice for 2FA is being removed 1-Feb-2027 and that automatic enrollment to passkeys starts 1-Sep-2026. Bring on the passkey overlords. Although, LLMs say that passkeys are superior to passwords since it includes a public/private key setup with the private key saved to a device that requires a PIN or biometric to access the private key.

show 2 replies
mullingitovertoday at 3:17 PM

You’d think a head of product at a tech company would embrace a “it’s literally impossible to have your password stolen if you use this” technology.

show 1 reply
luciana1utoday at 5:14 PM

the real achievement of passkeys is making people nostalgic for passwords

eigencodertoday at 8:25 PM

I hate passkeys so much. They're so confusingly implemented.

827atoday at 5:21 PM

Passkeys are so, so, so bad. One of the worst things our industry invented. The sooner sites start leaving them on the wayside and just go back to TOTP, SMS, and Email codes/links, the better. These work. We solved auth. Its fine.

vayliantoday at 7:22 PM

Obligatory https://fy.blackhats.net.au/blog/2024-04-26-passkeys-a-shatt...

It's a shame, because WebAuthn is really great technology. But tech companies are botching the rollout.

EPWN3Dtoday at 4:35 PM

I don't know everything there is to know about passkeys or anything, but my reaction to most of these comments is "You're passing yourself off as someone who has relevant opinions about security, and you can't possibly imagine how these things work or how they're useful? Come the fuck on."

Passkeys are basically session cookies that are signed by a secure element in one of your devices at the time you log in. That's it. They cannot be phished because there is no password to steal. If I had to guess, the basic flow is something like this:

1. When the passkey is created, the device's secure element coughs up a public key or something to the server representing itself as a trusted device

2. When a user logs in, the server issues a challenge (basically a random number) to the device and says "sign this with a private key that corresponds to one of the trusted public keys I have"

3. The secure element signs the challenge and sends it back

4. The server goes through its list of trusted device public keys until it finds one that verifies the challenge response. If it finds one, it logs you in. If it doesn't, you don't log in

Step (1) is probably bootstrapped with a username/password and second factor like SMS 2FA, OTP, or email 2FA.

Even if this isn't exactly how they work, it's a plausible implementation. Nothing about this requires vendor lock-in. The various secure elements that can produce passkeys come from many different places, so I'm sure sufficiently motivated open source people could create a firmware TPM that is certified for use with passkeys or something if they cared enough.

🔗 View 25 more comments