logoalt Hacker News

proniktoday at 8:40 PM0 repliesview on HN

I'm probably not the only one to have a deep distrust in passkeys. I've deep-dived in to what they are and how they work and I think I can accept them on their technical merits, but I can't shake the feeling that the adoption has been way faster than we've been used to, for whatever reason. I think it was half a year between the settling down of the specification to being bombarded by a "Get a passkey!" from every goddamn website on this earth. I don't really see what the conspiracy to move the whole world to passkeys would be here, but it certainly feels like there is one.

I think my problem with passkeys is the same as with almost everything today: if I lose my phone, my digital life will be almost as difficult to recover as if I lost my ID and my birth certificate at the same time. Yes, that's why you don't create one passkey (phone), but maybe two or three (browsers), but that's mental load on myself -- I don't even try to explain that stuff to my parents, even something as (somewhat) easy to use as a password manager is out of their scope. Add TOTP and passkeys on top of that and you've got perfect security that no-one in their right minds is using. No idea how to resolve the problem, but it's not by shoving a solution down our throats with a vengeance.