logoalt Hacker News

I don't like passkeys

265 pointsby ethanhawksleytoday at 12:06 PM218 commentsview on HN

Comments

hahn-kevtoday at 12:44 PM

I like using passkeys in bitwarden from Firefox, I just wish it didn't popup a dialog that's usually behind the browser.

micromacrofoottoday at 12:37 PM

The experience is also junk if you're using a password manager, I have passkeys that I'm not sure if I saved to the OS manager or my password manager... mostly my fault but I enter passwords so many times a day it can be hard to stay on top of which UI I'm clicking yes in to store them.

Password managers are great IMO, I can use some absurdly long password, backup is reliable, I can use them across devices. For extra secure stuff 2FA works the same, I've got an app with codes I can easily back up and use from multiple devices.

Passkeys tend to obscure everything and take away a lot of control.

pqdbrtoday at 1:44 PM

Related: the UX is currently terrible. Every time I go to a website that has passkey flow, I'm presented with: - MacOS native UI; which I cancel; then I see - Bitwarden UI; which I cancel; then I see - Chrome UI; which I cancel;

Like, seriously?

alpertoday at 1:33 PM

I had to setup a Passkey recently and wanted to store it in 1Password and the experience was quite absurd.

I don't know who designed this or who thinks these are acceptable affordances, but it seem to be part of the same disingenuous push that's behind passkeys in general.

silon42today at 12:31 PM

Is there a reason why passkeys couldn't be used in "expire-periodically" mode?

show 2 replies
commandersakitoday at 1:38 PM

Passkeys are a great way for attackers to have a secondary login into your account (e.g. Outlook, Gmail, etc.)

VCFundedGenYertoday at 1:07 PM

This is generally the same experience I've had.

Microsoft is especially poorly prepared for this - Often if you have a passkey, it will CONTINUE To ask you to create a passkey (a new and different one), and it may save it in a different place, which is infuriating.

Strong password + MFA is the way, and I don't see that changing.

thousand_nightstoday at 2:25 PM

am i the only one on HN who really likes passkeys?

so much better than fumbling around with a password managers

blackdahlia313today at 12:49 PM

Passkeys have made my life very easy. Especially using Proton Vault.

If you think passkeys aren't ready yet, blame the people implementing it on their platforms.

show 1 reply
ChrisMarshallNYtoday at 1:26 PM

Eh. Not worth complaining about.

Passkeys work nicely, and I'll use them, in cases where I want decent security, but I don't consider them the "Philosopher's Stone" of regular end-user security. I think they are still a bit too "fiddly" for your average Joe[line].

esafaktoday at 1:49 PM

Well I like them, as an option. I offer using passkeys and email interchangeably; if you lose one you can recover with the other. Passwords, SMS, TOTP are out for me.

OutOfHeretoday at 1:47 PM

Passkeys lock you into a third-party provider ecosystem that you really should be trying hard to avoid getting locked into. They also add a quantum safety risk. Stay away.

EPWN3Dtoday at 1:42 PM

I went in expecting yet another screed about how passkeys were not issued by RMS in a FOSS encyclical, and therefore not only were they insecure, but they were also a morally bankrupt abomination. I was pleasantly surprised to read an actual thoughtful critique, albeit one I largely disagree with.

The author's assertion that the greatest risk to an individual is account lockout versus phishing or password harvesting is just not grounded in reality. I get phishing emails and SMSs daily. The criminal ecosystem running these campaigns is extremely active already and set to become even more so with LLMs. These campaigns are by far the biggest threat to normies.

Whereas account lockout happens most often with multiple failed password entries, which passkeys completely eliminate. I just don't know where this risk evaluation comes from.

The author also points out that even with passkeys, if you're able to also log in with e.g. security questions, you still have a much weaker security footprint for that account. This is true, but it's also true of a TOTP second factor. So I'm not sure what the criticism is here.

The exportability argument is a real weakness and something I'd like to see addressed. Passkeys don't have an equivalent for backup TOTP codes that you can just write down somewhere or trivially store yourself. But it probably wasn't in v1 because the people who designed passkeys figured that websites would not go all in on them immediately and would preserve other authentication methods, which is exactly what's happened.

Finnucanetoday at 12:53 PM

I've resisted passkeys for some of the reasons listed. I use third-party password managers, they're device/system independent, and I can export the data when I want to. I don't see passkeys as a big advantage, or perhaps I should say the bigger advantage isn't really for the _user_.

Of course, at the rate we see security failures everywhere, I'm not entirely convinced writing your passwords on post-it notes wasn't such a bad idea after all.

show 1 reply
junarutoday at 12:31 PM

They exist for sole purpose companies can just shoot the "we have been hacked, but worry not your 'passwords' have not been leaked" email.

It's entirely one sided solution.

show 1 reply
whalesaladtoday at 12:54 PM

using them with 1password has been pretty effortless. 'want to add the passkey' sure why not. 'want to use the passkey?' sure why not. for me it works across devices/os/platform so not sure what the big gripe is tbh.

diego_moitatoday at 2:06 PM

I hate them, mostly because I am forced to use them.

They provide crappy usability, they're expensive, they're easy to lose, you can't use the physical keys when doing remote desktop access.

My job requires me to use them. I use only for the job and nothing else. For sites requiring 2FA, I use TOTP (time-based one time passwords) from KeePassXC.

lapcattoday at 1:04 PM

Two crucial things you can do with a password that you can't do with a passkey:

1. Write it down on a piece of paper and put it in a safe deposit box.

2. Read it on one device (or from a piece of paper!) and enter it manually on another device.

Plain text is the ultimate form of cross-platform portability. Passkeys are the ultimate form of vendor lockdown. The passkey vendors won't even allow you to view the private key, unlike with ssh keys, which you can also write down on a piece of paper. It's vendor cabal to destroy computing freedom in the name of "security", always the excuse. Tech company paternalism at its worst.

show 1 reply
deauxtoday at 2:03 PM

Passkeys suck because only the wealthiest 5% of the world is all-in on one ecosystem (such as Apple) while the remaining 95% uses a Windows laptop, an Android phone and (for the top 5-35%ish) maybe an iPad. All of these OSes push hard to get you to store your passkeys with THEM so it ends up a shitshow with everything scattered everywhere.

And why do the OSes push for this so hard? Because the goal of the execs is lock-in and control. And their lackeys here on HN who implement this stuff and their families are the 1% who are all-in on one ecosystem so they arrogantly believe "this all works great and the masses are just too stupid to get it".

tonymettoday at 1:52 PM

Username and password was a predictable flow. Passkeys are just a small component in the modern obstacle race of logging in. Every few months a new credential or ritual to access your own resources .

brettermeiertoday at 1:10 PM

I absolutely hate them and avoid them everywhere I can. I'm not bound to a single device or I don't want to get bound to some, and some pages quit your option with a normal password login after setting up a passkey. Absolutely frustrating.

oxcartctltoday at 1:36 PM

[dead]

T3RMINATEDtoday at 1:09 PM

[dead]

inquirerGeneraltoday at 1:48 PM

[dead]

dxjxjdjsssbtoday at 12:39 PM

[flagged]

show 4 replies
etatestertoday at 12:39 PM

As someone who uses a single password manager on my computer and phone, I don't see the problem with passkeys. I use Safari on both and I never even had to "set up" anything.

I can see why they would be problematic for people who otherwise live life with a single love2025 password though.

show 2 replies
karlsheatoday at 1:44 PM

Every time passkeys are brought up on HN it’s nothing but complaining and/or refusing to learn the basics about something new, but I’ve been switching to them on every site I can for months with literally no problems.

1Password everywhere, on iOS, Mac, and Windows. I’ve run into none of the issues elsewhere in the comments. Everything just works, including in-app logins.

Maybe your other password managers are just bad at implementing the right browser/OS hooks?

show 1 reply
xp84today at 2:24 PM

The article asserts with little proof that lockout risk is a big problem. But consumer sites themselves basically 100% of the time have a recovery path that amounts to a SMS code or emailed code.

The only part that is very persuasive is the part about storing your passkeys with Google or Apple integrations, and what happens if they ban your account. But the same argument would apply if you’re only storing your passwords in a Google or Apple password manager.

I use passkeys and I always store them in a password manager I control - but usually I also store another one in the OS on Windows, Apple, and Google. Best of all worlds. Also, I appreciate that idiots aren’t forcing me to “change my passkeys” every 90 months like they STILL do with passwords!

show 1 reply