Elektrine lite

← Feed

@lemmydividebyzero@reddthat.com

2026-09-26 07:42 UTC

I don't like passkeys | Ethan Hawksley

Replies (12)

  • @hummingbird@lemmy.world 2026-09-26 08:09

    Sadly did not dig into the whole “the other side decides which device you are allowed to use” topic, a feature inherently build into passkeys.

    Open ##4919876

  • @Technus@lemmy.zip 2026-09-26 08:18

    I feel like there’s some potential in password-derived passkeys, which would get around the storage and hardware lock-in issues. It’d essentially be a master password like for BitWarden, but instead of needing an app to store a bunch of generated passwords, the master password could be all you need to authenticate. Most of the sources of compromise for regular users would be eliminated because the password never leaves the client.

    Open ##4920013

  • @GreenShimada@lemmy.world 2026-09-26 08:24

    Passkeys are worthless trash, invented explicitly to save Microsoft and Google money on password reset server time. They do not solve session hijacking. Any attacker that has your granny on the phone to read them her password can also tell granny to go to a link and give them her session cookies.

    Open ##4920078

  • @audaxdreik@pawb.social 2026-09-26 08:40

    This article does a great job of articulating a lot of the uncomfortableness I have around passkeys. I’ve always said they make a lot more sense in an corporate environment but the level of control you lose in a personal setting is not commensurate with the protections and possible lock-in they offer. I just don’t like passkeys. They are an overly technical solution to what is mostly a human problem.

    Open ##4920226

  • @hornedfiend@sopuli.xyz 2026-09-26 09:07

    Passkeys are a good idea with an insufficient compatibility issue. In self host vaultwarden and it’s great with my passkeys and very convenient.

    Open ##4920421

  • @warm@kbin.earth 2026-09-26 09:16

    I think their biggest weakness is the vendor lock in. Using a 3rd party password manager is the best solution for most people, so they arent locked to their phone. But they are right in saying none of it is quite ready. I think the article is forgetting, they are password replacements, not account recovery replacements. Realistically, people are just as likely to forget a password, and account recovery proceedures still have to be in place. I dont see the issue there. Passkeys are good they are just being pushed before properly fully developed, but we are slowly getting there.

    Open ##4920481

  • @psycotica0@lemmy.ca 2026-09-26 12:25

    I don’t know that OP is wrong per-se, but I think they’re overstated a bit. Their statement that passkeys are better than people using the same password, but are a step back for people using a password manager, is maybe a bit much. It’s basically the same, but sometimes better. Most of their drawbacks are the hardware implementations, but that’s already true of people using hardware 2FA, and corporate management, which is already a problem if you use Apple’s or Google’s existing baked-in password managers. But if you don’t already have both of those problems, the standard is basically just “instead of having the password manager pretend to type in a box, what if they dumped something into the stream directly”, and that extends to what if the UI didn’t ask for anything and just said “hey, do you want to login? Just let me know and it’s done” And, like, should you be able to export from Apple’s built in store to migrate? Absolutely, but if you never used Apple’s passkeys in the first place, because ugh gross, then it’s not a problem you need solved yet. There is one problem I’ll admit, which is that it’s easier to make a sketchy password manager that just pretends to be a keyboard. I myself don’t actually use passkeys because I sync my passwords with git and use pass, which is cool and I love it. And then I type them using a dmenu script and xdotool, which is silly and I love it. But that doesn’t work with passkeys which I can definitely store in git, but would require a real actual connection between my browser and the tool, in a way that I don’t think currently exists. But just because I can’t use my sketchy crap, doesn’t always mean it’s a step back 😛

    Open ##4920622

  • @Passerby6497@lemmy.world 2026-09-26 18:08

    I really wish that SQRL had taken off, as it solved most of the problems noted. It was effectively passkeys that you generated on the fly based on your private key (which you can back up and restore to other platforms if necessary) and the website domain by scanning a QR code (or clicking rh QR code if your on the same device) and sends the signed challenge to the website to auth you. No need to login to your manager on random systems, no issues with platform lock-in, no worries about dedicated hardware, no worry about losing your access if your device dies (assuming you backup your shit).

    Open ##4920823

  • @pleksi@sopuli.xyz 2026-09-26 17:44

    I dont understand the issue. Arent passkeys and password in any case just stored in a pw manager nowadays?

    Open ##4921747

  • @DJKJuicy@sh.itjust.works 2026-09-26 17:25

    There is still nothing better than passwords. I don’t want my access to be tied to a specific device. Devices get lost, or break. I don’t want someone to be able to use my face or finger or eyeball to access my data. You can legally be compelled to unlock a device with your biometric security. So current biometric security sucks. And passkeys suck. Also, though…passwords suck for all the reasons that we all already know. There has to be some better method that the owner can have full agency over, I just don’t know what. I don’t have the answers.

    Open ##4922482

  • @ouch@lemmy.world 2026-09-26 21:08

    Good article. Currently passkeys are too much of a vendor lock-in to big tech. Bitwarden support alone does not change that.

    Open ##4925469

  • @muzzle@lemmy.zip 2026-09-26 14:18

    For users who previously reused passwords across all their sites, passkeys are a huge step-up. That is exactly why passkeys are a good thing. Basically everyone reused passwords everywhere.

    Open ##4926288