hn.today

I don't like passkeys

hawksley.dev666 points652 comments
Screenshot of I don't like passkeys

This argues that while passkeys are technically strong - phish-resistant and asymmetric so servers can't leak usable credentials - they are a poor fit for most personal users today because they raise practical risks that matter more day-to-day: permanent lockout, automated account bans, and device loss. Recovery paths like SMS, email links, and security questions remain the weakest link, and without reliable recovery users can lose access entirely. Hardware security keys can’t be backed up or moved, forcing people to buy and enroll multiple keys and hit storage limits (often 25-100 accounts per key, up to ~300 on premium devices). Platform-synced passkeys from Apple or Google centralize identity and risk losing all passkeys if that account is suspended, and FIDO export/interoperability is still immature compared with the simplicity of exporting a password string.

Third-party password managers that try to store passkeys fight fragmented OS APIs and lack the polished autofill UX passwords enjoy, especially for native apps. Passkeys also break down on unfamiliar or colleague devices where ports, Bluetooth, or hybrid QR flows are inconvenient or unreliable. The conclusion: passkeys make sense for enterprise deployments but today pose more practical harm than benefit for many individuals; a combination of randomly generated passwords in a password manager plus an independent TOTP app gives better day-to-day resilience, while passkeys mainly help those who previously reused passwords.

Read on hawksley.dev652 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Security

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.