This argues that while passkeys are technically strong - phish-resistant and asymmetric so servers can't leak usable credentials - they are a poor fit for most personal users today because they raise practical risks that matter more day-to-day: permanent lockout, automated account bans, and device loss. Recovery paths like SMS, email links, and security questions remain the weakest link, and without reliable recovery users can lose access entirely. Hardware security keys can’t be backed up or moved, forcing people to buy and enroll multiple keys and hit storage limits (often 25-100 accounts per key, up to ~300 on premium devices). Platform-synced passkeys from Apple or Google centralize identity and risk losing all passkeys if that account is suspended, and FIDO export/interoperability is still immature compared with the simplicity of exporting a password string.
Third-party password managers that try to store passkeys fight fragmented OS APIs and lack the polished autofill UX passwords enjoy, especially for native apps. Passkeys also break down on unfamiliar or colleague devices where ports, Bluetooth, or hybrid QR flows are inconvenient or unreliable. The conclusion: passkeys make sense for enterprise deployments but today pose more practical harm than benefit for many individuals; a combination of randomly generated passwords in a password manager plus an independent TOTP app gives better day-to-day resilience, while passkeys mainly help those who previously reused passwords.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.