Remix.run Logo
MBCook 2 days ago

I will never understand how a small group of tech savvy people are heavily confused and against a simple and more secure system.

You want anecdotes? Ok. I’ve had elderly adult relatives who aren’t good with their devices tell me unprompted they’re using them and like them when I mentioned the word out loud to myself using my phone around them.

These are people who don’t know the difference between apps and the web. Who have 200 tabs open because they don’t know what tabs are so a new one just gets opened automatically all the time. Can’t tell some websites apart. Who change their passwords on every login to some sites because they can’t get sign in right.

Yeah if you want to write them down or refuse to save passwords outside text files or demand they live on a security key on your keychain you’ll have a hard time. You’re being 0.0000001% of the user population. You’re not representative.

They are a MASSIVE UX win. A MASSIVE security win.

I’ve logged into my work computer with a passkey on my personal phone, no issue. It’s fine. They’re backed up locally. It’s fine.

The biggest problem, which is getting better and somewhat a transition problem, is sites using terrible UX to trigger the workflow. Those that follow the suggestions or close to it are great.

I love passkeys. I just don’t get the confusion.

AlexandrB 2 days ago | parent | next [-]

My elderly mother accidentally created a passkey (in Chrome) for one of her accounts. Normally, I try to keep a copy of her accounts and passwords in case she forgets them so I can help her out. With the passkey, this is impossible.

She doesn't know how she created one, she doesn't know what it is, and I don't know how to explain to her that if her PC dies I won't be able to help her log back into her account. I'm not even sure how I'm going to migrate this thing to a new PC for her.

MBCook 2 days ago | parent [-]

Any decent password manager can handle all of those. Apple does. I’d expect the same of Chrome, Edge, Firefox and 1Password but don’t personally use any of them.

Why not just set yourself up to be able to access her password vault? Why is copying magic strings a better solution? You could have done that to get password access without passkeys existing. So they change nothing.

ivlad 2 days ago | parent [-]

If you are going to store passkeys in a password manager, the whole situation is no more secure than just using passwords.

Consider:

1. Password managers tie passwords to sites, so phishing-resistance is achieved. 2. Password managers allow long, complicated, individual password per web site, so compromise blast radius is 1.

TSiege 2 days ago | parent | prev [-]

I've yet to meet a non tech person irl who uses them. I went through the laborious process years ago setting my parents up with 1Password. They find passkeys very confusing addition. I have yet to see the massive UX win. If that were true I don't think we'd be having this conversation. Good UX becomes the natural state of things and we don't even notice. I've had trouble myself setting up passkeys correctly with my 1Password. This never happens with traditional passwords and 1Password

bombcar 2 days ago | parent [-]

The win for passkeys is login with faceID. That people actually use.

readread 2 days ago | parent | next [-]

My usernames and passwords auto-fill with faceID already. Lots of forms even (somehow?) auto-submit after that, don't even have to press a button.

MBCook 2 days ago | parent [-]

The forms don’t. The browser does. There’s a set of heuristics.

The problem with autofill is it doesn’t help if the person keeps screwing up their passwords, changing them, or ends up with 5 different passwords in the password manager for the same site.

All of which I’ve seen.

MBCook 2 days ago | parent | prev [-]

There’s far more than that.