Remix.run Logo
fhdkweig 2 days ago

I think it is important to explain why I and others are so reluctant to this.

In security, you identify reasonable threats. You can't protect against all of them, and some may even be contradictory.

When I get a call on my phone that says "Potential Spam", I have never even once in my life decided to run over to my list of passwords and hand them over to the President of the Spanish National Lottery. Not even once.

But on many, many occasions I have dealt with a simple system that was replaced by a more complicated one and something in that Rube Goldberg machine broke down and deprived me of access to money, email, even a parking permit to my office.

Passkeys seem to protect against the former case that has never happened to me, while increasing the chances of the latter that has happened way too often.

zdp7 a day ago | parent | next [-]

You aren't considering all the advantages of passkeys.

Passkeys only work on the domain they were created for. Password managers usually default to providing the password of the current website, but nothing stops you from pasting that in at any site.

There is no danger to the credential db being stolen. The website only has your public key.

A website using passkeys can support cross device authentication which allows you to login to on a computer without it ever seeing your credentials.

I'm sure that isn't a complete list. My last point, despite all the comments here, there is no vendor lock in. Bitwarden provides an open source self hostable option. On both Android and Windows 11, you can change your passkey provider to Bitwarden. A proper passkey implementation, should allow multiple passkeys to provide access. My bank does exactly that.

Izkata a day ago | parent [-]

> Passkeys only work on the domain they were created for. Password managers usually default to providing the password of the current website, but nothing stops you from pasting that in at any site.

Considering how my bank has changed the sign-in domain three times (as well as some other sites), I consider this a feature, not a shortcoming.

nozzlegear 2 days ago | parent | prev [-]

It should go without saying that, while you've never given your passwords over to the President of the Spanish National Lottery, there people who do get duped into doing exactly that all the time.

fhdkweig 2 days ago | parent [-]

I don't like the default option being to treat everyone like they are a moron. I don't like being treated like a moron.