Remix.run Logo
abustamam a day ago

I signed into my Playstation account on a new phone. It told me to make a passkey. Its safe. So i said ok.

Later I tried to sign into my Playstation account on my computer and I couldn't. It said I needed to use my passkey.

I went back on my phone and deleted my passkey.

FWIW, Nintendo seems to have nailed the concept of passkey. I can sign in anywhere. If I'm on a new device, i just use my email password and 2FA.

I dont know why so many vendors find the need to complicate this. A secure solution implemented poorly can potentially be worse than an insecure solution.

One more anecdote on that front — I worked the help desk at a medical school during college. The IT department had their fun password requirements (number, special character, blood of a virgin, change every month, etc). Every single person who came to the help desk had their password written down on a sticky note on their laptops. These were med students , doctors, staff... everyone.

At some point these admins have to ask themselves whether they're actually helping people be more secure or if you're just making them jump through hoops.