| ▲ | kenrick95 4 hours ago |
| Passkeys have a marketing problem where no one is able to describe simply what it is without having to use technical jargon. There's also the problem where each OS tries too hard in pushing this to the face of end-user |
|
| ▲ | ryan-duve 3 hours ago | parent | next [-] |
| > Passkeys are passwords your second device makes/types for you, without you ever seeing it. My bigger problem with passkeys is how there's no universal way to register more than one device (in case the first one is lost). |
| |
| ▲ | jmbwell 2 hours ago | parent | next [-] | | This burden is on the site using passkeys. There should be some equivalent of “My Account > Security > Passkeys > Add Passkey.” There often isn’t, which is an incomplete implementation. And yes it’s frustrating. | | |
| ▲ | alienbaby 15 minutes ago | parent | next [-] | | It doesn't matter whose problem it is, it shouldn't be there. | |
| ▲ | account42 2 hours ago | parent | prev [-] | | Sites didn't need to do anything special for this use case with passwords so it is a passkey problem. |
| |
| ▲ | blackdahlia313 3 hours ago | parent | prev | next [-] | | Proton Pass. I moved to it and love it. | | |
| ▲ | malfist 3 hours ago | parent [-] | | Proton Pass hardly meets the bar of "universal way to register more than one device" Proton Pass is a specific way to do that, but not a universal way. Bitwarden can't use proton pass to move keys around, google can't, firefox can't. |
| |
| ▲ | 3 hours ago | parent | prev [-] | | [deleted] |
|
|
| ▲ | cfiggers 3 hours ago | parent | prev | next [-] |
| Imagine a password, but it a) types itself for you and b) detects when it's being sent to an impostor site and blocks them from seeing itself, so it can't be phished. Tada, passkeys. |
| |
| ▲ | rcxdude 3 hours ago | parent | next [-] | | Cool, where are they stored? (I know the answer: 'it depends', and that's the big problem with their usability: most users haven't a clue what the answer is and most tech support can't answer that question straightforwardly because it depends on some decisions the user probably didn't even realise they made). | | |
| ▲ | iamnothere 3 hours ago | parent | next [-] | | On my keychain in a USB hardware token. With a couple of backup tokens in fire safes. | | |
| ▲ | rcxdude 3 hours ago | parent | next [-] | | If you're using a USB hardware token your knowledge of it is at least an order of magnitude better than the median user's. I know where my passkeys are stored, I don't know where my family member's passkeys are stored and neither do they. The same is true for most of my otherwise fairly technical co-workers. | | |
| ▲ | iamnothere 2 hours ago | parent | next [-] | | There needs to be industry and government leadership on this to gradually require hardware token usage, for at least critical financial and government applications. Right now everyone is putting their energy behind passkeys, but those are much harder to understand than a physical token. I don’t know any non-technical people who understand how passkeys are normally tied to the device (or the manufacturer-provided cloud account in some cases), how to set them up on a second device, why you might want to do that, etc. And many technical people still don’t get it either! | |
| ▲ | faust201 2 hours ago | parent | prev [-] | | Then that family member does not worry like you do worry. The main point is assuming one can have a proper security for Google account - everything else becomes easy. The fearmongering of losing google account should stop. Yes, some people lose it. There are a larger proportion losing/getting pwned by repeat use. For the majority - just pressing the fingerprint to access an account (like amazon/eBay) via passkey is great. Fairly technical co-workers - I used to suggest them to buy USB security key few years ago. Now that same fairly technical some how has at least 2 devices with them - so they just skipped the USB security key need - and just use Google (in Android) or iPhone in Apple ecosystem. Everything just works. Yes, there will be a poor soul that may lost everything with only one device. | | |
| ▲ | Aerroon 11 minutes ago | parent | next [-] | | >Then that family member does not worry like you do worry. Until they lose access to that account and then it becomes my problem to solve. | |
| ▲ | iamnothere an hour ago | parent | prev [-] | | People keep their entire lives in cloud accounts these days. Their passwords, financial history, copies of important documents, baby photos, etc. Losing access to it is incredibly disruptive and may result in unrecoverable losses. It shouldn’t be this way, but it is. |
|
| |
| ▲ | UltraSane an hour ago | parent | prev [-] | | The biggest issue with passkeys is that since most USB tokens that support them don't allow syncing the private key to a backup device you have to enroll ALL of them to every site that supports passkeys. This is annoying but it makes storing backups in secure offsite locations impractical. | | |
| ▲ | iamnothere an hour ago | parent | next [-] | | This is a fair criticism and needs work, I have some short thoughts on it here: https://news.ycombinator.com/item?id=49755217 | |
| ▲ | EvanAnderson 43 minutes ago | parent | prev [-] | | It's beyond annoying. It's creating needless toil that no "normies" will ever actually do. I'd love a hardware sold in multi-packs and "born" at the factory with identical internal device key encryption keys (DKEK). I'd love, even more, if a token just allowed you to "commission" new ones w/ a user-specified DKEK on first use. I'd use one token as a daily driver and store the other(s) in safe location(s), empty of my personal key material. (Or, if I can just commission a new token w/ my DKEK, store a printed copy of my DKEK in a safe location.) Give the token a mechanism to "type" a backup of its internal state, encrypted with the DKEK, as a USB HID keyboard. That gives me an easy way to backup the token each time I enroll a new website. If I lose my daily-driver token I just pull a spare from storage, import my last backup, and I'm up and running. That would kick ass. No "You just need to buy two tokens and enroll them in every website" bullshit. | | |
| ▲ | iamnothere 9 minutes ago | parent [-] | | Maybe each token also needs a second key, with the DKEK used for authentication and the second used only for revocation. The main reason not to reuse the DKEK is so a lost key can be easily decommissioned. You would need some out of band way to collect and save your key IDs and publish revocations. I’m not sure if this would work from a security theoretic perspective, need to think about how the request is signed and transmitted so someone can’t fake a key being “alive” when it’s really “dead”. I do agree this would be incredibly useful if it can be made to work. |
|
|
| |
| ▲ | wolvoleo 3 hours ago | parent | prev [-] | | In a secure vault on your phone | | |
| ▲ | malfist 3 hours ago | parent | next [-] | | How do I use it on my desktop or laptop then? What if I switch browsers on my phone? What if I get a new phone? What if I change from android to iOS or visa versa? What if I need to log into the site on my Wii U's browser? | | |
| ▲ | Johnny555 an hour ago | parent | next [-] | | You can let Apple sync your passkeys between devices using iCloud Keychain. Then you can create a passkey on one device and have it available on all of your devices. | | | |
| ▲ | faust201 an hour ago | parent | prev [-] | | as long as you have one working device all will be OK. Either you scan the QR code shown by the website. or if you did login to Chrome with google account then desktop or laptop will just sign you -friction less. Same with iCloud account. If you browser vendor has implemented passkey then all good. Most things are built for the majority users. Most don't change. Most don't debate browser wars in hn. Life is like that. For Wii etc. You just scan the QR code shown in the TV interface. all just works. Yes, if you want 100% privacy and will do only your own dovecot server then it is not for you. |
| |
| ▲ | mystifyingpoi 3 hours ago | parent | prev | next [-] | | So if I drop my phone to the toilet, I will forever lose access to everything? Since the vault is on my phone. | | |
| ▲ | faust201 an hour ago | parent [-] | | A majority have more than one phone. Or at least they can get a new SIM card and sign into the iCloud account. Then all passkeys are synced from cloud. Yes, if you are edward snowden then not for you. For rest of us - it is useful | | |
| ▲ | recursive an hour ago | parent | next [-] | | This is crazy. I have one phone and zero iCloud. I don't think I'm that unusual. | |
| ▲ | chrystalkey an hour ago | parent | prev | next [-] | | Idk how much money you must be having, but all of my bubbles only ever go with one device | |
| ▲ | caryme an hour ago | parent | prev [-] | | A majority have more than one phone? |
|
| |
| ▲ | rcxdude 3 hours ago | parent | prev | next [-] | | Not always. And which vault? There can be multiple on a given device. This isn't some hypothetical 'mollify the user's worries' question, this is an important practical question of what do they need to worry about losing access to. Trust me when I say that most users I have talked to have absolutely no idea about this, and usually only find out when they've already lost them. | |
| ▲ | cpburns2009 an hour ago | parent | prev [-] | | Great, what happens if I lose my phone? |
|
| |
| ▲ | alt227 2 hours ago | parent | prev | next [-] | | As others have pointed out, this is a terrible oversimplification which misses all the nuances which cause people headaches when using passkeys. To your point, I for example would add point c) - Is linked to the device you are using currently. If you want to use another device to log in you are in a world of complexity and pain. | |
| ▲ | flerchin 3 hours ago | parent | prev [-] | | But how do I type it into my new phone? | | |
| ▲ | vntok 2 hours ago | parent [-] | | It depends. Are you part of the 99.99999% users of one of iOS+Apple or Androidlike+Google/Tencent or HarmonyOS+Huawei? If that's the case, you don't need to as the key is automagically saved by your OS' platform and synced with your new device. Otherwise, you're such an extreme outlier that you probably either know what you're doing or can find out by yourself, right? | | |
| ▲ | 6 minutes ago | parent | next [-] | | [deleted] | |
| ▲ | dspillett an hour ago | parent | prev | next [-] | | > … users of one of … Google …? If that's the case, you don't need to as the key is automagically saved by your OS' platform and synced with your new device. This absolutely does not encourage confidence in me. We all know how easy it can be to get locked out of a Google account and have no way of getting back in unless you have enough clout to make a huge noise online so a human there pays attention instead of you being stuck in the 'ol support-bot-run-around loop. It doesn't happen often when you consider how many users there actually are out there, but the potential inconvenience is high enough that “fairly rare in the grand scheme of things” is still enough to be reason enough to be wary. | |
| ▲ | faust201 an hour ago | parent | prev [-] | | The point is people like this usually are arguing as they hate adopting new tech. And they hate FAANG. No way to convince them. |
|
|
|
|
| ▲ | etatester 4 hours ago | parent | prev | next [-] |
| It's a key, what else do non-technical people need to know? Ironically on macOS we used to have an app called Keychain which unfortunately was effectively renamed to Passwords for non-technical users. |
| |
| ▲ | paulryanrogers 3 hours ago | parent | next [-] | | It's a digital key. Unlike physical objects they may reside in a TPM, a software vault, an export/backup, or any combination thereof. You may or may not be able to recover or migrate them, depending on where/how they were made. Therefore you may need multiple per service, or maybe not. Services which only allow one may end up locking you out with no recourse. You get to find out. None of this is obvious or self explanatory to normies. | | |
| ▲ | etatester 17 minutes ago | parent | next [-] | | That's false. It's a digital key and it doesn't matter where it's stored. My key is on iCloud and it can be unlocked with my many recovery methods and contacts https://support.apple.com/en-us/102641 As for normies, passkeys or passwords it doesn't make a difference. Either you have people who use love1969 everywhere or those who constantly lose their passwords. All passkeys accounts for normies require an email or phone number, which is what you can use to recover a password or passkey exactly the same way. | |
| ▲ | kskdkwkdkwk 3 hours ago | parent | prev [-] | | Probably because these caveats and weird behaviours are platform-dependent, not really the passkey’s fault. Passkeys really are not any more difficult to explain than 2-factor authentication. Anyone who’s currently been able to actually create an Apple or Google account and successfully navigate their devices up to a passkey screen will be able to grok how it works. People around here really ought to stop thinking users are complete idiots. Hell, you don’t even to scroll that far to read people calling users “normies” for crying out loud. What is this? High school? | | |
| ▲ | cpburns2009 an hour ago | parent | next [-] | | I don't care about the theoretical sufficiently advanced keypass implementation that works perfectly. I want to know about the half baked ones in the real world that I'll have to deal with. | |
| ▲ | alt227 2 hours ago | parent | prev | next [-] | | You obviously dont have to deal with anybody who doesnt know how or want to use computers. | |
| ▲ | paulryanrogers an hour ago | parent | prev [-] | | Do you know how many Google and Apple accounts my boomer parents have? Roughly one per smart-phone that they've ever used. They don't know the passwords or even the email address of any of them, not even the latest. | | |
| ▲ | etatester 15 minutes ago | parent [-] | | Tell me how passkeys makes this any worse. If one's digital life is a mess, there's no magic solution to it. |
|
|
| |
| ▲ | arwineap 3 hours ago | parent | prev | next [-] | | The keychain and passwords app are separate and keychain still exists I always operated under the assumption that the passwords app was just a more casual view into the keychain Maybe that's a bad assumption | | |
| ▲ | joombaga 3 hours ago | parent [-] | | They're separate stores. I was under the same assumption until I tried to use `security` to get a saved password. It doesn't work, and as far as I know there is no CLI for the Passwords app's store. |
| |
| ▲ | lezojeda 3 hours ago | parent | prev [-] | | [dead] |
|
|
| ▲ | mikepurvis 2 hours ago | parent | prev | next [-] |
| Surely it's a pretty easy pitch to average Joe: Using a passkey takes the place of typing in a code they sent by text or email. That's a pain point in everyone's day that should make the benefit easy to understand. |
| |
| ▲ | alt227 2 hours ago | parent [-] | | ok cool so when somebody logs into a site on their phone and sets up a passkey, then goes to their laptop and tried to log into the same account, how do you easily explain how to deal with this situation? | | |
| ▲ | kps an hour ago | parent | next [-] | | You don't. A laptop might still be a general-purpose computer under the owner's control, and we discourage those. | |
| ▲ | stetrain an hour ago | parent | prev [-] | | What I have seen is that the site gives you a QR code to scan with your phone. People are already used to needing their phone to sign in via an Authenticator app or SMS code. |
|
|
|
| ▲ | jmbwell 2 hours ago | parent | prev | next [-] |
| I tell people a website is like a payment terminal. Your device is like your debit card. A password is like a PIN on the card. A Passkey is like a chip on the card. Logging into a site with your device is like putting your card into the terminal. The site can ask for a password the way the terminal asks for a PIN, but if your device supports Passkeys, that’s like your card having a chip, and it’ll use that instead. So think of Passkeys like using a chip card. I dunno how well this analogy works down to the last detail but it has gotten it across to all the parents I’ve used it with |
| |
| ▲ | seirim an hour ago | parent | next [-] | | Great analogy, am going to use that going forward, thank you. | |
| ▲ | dgunay an hour ago | parent | prev [-] | | Do most people understand why cards have a chip in them now? |
|
|
| ▲ | Spide_r 3 hours ago | parent | prev | next [-] |
| That's the main thing I wish was done better. There was barely any actual lead up from the perspective of an average person. Just a new unfamiliar flow on half of the login screens that they use. Sure, its explained. But not in a satisfactory way that would reach all users at their level. This is a bit of an exaggeration and out of proportion, but I think my ideal would be one of the big tech companies should have bought out something like a super bowl ad. Something that actually conveys the idea "hey, we know you've used passwords since you were able to type on a keyboard, but here's new technology that's better and here's why" in plain language that the average person can understand. Unfortunately, XKCD 2501 continues to be relevant. [1] [1] https://xkcd.com/2501/ |
| |
| ▲ | Al-Khwarizmi 3 hours ago | parent [-] | | The average person? I have a Master's and PhD in CS, code regularly, and have followed and used all the cool technologies from the days of gopher, telnet and Mosaic to crypto, and lately LLMs. And I still don't have a clear enough picture of passkeys to know really basic things like "what if we have a family computer but each wants to access their private accounts and keep the others from accessing?", "what do I need do to login from an airport computer?" or "what should I do if my phone is stolen?" If it's that unclear to me, I can't imagine how it can be to the average user. The way they explain them is atrociously unclear, borderline negligent for services that nag people to activate it for accounts where they may hold valuable data for their personal lives. And while I don't want to spend much time finding out the details as long as I have the option to decline them, I suppose if they can't explain it and convince people of its advantages, it's because it's just bad tech. | | |
| ▲ | alt227 2 hours ago | parent [-] | | I cant upvote you enough for this very concise explanation of passkeys pain points. |
|
|
|
| ▲ | dboreham an hour ago | parent | prev | next [-] |
| As implemented they also lack conceptual integrity: you get them somehow (where are they?), and somehow you can use them (how, exactly?) but you can't enumerate them anywhere, see them, see where they came from and what they can do for you. |
|
| ▲ | lezojeda 3 hours ago | parent | prev [-] |
| [dead] |