Remix.run Logo
elteto 5 hours ago

While the technology itself may be great (I don't really know since I don't use them) it has been co-opted by the tech conglomerates as another form of isolating and walling off users into their ecosystems.

And honestly, nowadays, if tech companies are pushing really hard for something then that is an immediate red flag for me and it bears more scrutiny. One of those "if you see them running that way you run the opposite way".

reddalo 4 hours ago | parent | next [-]

Exactly. That's why I'll never use passkeys: they're just another way to force us into a commercial walled garden.

Passwords with 2FA are simply better and more freedom friendly.

jwcrux an hour ago | parent | next [-]

How do you see passkeys as a walled garden but not 2FA? You presumably store your 2FA seed in a password manager.

dsl 31 minutes ago | parent [-]

I can write my own authenticator implementation in a few hours by hand, maybe 5 minutes vibe coded. https://www.rfc-editor.org/info/rfc6238/

Even if you throw your phone into a volcano and buy a new one, you can still receive SMS verification.

apexalpha 3 hours ago | parent | prev [-]

I just bought a passkey... It's a USB device, completely separate from any big conglomerates.

reddalo 2 hours ago | parent [-]

But then you need to phisically carry it along with you everywhere you go, if you want to log into a service :/

finaard an hour ago | parent | next [-]

That's not the problem for me - I carry a bunch of tokens with me anyway (all my banking stuff is on hardware tokens, for example). My problem is more: My browsers run in containers or VMs, intentionally without hardware access. Getting passkeys to work there would be quite a bit of effort.

apexalpha an hour ago | parent | prev | next [-]

Yes, it’s like a key. :)

Though realistically I use a passkey for services I care about and a password manager for the rest.

eikenberry an hour ago | parent [-]

Keys can be copied very easily. It’s one of their primary features. Can you easily copy your USB key?

jazzyjackson an hour ago | parent [-]

Yubikeys are Secure Enclaves designed to not be copyable

SoftTalker 2 hours ago | parent | prev [-]

And hope you don't lose it, or leave it in a pocket when you do the laundry, or plug it into a faulty USB port that zaps it, etc.

vel0city 2 hours ago | parent [-]

My yubikeys have survived dips in the ocean, spilled beers, run over by cars, dropped in pans of used motor oil, left out in thunderstorms, and multiple trips through the washer and dryer. They're still fine even after a decade.

hnfong an hour ago | parent [-]

Nothing survives the xkcd 538 wrench attack.

alibrarydweller 2 hours ago | parent | prev | next [-]

I did a deep dive on this since progressively more places are taking a hard line about Passkeys.

The most flexible, independence preserving thing to do is to use a third party password manager like Bitwarden, and make that the default passkey flow for your devices. If desired, you can self-host something like Vaultwarden so that you can both keep the keys independent of third parties and walled gardens and also propagate them to other client devices.

To be clear I'd much rather not have learned / implemented any of this, and I don't use passkeys unless forced, but this seems like a valid coping strategy.

spider-mario 5 hours ago | parent | prev | next [-]

It’s a bit ironic that Apple is the one that lets you export them.

rcxdude 5 hours ago | parent [-]

They're also not supporting device attestation which would allow websites to insist on particular implementations of passkeys.

dingaling 3 hours ago | parent [-]

That's more because attestation breaks their passkey cross-device sync process, rather than out of benevolence.

mschuster91 5 hours ago | parent | prev [-]

> And honestly, nowadays, if tech companies are pushing really hard for something then that is an immediate red flag for me and it bears more scrutiny.

The reason is the ever increasing number of hijacks of social media presences and code hosting portals, with the latter being a serious financial threat. Done right, passkeys stay in the Secure Enclave, at least for anything Apple and most of the Android sphere. There is no reasonable way to obtain login credentials for accounts protected by passkeys without physical access to the user's device(s).

zamadatix 4 hours ago | parent | next [-]

The doubt is more "how will tech companies use passkeys as an excuse to do something stupid" than "passkeys themselves must have inherent problems because tech companies are pushing them".

Passkeys could be the savior of all security problems worldwide from a capability point of view and tech companies would still ruin it by trying to force ways it pushes you into their ecosystem instead of just being whats both secure and convenient.

As an example, I have 3 different passkey _APPS_ on my phone and cannot go down to one because of various reasons with each (such as MS authenticator, forced for integrating to Microsoft at work).

iso1631 5 hours ago | parent | prev [-]

> There is no reasonable way to obtain login credentials for accounts protected by passkeys without physical access to the user's device(s).

Click "I lost my device", enter contact, get a reset link via email/sms

terminalbraid 4 hours ago | parent | next [-]

Email and SMS are not reasonable and both have an extraordinary number of flaws.

jmbwell 4 hours ago | parent | next [-]

So use the recovery codes. Or scan the QR code and auth from another device

I’d buy that there are too many different confusing ways to recover from this situation, but not that it’s impossible

Barbing 3 hours ago | parent [-]

>use the recovery codes.

Fun fact: Google can decide to reject these. Lose access to the original device, try to rely on recovery codes to login with known current password on family member’s device… nope!

iso1631 3 hours ago | parent | prev [-]

Sure, yet in the real world those are the acceptable means if you want your customer to continue to pay you when they've lost their phone.

4 hours ago | parent | prev | next [-]
[deleted]
gong_hits 15 minutes ago | parent | prev [-]

[dead]