Remix.run Logo
vanschelven 4 hours ago

Passkeys remind me of ipv6 in that they are a "solution" coming from the supply-side, without (apparently) having done any research in what motivates actual users (and what would motivate them to switch).

<<ducks>>

coldpie 3 hours ago | parent | next [-]

They make sense as a technology for businesses & their users. In that scenario, the owner of the account is not the user, but the business. It makes sense for the business to be able to place strong restrictions on how & where the user may log in, it fixes a lot of real problems businesses may have thanks to sloppy user behavior, and the business is also motivated to provide a way to fix broken logins. It's a good solution for that scenario.

But for regular end users where services are primarily motivated to take money from those users and lock them into their ecosystems, they are a usability disaster and yet another exploitation vector.

It's one solution for two very different usecases, and it just does not work. There is an approach that could work for end users who own their own accounts, but they need to go back to the drawing board and rewrite the protocol with the assumption that the keystore is hostile to the user's interests. That means strong guarantees on key portability so users can migrate away from hostile keystores, and absolutely no ability for services to restrict the user's choice in passkey provider software.

frantathefranta 2 hours ago | parent | prev [-]

I think passkeys were made to work in mind with complete idiots (here's a pop-up, tap it, now you have access to website without password, don't think about where it was saved or that it exists at all). I can understand parts of IPv6 like Router Advertisement being like that but there is so much customizability for the user that I can't really see them being similar that way.

cpburns2009 an hour ago | parent [-]

Except they never considered that "complete idiots" could lose access to their phone's passkeys.