Remix.run Logo
mystifyingpoi 5 hours ago

> how do I log in on a device that I don't own?

Sad reality is that such usecase is less and less common, thus, no one cares about it. I think majority of my friends would not be able to access their email, or facebook or alike, if they were forced to use my computer in emergency.

epihelix 2 hours ago | parent | next [-]

And that sounds fine, until you're traveling and your devices get stolen or lost. How, exactly, are you going to get into your email then, once passkeys become the only means of login? Because that moment is when you really do need to access your email, stat.

jayknight an hour ago | parent [-]

What services implement it like this? Don't services usually implement passkeys as a more secure alternative to a password, but password login is still available?

Some sites allow passkeys as an option for MFA, so that could be an issue if the passkey is your only MFA option and MFA is required. But I imagine email would pretty much always be a fallback.

mrweasel a few seconds ago | parent | next [-]

[delayed]

basch 13 minutes ago | parent | prev [-]

When was the last time you tried to log into something like Google, Apple, Microsoft etc without your phone nearby, on a fresh computer?

alienbaby 3 hours ago | parent | prev | next [-]

Rubbish. Such use cases are extremely common anywhere it can't be expected everyone has access to their own device.

makeitdouble 2 hours ago | parent | prev | next [-]

A variant of that is alternative accounts that properly live on a different device/context.

For instance YouTubers usually have a different account for their channel than the one they use privately, and don't want their channel account logged in everywhere.

That means having to log in as a guest when push comes to shove. And similar setups are common for most self-employed keeping a "work" account IMHO.

cj 4 hours ago | parent | prev | next [-]

Isn't there a workflow where you scan a QR code to confirm the pass key on your phone?

I've definitely done this, but not sure if the workflow was at the OS or browser level.

I'm honestly confused by all the negativity in the comments. Passkeys are great for convenience. Just leave your password login enabled as a backup. That defeats any security benefit, but oh well.

kps 3 hours ago | parent | next [-]

> Isn't there a workflow where you scan a QR code to confirm the pass key on your phone?

For people in this position, if they had their phone, they probably wouldn't be logging in on a computer anyway.

limagnolia 2 hours ago | parent [-]

There are a lot of reasons why I might want to login on a computer I don't own to do something, rather than to use my phone. Having a keyboard is a major usability benefit for many types of work. Larger screen, printer. Software that is on the machine that can't run on my phone.

kps 2 hours ago | parent | next [-]

I agree with you; those are all reasons I only use my phone for on-the-go messaging or navigation. I'm against the idea that you should have to have a secure (against the owner) connected phone on your person at all times in order to sign in to a web service.

vel0city 2 hours ago | parent [-]

You don't have to with passkeys. I use passkeys every day, they rarely involve using my phone.

xboxnolifes 2 hours ago | parent | prev [-]

Thats still irrelevant to the example being discussed.

conradludgate 2 hours ago | parent | prev | next [-]

This is what I use to log into our remote desktop software at work. The passkey is on my phone and I scan a QR code presented by the remote desktop software (in this case it's the Windows App on my macbook and Microsoft Authenticator on my android).

dgunay 3 hours ago | parent | prev [-]

There is. Doesn't work on every browser but it's really nice and I use it routinely.

Latty 4 hours ago | parent | prev | next [-]

Which is a trade-off that makes sense for a lot of people. If you have multiple devices, many of which are portable and one you have on you all the time, the need for that is just way lower, so being more secure against commonplace automated widespread attacks is worth it to them.

iamnothere 3 hours ago | parent [-]

Many people are moving to only a single portable device that’s easily lost, broken, or stolen, without any understanding of backups or fallbacks for their accounts.

And many are moving to virtual wallets like Cashapp rather than banks with a physical presence where you can take out money without a phone.

It’s a bad situation.

pixl97 an hour ago | parent [-]

Heh, this situation totally reminds me of politics.

Person 1: "People that end up in this situation that can easily happen should be punished to the full extent of the law with no mercy!"

[Exact situation happens to Person 1]

Person 1: "This is the greatest injustice, do people have no empathy? I could not have avoided this situation!"

2 hours ago | parent | prev | next [-]
[deleted]
megous 2 hours ago | parent | prev [-]

That's actually a good use case for HW keys. Since untrusted computers are much more likely to have keyloggers/malware, etc. So you don't need to reset password and invalidate all sessions after each such login on an untrusted computer.