Remix.run Logo
ectoloph 5 hours ago

I am conflicted with passkeys.

I actually prefer non-resident U2F in some ways. You don't have to store anything on your key, you are just signing requests. This is relevant where U2F/FIDO keys have limited slots for 'resident' keys.

In principle, it's great. You have one good password to remember for the average user, and that's enforced by their device's probably good enough security posture.

They are resistant to being phished and they won't reuse the same one everywhere. They then don't end up going from hunter2 to hunter2! everywhere.

But my experience for users is that they worry they are giving their biometrics to Amazon or whoever and so the UX just confuses them.

The certification aspect was new to me too last time passkeys came up. Sites can require that a given passkey has been certified.

The patchy support for them is also frustrating. MacOS does not support NFC FIDO/U2F. iOS does.

iamnothere 2 hours ago | parent | next [-]

Absolutely! U2F keys are unlimited, but I only have so many slots on my hardware key. And now sites are moving away from supporting U2F towards a passkey-only model. No! I have limited slots!

wang_li 43 minutes ago | parent | prev [-]

I don't want to have the security sensitivity of my devices be escalated by the fact that I access a very important service with that device. Currently I have separate passwords and a 2FA on my investing and bank accounts. I don't want to have to treat my cheap travel laptop as a SCIF because it is synced with my cloud services and has passwordless access to my entire financial life.