Remix.run Logo
pixl97 2 hours ago

You go to country X (USA sounds good to put in here).

You get mugged.

They take your phone and keyring.

They can't do anything with it since it's locked, but you don't have it.

Aren't passkeys great?

staticman2 36 minutes ago | parent | next [-]

Wouldn't I have the same problem with passwords? I would lose my phone and be unable to two factor log in to my Gmail account or bank from someone else's device?

jazzyjackson 2 hours ago | parent | prev [-]

They can’t do anything with it

I have a backup key at home

Mission accomplished

mrweasel an hour ago | parent | next [-]

But the problem is that you can't really backup passkeys and because people are frankly frequent tricked into using them, they have no good recovery options.

I know plenty of people who only have a phone, no other devices. They don't backup that phone, they should but they don't. They don't use a password manager either, maybe they should, but they don't.

My issue with passkeys are that they are designed for a reality that don't exist, or at least only exists for people who are already doing a lot to secure their devices.

vel0city a minute ago | parent | next [-]

> But the problem is that you can't really backup passkeys

The individual passkey? Maybe not. But I don't really need to backup the passkey, I can just have backup passkeys or other backup authenticators, including complicated stored one-time passwords.

To answer your earlier hypothetical, I'm out traveling and I'm mugged. Well, hopefully, I'm not mugged in the part of the travels where I'm carrying truly everything at the moment, and I can just go back to the hotel room and re-auth with a device I saved there Problem solved, no big deal. If I lost truly everything while I'm out, I'd do as suggested elsewhere here and call home to get a trusted friend/family member to read me off the one time password saved at home or whatever.

> My issue with passkeys are that they are designed for a reality that don't exist

The reality of passwords being hijacked is absolutely a reality of today and is a constant issue for tons of people.

> I know plenty of people who only have a phone, no other devices.

And I really don't get why we can't also teach these people to also have a little token they use that can also be a part of their online identity. And sure, for certain kinds of accounts have appropriate levels of recoverability, but for the normal authentication workflows its so much better in so many ways.

pixl97 44 minutes ago | parent | prev [-]

> designed for a reality that don't exist

They are designed for a wealthy technologically inclined user with a very stable lifestyle and trusted resources and connections to other people. You know, the exact people who developed them.

rcxdude an hour ago | parent | prev | next [-]

Do you have a plan for getting home without access to any of your accounts? And one of the problems with passkeys is that it's unreasonably difficult to keep a backup key.

pixl97 an hour ago | parent [-]

You're asking way too much foresight in this thread I guess. There are some people who have lived lives without any series of unfortunate events, they can't even imagine what the world can serve up.

tavavex 44 minutes ago | parent | prev [-]

Great, now I just need to get back home to use my uncompromised accounts (which would have still been protected by my device as long as the thieves aren't NSO Group, but whatever). Gee, it seems my tickets back home were taken with my stolen phone! Not to worry, they sent me an email confirmation, so all I need to do is log into my passkey-protected email on my friend's phone and have them download my ticket in addition to theirs, or print them at a public computer. Oh wait