Why passkeys are a step back for personal security: examining account lockout risks, platform lock-in, hardware key limits, and fragile recovery flows.
That’s why you shouldn’t use exclusive on device storage for them, like Apple/Google want you to. Biometrics are shit, I prefer passwords if we are having no passkeys. I agree they are not perfect, but we can improve them and they will be a lot better than passwords for the majority of people.
Also, you wont lose your account, youll just have to go through a recovery process. Exactly the same as you would now if you forgot a password or lost a MFA code.
Don’t proper biometrics also lock you to a device? My phone isn’t sending my fingerprint anywhere, it’s comparing data against its baseline and then attesting that. If you did it any other way, then any data leak means you’re exposed literally forever.
Passkeys are just more convenient replacements to passwords, ideally suited for a password manager flow.
For most people, this works really well and is a lot better than remembering loads of passwords. It’s easier to get people to remember a single stronger password and use passkeys to login to services.
The whole lose access thing isnt as big of a deal breaker as you make it sound (It literally works the same as it does now with passwords). Considering the large amount of people that forget their passwords and constantly reset them, passkeys can help. There’s a reason popular sites just ask you for a code from an email now instead of even prompting for your password.
You want to use biometrics to individually login to services, great. But what about those of us who don’t want to rely on biometrics? That’s where passkeys do both jobs.
That’s why you shouldn’t use exclusive on device storage for them, like Apple/Google want you to. Biometrics are shit, I prefer passwords if we are having no passkeys. I agree they are not perfect, but we can improve them and they will be a lot better than passwords for the majority of people.
Also, you wont lose your account, youll just have to go through a recovery process. Exactly the same as you would now if you forgot a password or lost a MFA code.
Biometrics are NOT shit.
And the recovery process is useless if you don’g have acess to your recovery method. Passkeys create the Ouroboros kind of situation.
Don’t proper biometrics also lock you to a device? My phone isn’t sending my fingerprint anywhere, it’s comparing data against its baseline and then attesting that. If you did it any other way, then any data leak means you’re exposed literally forever.
Passkeys are just more convenient replacements to passwords, ideally suited for a password manager flow.
For most people, this works really well and is a lot better than remembering loads of passwords. It’s easier to get people to remember a single stronger password and use passkeys to login to services.
The whole lose access thing isnt as big of a deal breaker as you make it sound (It literally works the same as it does now with passwords). Considering the large amount of people that forget their passwords and constantly reset them, passkeys can help. There’s a reason popular sites just ask you for a code from an email now instead of even prompting for your password.
You want to use biometrics to individually login to services, great. But what about those of us who don’t want to rely on biometrics? That’s where passkeys do both jobs.