Why passkeys are a step back for personal security: examining account lockout risks, platform lock-in, hardware key limits, and fragile recovery flows.
I don’t want my access to be tied to a specific device. Devices get lost, or break.
I don’t want someone to be able to use my face or finger or eyeball to access my data. You can legally be compelled to unlock a device with your biometric security.
So current biometric security sucks. And passkeys suck.
Also, though…passwords suck for all the reasons that we all already know.
There has to be some better method that the owner can have full agency over, I just don’t know what. I don’t have the answers.
There’s a fantastic paper from a while ago that did a great job of covering what you’re getting at. It’s one of the most cited papers in password security research. Basically, everything we’ve ever found sucks but passwords seem to suck the least. Great read if you have the time - https://www.cl.cam.ac.uk/techreports/UCAM-CL-TR-817.pdf
Every attempt at using passkeys has been a step into murkier, less easily understood, less convenient security.
Passkeys may be a “step up” from password + TFA in terms of usability, but there’s such a variety of implementations and explanations of how those implementations “keep me secure” - I feel like any idiot who grabs my phone when I’m not looking and can follow my unlock finger smudges on the screen can use my pass keys… No thanks.
There is still nothing better than passwords.
I don’t want my access to be tied to a specific device. Devices get lost, or break.
I don’t want someone to be able to use my face or finger or eyeball to access my data. You can legally be compelled to unlock a device with your biometric security.
So current biometric security sucks. And passkeys suck.
Also, though…passwords suck for all the reasons that we all already know.
There has to be some better method that the owner can have full agency over, I just don’t know what. I don’t have the answers.
There’s a fantastic paper from a while ago that did a great job of covering what you’re getting at. It’s one of the most cited papers in password security research. Basically, everything we’ve ever found sucks but passwords seem to suck the least. Great read if you have the time - https://www.cl.cam.ac.uk/techreports/UCAM-CL-TR-817.pdf
Every attempt at using passkeys has been a step into murkier, less easily understood, less convenient security.
Passkeys may be a “step up” from password + TFA in terms of usability, but there’s such a variety of implementations and explanations of how those implementations “keep me secure” - I feel like any idiot who grabs my phone when I’m not looking and can follow my unlock finger smudges on the screen can use my pass keys… No thanks.