3 ms·
RIP Passwords? Passkey support rolls out to Chrome stable
- cmdli 4y agoOne of the biggest problems with the adoption of passkeys, I think, is the lack of flexibility and possibility of vendor lock-in. What happens when you don't want to use Apple or Google? Will they support the transfer of credentials out of their walled garden? Can I transfer my credentials out of Chrome, like I can with passwords? These aren't unsolvable problems, but I think this is a point where openness and user control should be a priority, both of which Apple and Google don't have a great track record with. As an aside, I would like to plug Bulwark Passkey (https://bulwark.id https://bulwark.id), my open-source passkey manager which I think solves some of these problems. Passkeys have the potential to fix a lot of the problems with passwords, but there are fundamental concerns around user control that I think need to be addressed.
- lbhdc 4y agoThat was my take as well. I don't intend to adopt passkeys until they have been around for a long time, and hopefully some of those growing pains will be teased out or it is apparent that its a walled garden.
- Spivak 4y agoWhich is why Bitwarden, 1Password, LastPass, et al are set to make a killing in this space for no other reason than being able to see outside their walled gardens.
- deleted 4y ago[deleted]
- anenefan 4y agoGiven history, it's almost a given certain companies will move to user pay and lock in their customers. As for adoption, I see a few stumbling blocks. Those who have the mod cons will obviously adopt with little foresight. IMO, the first to refuse outright, will be the people who've already grown tired of needing to do something on the day, but experienced the service they want to use is down ... worse some third party the site relies on is, very very slow, down or broken, or they are met with some new strange issue the site despite the correct password, had with validating their operating system or the pooled IP your ISP has unwittingly assigned this day, has been abused. (I already shop away from such systems, and it's a dull pain when a once perfectly working online shop, adopts some newfangled clever thinking, oh bother. ) The next on the rung, will have in mind those who take their devices near everywhere ... esp phones with the multitude of apps and their life wrapped up in it. Unless under a rock, we've all heard the horror stories when some people have lost their device. With this in mind, after theft or loss, how does one prove they are in control of their email, sms etc when the have to tackle getting their ship back to normal? [Yes, the service will have asked the user set a password to the passwordless service ... or have a stored fingerprint of a second or third device.]