5 ms·
> Recognizing the increasing demand by consumers to enhance security and in particular user convenience, Amazon rolls out passkeys widely across most devices an
by newscracker 3y ago
> Recognizing the increasing demand by consumers to enhance security and in particular user convenience, Amazon rolls out passkeys widely across most devices and browsers. This underlines Amazon’s commitment to bend to consumer demand.
Which consumer base has demanded enhanced security and convenience (for which passkeys are the proclaimed answer)? The non-tech crowd has no idea what it is and is probably just hearing about it. The tech crowd on a forum like HN seems to be mostly against it because of issues with account recovery and cross-device use that passwords don’t pose.
From what I understand, it seems like passkeys may ultimately rely on SMS OTP or similar mechanisms for account recovery. The other likely result would be losing the account forever, especially if the user is a single device one (there are billions of such people around the world).
I’m going to wait it out a little longer to see how the interoperability factors play out in reality and learn from those who are braver than me.
- lxgr 3y ago> to enhance security and in particular user convenience What convenience? Amazon's implementation saves me exactly one thing. "Typing my password" (i.e. pressing my password manager's autofill key combination). The annoying part is having to enter my OTP over and over and over again, with the non-functional "don't ask again on this browser" box below serving as a little mocking statement to show that they have indeed thought about this use case – they just haven't bothered to actually implement it.
- circuit10 3y agoI haven’t read the article so I don’t know if this is the same thing as passkeys but most password managers should support TOTP authentication
- BakaRakuda 3y ago> Which consumer base has demanded enhanced security and convenience (for which passkeys are the proclaimed answer)? The non-tech crowd has no idea what it is and is probably just hearing about it. The tech crowd on a forum like HN seems to be mostly against it because of issues with account recovery and cross-device use that passwords don’t pose. Yeah it's going to be mostly the tech crowd at this point, and it will filter down to non-tech people. And we will all be better off when we are all using passkeys. Looking at my girlfriend's computer her password situation is a nightmare of potentially compromised passwords, reuse of weak passwords, among other issues. Even after spending hours trying to clean it up there are still tons. If we were in a passkey only world then no more weak passwords for her to reuse, no chance of phishing said password from her. Even if the server gets hacked there is no password to get pwned. I really don't care what the contingent of passkey haters on here say. A lot of the discourse here isn't what it used to be. Little better than Reddit for techies. > From what I understand, it seems like passkeys may ultimately rely on SMS OTP or similar mechanisms for account recovery. The other likely result would be losing the account forever, especially if the user is a single device one (there are billions of such people around the world). That's not as I understand it. Why would SMS OTP be used? 100% of accounts today will already have a password, that's how you would login if you lose your only passkey device. If/When passwords are not a thing anymore then why wouldn't the recovery use a "lost password" type flow that happens is facilitated via the account email? > I’m going to wait it out a little longer to see how the interoperability factors play out in reality and learn from those who are braver than me. Fair enough, but you can add a passkey to an account and your password will still work. So it's not like it will cause any harm to try it. You can even remove passkeys from an account if you really don't want to use it. The worst thing about passkey support on Amazon is they didn't embrace it completely so you still have to go through all of the login form bullshit instead of being a one step biometric unlock that passkeys can enable.
- stavros 3y agoYou're right about the level of discourse, and it's become especially obvious to me whenever there's a discussion about passkeys. Everyone keeps repeating the same debunked arguments over and over, with only maybe one argument (attestation) holding some water. It's too bad, I'm really excited about passkeys increasing authentication usability (and security second, for me), but most people here seem to want to hold on to passwords, as if they aren't both terrible UX and terrible security.
- wkat4242 3y agoAttestation is a big barrier for self hosting which is the only way I'd adopt it. But afaik the biggest implementation of passkeys (Apple) doesn't support attestation so right now it's not a problem, nobody requires it in order not to lose all the Apple userbase. This may change in the future though. Another problem is no self hosted toolchain with full cross platform sync but hopefully it'll come.
- stavros 3y ago> Attestation is a big barrier for self hosting which is the only way I'd adopt it. The issue I have with attestation it that I feel that I feel that we're saying "is it a problem?" "no, but it theoretically could be, so let's use passwords instead". I think that passkeys are better than passwords, even with attestation, and if it becomes a problem, we can complain about it then.
- wkat4242 3y agoAttestation is a huge problem because it can be used to exclude self-hosted systems, which is the only way I would even consider using passkeys. I abhor "sign in with Google/Microsoft/Meta...etc" things too. For example the admins at my work refuse to "certify" any security keys other than yubikeys. And because those do support attestation it is not possible to circumvent it. For work it's not an issue, they will just have to supply me a key if they want me to use the damn thing, but I don't want consumer-focused sites to use it obviously. Attestation is inherently evil and anti-FOSS. I just won't opt in to it until attestation is gone, but thanks to iCloud not offering it, it is currently not demanded by any of the sites.
- lll-o-lll 3y ago> The tech crowd on a forum like HN seems to be mostly against it because of issues with account recovery and cross-device use that passwords don’t pose. Because of an embarrassing amount of ignorance. Own an android phone? An iPhone? Congratulations, your passkeys are on your password manager. You can recover your passwords when you lose your phone right? Exact same mechanism. (Now, if we want to talk about how solid the protection is for apple/google at keeping these private keys safe in their clouds, and how secure something is when one magic password is enough to unlock literally everything, or how confident we can be that the govs won’t be able to get their paws on them, that’s a more nuanced topic).
- mekoka 3y agoYou obviously don't travel. Lose your phone while abroad. Good luck!
- adolph 3y agoAlso a solved problem with keychain managers. Example: With iCloud Keychain, you can keep your passwords (and other secure information) updated across your devices and shared with the people that you trust. https://support.apple.com/en-us/HT204085 https://support.apple.com/en-us/HT204085
- wasmitnetzen 3y ago> keychain managers Proprietary keychain managers. I will not hand Google or Apple the keys for every account I have, or even just the metadata where I have accounts. I'm well aware that they claim that they don't have access to that, but I do not trust them.
- adolph 3y agoAlso third party keychain managers (which are also often proprietary), so no need to hand your preciouses directly to Goaple.
- Double_a_92 3y ago"Normal" people usually have an incredibly hard time managing accounts and their logins. They constantly have to restore account passwords, or just straight up create new accounts. A passkey which is backupped to their Apple or Google accounts will make things easier.