5 ms·
What is the adoption for passkeys? I do not get the impression that they will replace passwords or “social” logins anytime soon.
by hankman86 2y ago
What is the adoption for passkeys? I do not get the impression that they will replace passwords or “social” logins anytime soon.
- pmontra 2y agoI have yet to notice a site asking me a passkey.
- blowski 2y agoI've found them to be a real pain in the arse because they're implemented so inconsistently. Only the biggest sites are offering them, but it's those big sites where I'm worried about locking myself out because of setting it up wrong.
- scrollaway 2y agoI've locked myself out of Squarespace by setting up then subsequently removing a passkey. Doing so triggered a bug which "updated" the TOTP (that was already set up) and the backup codes. Support was absolutely deaf to the whole thing being a bug, absolutely impossible to report, and I'm sure it'll keep being an issue for years to come.
- ciroduran 2y agoFunny enough, you can use a passkey to log in with Nintendo
- paulryanrogers 2y agoYet if the limit is one then you'll still need a fallback like forgot password. Because the original device may fail.
- FeelingGood 2y agoThey might not ask you to setup a passkey, but many sites already support it: https://passkeys.directory/ https://passkeys.directory/
- doctor_eval 2y agoReally? That’s how I log into GitHub!
- pmontra 2y agoI stopped logging in into there since they forced 2FA on me because of an old contribution to an open source project. It's too much of a pain and I don't need to be logged in to look at the code of the modules or libraries I'm using or I could use. As collateral damage, I stopped opening issues on open source projects, that was maybe two or three issues per year. All my customers are on Bitbucket at the moment and it still works with username and password. If it would switch to 2FA, I'd have to comply.
- nathan_douglas 2y agoIf you have something like 1Password, it takes one or two clicks to set up 2FA for a given site and Passkey setup for a given site is pretty painless. There’s even a decent amount of CLI integration for signing commits, etc. As a federal contractor working in and out of higher security areas, 2FA and Passkey are… really not intrusive or disruptive to my daily life.
- stavros 2y agoIt amazes me the lengths people will go to to avoid security.
- ayewo 2y agoIt’s not that the gp is trying to avoid being secure. It’s that for a service that you only have a need for, a few times a year, mandating 2FA is an unnecessary hassle that can lead to user frustration. I’ve experienced the same with Gitlab. I rarely use Gitlab and don’t have anything important hosted there but when a project I was a member of enabled 2FA for all contributors, it made my Gitlab account completely frustrating to use. Typical scenario: I’m trying to do something brief on Gitlab that requires me to be logged in so I login then get shown an interstitial page saying I cannot proceed until I enable 2FA on my Gitlab account. Every action I attempt while logged in will fail unless I either enable 2FA or remove myself from the project that enabled mandatory 2FA after I was added. GitHub’s 2FA implementation is night and day better than Gitlab’s but I imagine the user frustration must be similar if you find yourself suddenly having to enable 2FA because a GitHub org you were already part of mandates it.
- drumdance 2y agoThere are 3-4 I regularly use. Google offers it for their business accounts, of which I have a couple.