3 ms·
FWIW people don’t actually understand how passwords work either (password hashing etc.), and I am not sure it’s important for most people to understand how pass
by jesseendahl 2y ago
FWIW people don’t actually understand how passwords work either (password hashing etc.), and I am not sure it’s important for most people to understand how passkeys actually work. Also, majority of people reuse the same (extremely weak) password, or they go through an account recovery flow every time they login anywhere. This is why you saw the “magic link” pattern take off in the first place — users were already going through essentially the same flow before. Now at least they can sign in with biometric authentication on a regular basis, using passkeys. And if they do get locked out of their account for some reason, they go through the account recovery flow — same as they did when using their password before.
But at least they won’t get phished anymore! That’s a huge win.
- deleted 2y ago[deleted]
- TeMPOraL 2y ago> people don’t actually understand how passwords work either (password hashing etc.) Those are implementation details that they need not to care about. Password hashing is about mitigating the consequences of you the account provider screwing up. I know, technology and finance are special, in that the more a service provider fucks up, the more it is your fault somehow (see: "identity theft") - but most people didn't get that memo.
- jesseendahl 2y agoIndeed — I am arguing that 99% of normal everyday folks using passkeys also do not need to understand passkeys.
- TeMPOraL 2y agoDifference is, passwords break like normal things people are used to. Passkeys break like some alien technology from fifth dimension, there is no reference to everyday experience for the one thing people need to understand, which is how to not mishandle auth on their end, and how to recover when they invariably do mishandle it.