4 ms·
> Don't use passkeys Better title. Mom can't figure out what they are or how to use them. They bind you to your device/iCloud/Gaia account so if it gets stole
by akersten 7mo ago
> Don't use passkeys
Better title.
Mom can't figure out what they are or how to use them. They bind you to your device/iCloud/Gaia account so if it gets stolen/banned you're out of luck (yeah yeah multiple devices and paths to auth and backup codes, none of that matters). It's one further step down the attested hardware software and eyeballs path. Passwords forever, shortcomings be damned.
- Someone1234 7mo agoUnfortunately some vendors are now REQUIRING passkeys; specific example: https://www.healthequity.com https://www.healthequity.com > As of October 2025, passkey login has been fully rolled out and is now required for members with Health Savings Accounts (HSAs) and Reimbursement Accounts (RAs) who use the HealthEquity Mobile app and web experience. https://help.healthequity.com/en/articles/11690915-passkey-faq https://help.healthequity.com/en/articles/11690915-passkey-f... The FAQ is a little misleading by saying WHEN your account has a passkey this and that, but reality is that after October they made them completely mandatory, no bypass, no exceptions. 100% coverage. Oh, and by the way, passkeys have been broken on PC/Linux when using Firefox for months: > There Was A Problem: We encountered an error contacting the login service. Please try again in a few minutes. Neat. You have to use Chrome or Edge.... For months, after making it mandatory...
- buzer 7mo agoThat's weird, I can login to my HealthEquity account (which contains HSA) without any issues and I don't have passkey setup. I confirmed it just now just in case. That article does say "HealthEquity Mobile and web experience" so maybe it's just for customers who use both, I only use web.
- saagarjha 7mo agoI’ve only used web and they forced me to enroll one.
- cyanydeez 7mo agoside note, HSAs are also a symptom of a failed Healthcare system
- Someone1234 7mo agoYou aren't wrong, but many of us are stuck in that failed healthcare system and making the best of it.
- pabs3 7mo agoKeepassXC has exportable passkeys, so you can avoid the stolen case at least.
- hollow-moe 7mo agoToo bad the spec is stupid and requires password managers to be identifiable so servers can deny the "insecure ones". It's already a pain to use Keepassxc for otp since they all want you to use their apps but it's still doable (the worst offender being steam where you have to hack your own app to extract the otp secret). With passkeys you won't have a choice to use The Google AuthenticatorTM etc because eventually some exec will find they can block every provider except their own to boost app download KPI. I really like concept of passkeys, the simple fact of using asymmetric keys is so much better than giving the secret to prove you have it, but the spec is hostile and thought for vendor closing.
- pabs3 7mo agoIIRC KeepassXC can just identify as Apple Passkeys and it will work fine.
- lousken 7mo agoNo, the spec is for companies that need to enforce higher levels of security so that you can e.g. only enable Yubikeys in your env. I hate big tech just like anybody else but this is just spreading FUD right now. Also execs can already enforce their apps only - banking apps for approving transactions are already a thing at least in europe, no fido passkey needed.
- timmyc123 7mo ago> Too bad the spec is stupid and requires password managers to be identifiable so servers can deny the "insecure ones". There is no requirement that credential managers identify themselves. Please stop spreading misinformation.
- 8cvor6j844qw_d6 7mo ago> exportable passkeys But didn't the author hint that this could get blocked? My general read on passkeys and their implementers is that exportability is seen as a risky feature, and there's a push to make it as opaque as possible, likely through attestation or similar mechanisms. [1]: https://github.com/keepassxreboot/keepassxc/issues/10407 https://github.com/keepassxreboot/keepassxc/issues/10407
- mgrandl 7mo agoI love passkeys in my selfhosted vaultwarden, but I agree the UX for older people is not quite there.
- jesseendahl 7mo agoPasswords are terrible UX for old people in my experience. They try use the same password everywhere, but then password complexity requirements mean they can't use the exact same password everywhere, and then they forget which variant they used on which service, so they just end up going through the reset password flow every time they sign in. I am not convinced that's a better UX than them just using their fingerprint or face to login.
- afiori 7mo agoAlso a password could be the passkey, the passkey protocol is basically a way to send to a server an authenticated public key. The client could deterministically convert passwords to key-pairs and authenticate with those
- utopiah 7mo ago> They bind you to your device Isn't it why good practice is to bind at least 2 hardware passkeys and/or have recovery codes? Sure someone can steal your phone/laptop/yubikeybio but then you can use the NitroKey you have at home in your drawer to recover your account.
- aeronaut80 7mo agoYou can’t expect your grandma to go to those lengths. Heck, even most internet-native people probably wouldn’t.
- utopiah 7mo agoFor a random website, no, for bank and primary email (used for account recovery), they probably should. It honestly takes a minute to add a key and it's just that, a physical key. IMHO what's risky in terms of UX and habits is precisely that most workflows do not highlight this. So people rightfully are scared of losing that 1 precious key, so they don't activate 2FA because of that. Meanwhile if the UX when they activate 2FA would clarify that they only have 1 key stored, adding a 2nd one or saving codes (most do propose that option for 2FA authenticators but not hardware passkey AFAIK) is what will make them both safe against attacked but also against their own accident (shit happens) then maybe behaviors would change. Anyway, yes, you're right, most people don't do that or aren't even aware of it but arguably as more and more important and intimate part of our lives are online, it becomes crucial for one owns sanity to better understand how this all works.
- Telaneo 7mo ago> For a random website, no, for bank and primary email (used for account recovery), they probably should. Even for this, for grandma, this is probably still asking for a lot. Grandma's bank will have a recovery option even if she's tossed her phone, computer and hardware token in the ocean, and then had a stroke which made her forget any passphrases or whatever: You can call the bank and physically authenticate yourself with a passport, driver's licence or some other ID. It's a bitch to do, you may have to go to an actual bank branch, but grandma will get access to her money again. Meanwhile, her access to physical mail doesn't stop just because she's forgotten some passphrase or lost her phone. Even techy people get caught out by Google forcing 2FA, while casuals don't even consider the possibility of losing access to their email. While both the rhetorical you and grandma both should probably have a bulletproof recovery option for their email, since it will be the foundation of their digital identity, getting them to acknowledge the problem is going to be hard, and the solution, paying for a Yubikey or some other house of cards solution, is a tough sell.
- jesseendahl 7mo ago>They bind you to your device/iCloud/Gaia account so if it gets stolen/banned you're out of luck This is the biggest myth/misconception I see repeated about passkeys all the time. It's a credential just like your password. If you forget it, you go through a reset flow where a link is sent to your email and you just setup a new one. And if it happens to be your Gmail account that you're locked out of, you need to go through the same Google Account Recovery flow regardless of whether you're using a password or a passkey.
- ratmeadow 7mo agoGenuine question: what if the recovery asks for a 2nd factor that's e.g. the device which you lost? Is that common? Personally I don't really trust companies to not do a whoopsie and permanently lock you out when you lose credentials. Especially when the company is big or hard to access in person. For someone like me who already uses a password manager for everything, passkeys seem to add no security while reducing usability and control.
- realityking 7mo ago> For someone like me who already uses a password manager for everything, passkeys seem to add no security while reducing usability and control. One advantage of passkeys is that they’re phishing resistant. They’re bound to the website that you created them for, it’s impossible to use them for a different website.
- NekkoDroid 7mo ago> Genuine question: what if the recovery asks for a 2nd factor that's e.g. the device which you lost? Is that common? Instagram does something similar. If you have no logged in device and you reset your password, good luck getting in, cuz it wants you to log in a device "it recognizes" else it won't let you log in.
- gzread 7mo agoGoogle does it too. You log in with your password and it says "please press the number 35 on your phone"
- reddalo 7mo agoI'm also completely against passkeys. A safe password and a good password manager are way better, they don't lock you into any platform. It's super sad to see all kinds of websites offering you to add a passkey when you log in.
- tuwtuwtuwtuw 7mo agoI was planning to make use of passkeys when logging on to various services, so I ordered three physical devices, supporting passkeys (yubikey). I ordered USB C and USB A variants, with NFC support. Is this a mistake? I am already using password manager and totp for my accounts, but I am tired of dealing with passwords. Even when using a password manager (bitwarden in my case), it just get tedious bringing out my phone, starting auth app, locating the correct account, reading 6 digit token and logging on.
- reddalo 7mo agoNo it's not a mistake. But say you lose the Yubikey, or you're away from home. How do you deal with that? You still need a password somehow.
- tuwtuwtuwtuw 7mo agoSure. But I think that is same scenario as me loosing my phone today, since I use that for two factor auth. My plan was to continue using bitwarden for passwords as well, but more as a break-glass mechanism that I really use. I want to use passkeys mostly for convinience.
- pamcake 7mo agoYou're good. The relevant advice in article is to not reuse keys for encryption and auth. Encrypting password manager database with a passkey or other authentication key on one of those yubikeys would be the mistake. Encrypting it with a separate dedicated key (or passphrase) on the same yubikey in parallel to its passkeys is fine.
- dariosalvi78 7mo ago
- lxgr 7mo ago> They bind you to your device/iCloud/Gaia account Then don't use Apple's/Google's/whatever Gaia is as your passkey provider? > Mom can't figure out what they are or how to use them. Then do something nice for your mom and set her up with Bitwarden, 1Password or KeepassXC, which prevents the platform lock-in. > It's one further step down the attested hardware software and eyeballs path. None of the synchronized passkey implementations, which big tech has been pushing lately, support attestation, so this is just FUD. Yubikeys do, but fortunately they don't seem to have the (non-enterprise) weight to make it mandatory for all passkeys.