6 ms·
This is much, much simpler than you think it is. Passkeys are just passwords that require a password manager. If you lose your passkey, you'll reset your passke
by dfabulich 3mo ago
This is much, much simpler than you think it is. Passkeys are just passwords that require a password manager. If you lose your passkey, you'll reset your passkey the same way you reset your password, probably with a "forgot my password" email.
(But you're not going to lose it, because you use a password manager, and the passkey will be stored there and synchronized to all of your other devices.)
The weird part is that password managers provide no way for you to copy and paste your passkeys. To present a passkey, you have to use a password manager. This makes it impossible to copy and paste your passkey to the wrong person (someone trying to trick you).
Major password managers don’t even allow you to export your passkeys to a file that you can read/backup yourself. Instead, the password managers each have their own finicky app-to-app mechanism for transferring passkeys from one password manager to another. (I think all the password managers kinda like that lock in.)
Finally, note that for logging into your password manager itself, you'll always require something outside your password manager to login, probably a password, but possibly a YubiKey; your choice. (It's your one "last password," as they call it.)
https://danfabulich.medium.com/passkeys-are-just-passwords-that-require-a-password-manager-ebb7f2fdcadf https://danfabulich.medium.com/passkeys-are-just-passwords-t...
P.S. It's past time to move off of LastPass. LastPass lost all of your passwords again last month, just like they did in 2022. The most similar service is 1Password. If you like LastPass, you'll like 1Password about the same, but 1Password hasn't had multiple terrible security breaches.
- throwaway-blaze 3mo agoI love that you wrote 6 paragraphs and linked to a medium post all without actually answering the question posed by the comment you replied to.
- dfabulich 3mo agoYes, I did. When you set up a passkey on your phone in your password manager, you'll transfer it to your other device using your password manager. Either your password manager will automatically synchronize for you, or you can transfer your passkey to another password manager that will do the synchronization, via the finicky app-to-app transfer system (Credential Exchange Protocol). You can transfer from Apple to Bitwarden and vice versa. The family sharing question was added later, but the answer is: all of the major password managers have finicky family-sharing features for passwords and passkeys. For passwords, most people don't bother with formal family-sharing features, and just share passwords via copy and paste. For passkeys, you have to use the family-sharing features, which means you and your family member have to use the same password-manager vendor to share those passkeys. It’s up to you to decide whether protecting yourself from being tricked into exporting your passkeys is worth sacrificing your ability to read them.
- pseudalopex 3mo ago> It’s up to you to decide whether protecting yourself from being tricked into exporting your passkeys is worth sacrificing your ability to read them. Until a relying party uses attestation to decide this for you.
- kodt 3mo agoI looked up the June 2026 breach and there is no mention of passwords being stolen. Only some PII (Phone, name, email, address) through a third party.
- TeMPOraL 3mo ago> Major password managers don’t even allow you to export your passkeys to a file that you can read/backup yourself That's a red flag to me. It's enough that phone backup systems go out of their way to prevent you from accessing your own data, too, for unexplained "sekhurity" reasons. > P.S. It's past time to move off of LastPass. LastPass lost all of your passwords again last month, just like they did in 2022. The most similar service is 1Password. If you like LastPass, you'll like 1Password about the same, but 1Password hasn't had multiple terrible security breaches. That's the most annoying thing about password managers, and a major reason I still don't use them: there exists no password manager that is cross-platform (desktop/mobile in particular), local-first, and isn't sketchy or enshittified or otherwise on HN's current "don't use it, use <whatever> instead" list. For core security tool class, that doesn't inspire confidence.
- dfabulich 3mo agoApple, Google, Microsoft, Mozilla, and 1Password don’t let you export passkeys to a file that you can read and backup, but Bitwarden, Proton Pass, and KeepassXC do. I think Bitwarden is on HN's current happy list. (I just use Apple iCloud myself.) Allowing passkeys to be exported to a plaintext file undermines the phishing protections, at least somewhat. It’s possible to trick you into exporting your passkeys from Bitwarden and sending the file to an attacker. The major password managers say that this is the reason they don’t allow exporting passkeys, and it’s not false, but they’re also making it harder to switch password managers, which may be their ulterior motive. (You can’t even import those exported passkey files into any of the major password managers, which they would be incentivized to do, if those smaller players had significant marketshare.) It’s up to you to decide whether protecting yourself from being tricked into exporting your passkeys is worth sacrificing your ability to read them.
- threecheese 3mo agoI’ve relied on iCloud as well, but just learned that it allows apps to store persistent data. This data is synced between all devices, and there’s no way for you to view or manage/delete it. Even determining which apps do this requires you to enumerate the apps entitlements, which is nontrivial. And so an app you install on your iPhone can have configuration or credentials persist to each iCloud-connected device, and you have no control over it. This is certainly convenient, if that’s the behavior you want; if not, there’s no visibility or control.
- jasode 3mo ago>This is much, much simpler than you think it is. Passkeys are just passwords that require a password manager. The issue isn't what passkeys _are_ (e.g. explaining they are like public/private "ssh keys" and hoping that type of explanation ends the confusion). Instead, it's the workflow around passkeys. The websites show very confusing dialog popups and choices that a lot of normal people will not understand. This is a good article with screenshots showing the confusion: https://arstechnica.com/security/2024/12/passkey-technology-is-elegant-but-its-most-definitely-not-usable-security/ https://arstechnica.com/security/2024/12/passkey-technology-... I have senior citizens asking me about passkeys because their bank and medical websites keep reminding them about switching to passkeys every time they login into their accounts. My recommendation to them is not to do it unless they have a simplistic single vendor setup such as only Apple iPhone and MacBook with iCloud Passwords app. If instead they have a mixed Windows + Apple setup with 3rd-party password manager, they could accidentally put a new passkey into the os or browser instead of their external password manager and not realize what has happened. This happens because the different parties implementing passkeys all have different agendas that suits their interests and that's what makes the workflow confusing for normal people.
- dfabulich 3mo agoI don't think you're giving those seniors good advice. When the banks ask people to "switch" to passkeys, they're not removing the passwords; they're adding passkeys as an alternate login mechanism. If you lose your bank passkey, (e.g. if you put it in the wrong password manager and you can't figure out where it is) you can just sign in with your bank password. In the worst case, banks actually don't make it very hard for seniors to reset your password/passkey; just show up at a branch with photo ID, your bank card, and your PIN, and a teller will help you reset your credentials. They do it all the time. And, remember, seniors could also put a randomly generated password into the wrong password manager. In that case, they'll either have to reset their password, or they'll have figure out what they did, retrieve their password from the OS password manager, and transfer that password to their preferred password manager. The exact same story applies to passkeys, except, because passkeys can't be copied and pasted, you'd have to figure out how to use the finicky app-to-app transfer system ("Credential Exchange Protocol"). That's probably too complicated for most seniors, so falling back to a password is almost certainly their best bet.
- lelandbatey 3mo ago> This makes it impossible to copy and paste your passkey to the wrong person (someone trying to trick you). It also, unfortunately, means it's not possible (via most passkey implementations) to back those passkeys up to paper. Which is quite unfortunate: backing up to paper is one of the most stable and human accessible ways of ensuring redundancy and continuity, an inevitable but also oft-ignored part of credential management. Security folks would like to pretend "solving continuity" isn't a problem, or is a problem that doesn't need to be accessible.
- no-name-here 3mo ago> back those passkeys up to paper Is writing down passwords something people do? I have countless passwords saved over >20 years and I don’t think I’ve ever recorded one to paper. I even checked a couple of popular password management solutions and they don’t seem to have “print” functionality.
- cwillu 3mo agoIt is absolutely a thing people do. Google even offers a convenient printout as a way to provide account recovery.
- syntheticnature 3mo agoYes, this is extremely common, both as a continuity means and/or as a localized password manager. Know someone who uses a Rolodex for hers, which is funny and yet it works. Doesn't work well in office environments, but at home the local threat model is largely fine with this.
- malfist 3mo agoThe passphrase to my bitwarden database is in my will. And a bitlocker decryption key is right beside it.
- deleted 3mo ago[deleted]
- tekla 3mo ago
- sandeepkd 3mo agoI am an engineer and have some insights on the discussions and developments around it. ITS NOT SIMPLE AT ALL 1. The idea was to provide a phishing resistant authentication method for enterprise users (companies loose quite a lot of money to phishing). 2. Majority of industry players shared the vision of a credential which is available across the platforms and browsers 3. The vision for collaboration never materialized so everyone went their own way to implement it. Examples would be google rolling out browser (Chrome) managed authentication which led to this situation where even on the same machine you have to remember which browser you used to create the Passkey credential. 4. Interestingly enough the earlier popular name was WebAuthn, Apple started calling it Passkey on fly, given Apple's popularity everyone just caved in. 5. My personal interpretation is that in some sense Apple wanted to be the default password manager on Apple devices. 6. This is when all password manager companies jumped in strongly to save their business and the protocol went into a direction where you can use your existing password manager to store the credential/Passkey as well Personally its a mess, the phishing resistant aspect has its own benefits though. If you are using it with security in mind then my recommendation would be to use a hardware backed security key with NFC enabled. Everything else is pretty much lipstick on pig, they are worse than passwords in some sense from usage perspective.
- pishpash 3mo agoIt should have never been a cloud password manager play. It should be hardware device only, and tied to the device. One passkey on each hardware device.
- jallmann 3mo agoThat leads to the cross-device usability issues from the original post. Even for an experienced engineer, it's a headache to manage multiple devices across multiple sites. With the "cloud password manager" angle there is some hope of being user friendly, although we're certainly not there yet for most folks.
- Someone1234 3mo agoThen most of us would never use it. That means either: - Only one specific device can ever login (bad). - It doesn't limit login to one specific device, therefore it does nothing. Linking Passkeys to a physical device was always DoA. At least not without a way to enroll every device you own, and strong recovery strategies. But considering how inconsistent every company's Passkey implementation is (inc. many that only allow ONE TOTAL!), it is DoA.
- aetch 3mo agoHaving to rely on a possibly proprietary password manager app to use a passkey sounds like a nightmare. A lot could go wrong with the password manager like becoming incompatible, becoming subscription based, lack of updates for bugs, etc. I don’t passkeys for the same reason as the original commenter.
- xboxnolifes 3mo agoSo to login using a public PC, you need either USB access (and carry around your password manager) or you need to install the password manager on the PC to log into a website?
- realityking 3mo agoThere’s a process to scan a QR code with your phone and your phone then authenticates with the passkey.
- archargelod 3mo agoDiscord has an option to login with qr code. And it's very often used maliciously to steal accounts.
- mwwaters 3mo agoThe passkey method uses Bluetooth to ensure proximity.
- dwheeler 3mo agoWait a sec. My understanding is that passkeys are public/private keypairs. Public is in server, so even breaking into a server does not reveal the private key. The big risk with passkeys is storing the passkey where it will be held hostage. Don't store it in most single-ecosystem devices like Apple. Bitwarden can export, and I think 1Password can as well.
- deltoidmaximus 3mo agoThat's where the attestation feature comes in. It allows them to force you into a hostage situations by restricting passkey implementation. There's a reason that was part of the spec from the get go but a passkey transfer system wasn't.
- malfist 3mo agoThis is not much simpler than they think it is. > But you're not going to lose it, because you use a password manager, and the passkey will be stored there and synchronized to all of your other devices That's just wrong. I use android, my partner uses ios. If he creates the passkey in safari, it's not going to get synced over to my phone. And that's just the first of the family sharing passwords issues. Same person issue is also present if somebody uses an iphone and a windows laptop, or chromebook. It doesn't help that all modern browsers eagerly try to step in and offer their implementation of passkeys for logins, and they're not featured enough to support the type of shared access or synced access many people would expect from a password manager. How useful is your firefox passwords on an iphone? Or Mac OS's keychain I use as a daily driver on my windows gaming desktop? > Major password managers don’t even allow you to export your passkeys to a file that you can read/backup yourself This is wrong. Every single major password manager supports export. Lastpass, 1password and bitwarden all do that. > It's past time to move off of LastPass. LastPass lost all of your passwords again last month That just isn't true. Last month, their third party customer support portal was breached. That did not involve passwords.
- dfabulich 3mo ago> Every single major password manager supports export. They all support exporting passwords, but, check your CSV; you won't find any passkeys in the CSV export for Apple, Google, Microsoft, Mozilla, 1Password, or LastPass. (Bitwarden, Proton Pass, and KeepassXC do support exporting passkeys to CSV, which undermines the phishing protections, at least somewhat. It’s possible to trick you into exporting your passkeys from Bitwarden and sending the file to an attacker. It’s up to you to decide whether protecting yourself from being tricked into exporting your passkeys is worth sacrificing your ability to read them.) > How useful is your firefox passwords on an iphone? Did you try it? That's the primary feature of the Firefox app for iPhone. (Especially since the Firefox app for iPhone is just Safari's WebKit wearing a Firefox disguise.) > Or Mac OS's keychain I use as a daily driver on my windows gaming desktop? https://apps.microsoft.com/detail/9pktq5699m62?hl=en-US&gl=US https://apps.microsoft.com/detail/9pktq5699m62?hl=en-US&gl=U... > With the iCloud for Windows app, you can access photos, files, passwords, and other important information from your iPhone or other Apple devices on your Windows PC. When Apple's your password manager, you use Apple's password manager app to synchronize passwords and passkeys.
- __MatrixMan__ 3mo ago> Instead, the password managers each have their own finicky app-to-app mechanism for transferring passkeys from one password manager to another. (I think all the password managers kinda like that lock in.) It's a nice simplifying step to talk about password managers here, but in the majority of the cases this won't be handled by a password manager, but rather by the device operating system, and the device manufacturers really like that lock in. They're also in an especially good position to abuse it, because they now know every service that you authenticate and the webauthn "attestation object" field lets them set up a side channel with those services such that they can sell additional information about you. Some people will tell you that the attestation object is not used in the consumer passkey system, so there's no way for this abuse to occur, but since it's usually going to be the device manufacturer who controls the password-manager-like component here, and they're the ones who stand to profit most from this kind of abuse, I think we need stronger guarantees than "the spec says you shouldn't do this unless the user is your employee and you paid for their device". Until they fix this, I'm sticking with my mess of TOTP authenticators and yubikeys.
- dfabulich 3mo agoAll of the major operating systems and all of the major browsers are password managers. Apple, Google, Microsoft, and Mozilla are all password managers. They all have apps that let you access their password managers on other operating systems. You're right that all of the major password managers like their lock in. The Credential Exchange Protocol is just barely good enough that OS vendors can say they "support" it, but tricky enough to find that ordinary users probably will never try it. (Not to mention that it doesn't even work yet on Windows or Android.) As for attestation, the good news is that Apple always returns 0s for the attestation ID (because Apple, like you, opposes it as a side channel), and so any public site/app that insists on attestation would reject all Apple devices. This gives smaller password managers like Bitwarden sufficient cover to 0-out their attestation as well.
- pseudalopex 3mo ago> As for attestation, the good news is that Apple always returns 0s for the attestation ID (because Apple, like you, opposes it as a side channel), and so any public site/app that insists on attestation would reject all Apple devices. The bad news is this could change.
- robertlagrant 3mo ago> The weird part is that password managers provide no way for you to copy and paste your passkeys. The main feature of passkeys is that they can't be pasted into a website they shouldn't be pasted in to. That means you can't copy them, by design.
- Telaneo 3mo agoThey're just text behind the scenes, so you can copy them if you really want to. KeepassX lets you do it, and got into a kerfuffle about it.[1] It's an impossible design. It's all just obfuscation, most of which is confusing to users. [1] https://github.com/keepassxreboot/keepassxc/issues/10407 https://github.com/keepassxreboot/keepassxc/issues/10407
- robertlagrant 3mo ago> They're just text behind the scenes, so you can copy them if you really want to. KeepassX lets you do it, and got into a kerfuffle about it.[1] Yes - the kerfuffle is broadly I think the fact that it negates the main advantage of passkeys: people can't be tricked into pasting them into a fake login screen. > It's an impossible design. It's all just obfuscation, most of which is confusing to users. I agree - they're explained in a really odd way, and I think that's because they're a technology with multiple interaction patterns, rather than a single thing like a password. E.g. your fingerprint on your Mac is implemented as a passkey, or clicking on a browser passkey is also a passkey, or using a password manager via a different UI is also a passkey, or touching a Yubikey is also a passkey. The underlying mechanism (passkey) probably has been surfaced more than it should've been.
- giantg2 3mo agoThis seems like a consolidation of risk to rely on a password manager, especially software defined, especially if it relies on a password. I like the hardware token idea (yubikey). But even that seems cumbersome because you should be making a copy for safe keeping. And how do you securely do password recovery if most security questions can be obtained via osint or the reset links are sent to a site you are similarly locked out of is compromised?
- preisschild 3mo ago> This is much, much simpler than you think it is. Passkeys are just passwords that require a password manager. This is not true. There are device bound passkeys where the private key is stored in a HSM (TPM2.0, Android SE, or apple SE) instead of a hosted service (iCloud, Bitwarden.com). You can just add multiple Passkeys to a single site to have another backup device should your other one be unavailable.
- EvanAnderson 3mo agoSpeaking about hardware tokens: If I have to go get the backup out of "secure" storage each time I want to add a new Passkey it's not really a backup. The design should have allowed, even if it was just within only the purview of a single manufacturer, a method for the device to export an encrypted dump that could be reloaded onto a factory-new device. Heck, make it a value-added service that the manufacturer has to initiate and tie it to some real-world identity verification. The idea of having to put backup devices in-hand regularly is a bad design. Phone apps. get around this idiocy by backing-up the encrypted Passkeys to a hosted service.
- pseudalopex 3mo ago> If I have to go get the backup out of "secure" storage each time I want to add a new Passkey it's not really a backup. Yes. > even if it was just within only the purview of a single manufacturer > Heck, make it a value-added service that the manufacturer has to initiate and tie it to some real-world identity verification. No.
- pseudalopex 3mo agoJust have the 2nd device when you create any account. But have it away from the 1st device always. Just update 10s or 100s of accounts for every new device. Just never use sites which allows 1 Passkey.
- deleted 3mo ago[deleted]
- Melatonic 3mo agoOldschool KeePass ftw
- pibaker 3mo ago> This is much, much simpler than you think it is. Passkeys are just passwords that require a password manager Cool. So can I write down my passkey on a piece of paper and put it in a safe? > you'll reset your passkey the same way you reset your password, probably with a "forgot my password" email Cool. But what if I lose the passkey to my email account? > and the passkey will be stored there and synchronized to all of your other devices Cool. Surely backups and synchronization never fails. > The weird part is that password managers provide no way for you to copy and paste your passkeys Uh oh. So you are saying passkeys are not like passwords? Last time I checked, every password manager lets me copy and paste my passwords just in case. > To present a passkey, you have to use a password manager Uh oh. So you are saying passkeys are not like passwords, like at all? Last time I checked, I can just type in my password using a keyboard on all websites I visit. > This makes it impossible to copy and paste your passkey to the wrong person Uh oh. So it means I can't just give my password to a family member sitting in the opposite side of the room? Sorry mom, corporate has decided that you are trying to trick me. > Major password managers don’t even allow you to export your passkeys to a file that you can read/backup yourself Uh oh. So is there a registry of Major League Password Managers that are guaranteed to implement Corporate Strength Cybersecurity Measurements? Will I be blocked by services if I happen to have landed on a minor password manager?
- gblargg 3mo ago> This is much, much simpler than you think it is. Passkeys are just passwords that require a password manager. If you lose your passkey, you'll reset your passkey the same way you reset your password, probably with a "forgot my password" email. This is why I don't bother with these if they have a weaker workaround, which will be open to remote hacking.
- pseudalopex 3mo ago> Passkeys are just passwords that require a password manager. Passkeys are passwords which allow a relying party to control what password manager you can use.[1] [1] https://news.ycombinator.com/item?id=46305566 https://news.ycombinator.com/item?id=46305566
- jhhh 3mo agoI am not happy about a trade-off which involves me having to cede control of my digital identity to 'providers' who will not give me access to it, in exchange for maybe not getting phished. If passwords continue to exist for a long time then this entire exercise is pointless as they can still get phished. If passwords go away and we can only use passkeys then you're only entry point to any kind of digital account is through one of the designated providers. If you don't have a provider that spans all of your platforms then you're screwed or have to manage multiple pass keys which is also stupid. Even the current crop of online providers as you illustrated in your post are unsecure and unreliable. No thanks.
- boobsbr 3mo ago> Passkeys are just passwords that require a password manager. How come I log into my corporate Windows laptop by typing a passkey instead of a user/pass combo?