5 ms·
Passkeys have a marketing problem where no one is able to describe simply what it is without having to use technical jargon. There's also the problem where each
by kenrick95 10d ago
Passkeys have a marketing problem where no one is able to describe simply what it is without having to use technical jargon. There's also the problem where each OS tries too hard in pushing this to the face of end-user
- etatester 10d agoIt's a key, what else do non-technical people need to know? Ironically on macOS we used to have an app called Keychain which unfortunately was effectively renamed to Passwords for non-technical users.
- paulryanrogers 10d agoIt's a digital key. Unlike physical objects they may reside in a TPM, a software vault, an export/backup, or any combination thereof. You may or may not be able to recover or migrate them, depending on where/how they were made. Therefore you may need multiple per service, or maybe not. Services which only allow one may end up locking you out with no recourse. You get to find out. None of this is obvious or self explanatory to normies.
- kskdkwkdkwk 10d agoProbably because these caveats and weird behaviours are platform-dependent, not really the passkey’s fault. Passkeys really are not any more difficult to explain than 2-factor authentication. Anyone who’s currently been able to actually create an Apple or Google account and successfully navigate their devices up to a passkey screen will be able to grok how it works. People around here really ought to stop thinking users are complete idiots. Hell, you don’t even to scroll that far to read people calling users “normies” for crying out loud. What is this? High school?
- alt227 10d agoYou obviously dont have to deal with anybody who doesnt know how or want to use computers.
- paulryanrogers 10d agoDo you know how many Google and Apple accounts my boomer parents have? Roughly one per smart-phone that they've ever used. They don't know the passwords or even the email address of any of them, not even the latest.
- etatester 10d agoTell me how passkeys makes this any worse. If one's digital life is a mess, there's no magic solution to it.
- paulryanrogers 10d agoArguably Yubikey and similar are better. Even vanilla passwords are at least understood by my parents, despite their confusion over account proliferation. Passkeys are a step backward for them, even more so in light of account confusion.
- cpburns2009 10d agoI don't care about the theoretical sufficiently advanced keypass implementation that works perfectly. I want to know about the half baked ones in the real world that I'll have to deal with.
- etatester 10d agoThat's false. It's a digital key and it doesn't matter where it's stored. My key is on iCloud and it can be unlocked with my many recovery methods and contacts https://support.apple.com/en-us/102641 https://support.apple.com/en-us/102641 As for normies, passkeys or passwords it doesn't make a difference. Either you have people who use love1969 everywhere or those who constantly lose their passwords. All passkeys accounts for normies require an email or phone number, which is what you can use to recover a password or passkey exactly the same way.
- paulryanrogers 10d agoWhere passkeys are stored is as important as where physical keys are stored. People must understand security controls, at least at a surface level, in order to effectively manage and trust them. Passkeys fail that test.
- arwineap 10d agoThe keychain and passwords app are separate and keychain still exists I always operated under the assumption that the passwords app was just a more casual view into the keychain Maybe that's a bad assumption
- joombaga 10d agoThey're separate stores. I was under the same assumption until I tried to use `security` to get a saved password. It doesn't work, and as far as I know there is no CLI for the Passwords app's store.
- lezojeda 10d ago[dead]
- ryan-duve 10d ago> Passkeys are passwords your second device makes/types for you, without you ever seeing it. My bigger problem with passkeys is how there's no universal way to register more than one device (in case the first one is lost).
- blackdahlia313 10d agoProton Pass. I moved to it and love it.
- malfist 10d agoProton Pass hardly meets the bar of "universal way to register more than one device" Proton Pass is a specific way to do that, but not a universal way. Bitwarden can't use proton pass to move keys around, google can't, firefox can't.
- deleted 10d ago[deleted]
- jmbwell 10d agoThis burden is on the site using passkeys. There should be some equivalent of “My Account > Security > Passkeys > Add Passkey.” There often isn’t, which is an incomplete implementation. And yes it’s frustrating.
- cfiggers 10d agoImagine a password, but it a) types itself for you and b) detects when it's being sent to an impostor site and blocks them from seeing itself, so it can't be phished. Tada, passkeys.
- rcxdude 10d agoCool, where are they stored? (I know the answer: 'it depends', and that's the big problem with their usability: most users haven't a clue what the answer is and most tech support can't answer that question straightforwardly because it depends on some decisions the user probably didn't even realise they made).
- wolvoleo 10d agoIn a secure vault on your phone
- mystifyingpoi 10d agoSo if I drop my phone to the toilet, I will forever lose access to everything? Since the vault is on my phone.
- faust201 10d agoA majority have more than one phone. Or at least they can get a new SIM card and sign into the iCloud account. Then all passkeys are synced from cloud. Yes, if you are edward snowden then not for you. For rest of us - it is useful
- lezojeda 10d ago[dead]
- Spide_r 10d agoThat's the main thing I wish was done better. There was barely any actual lead up from the perspective of an average person. Just a new unfamiliar flow on half of the login screens that they use. Sure, its explained. But not in a satisfactory way that would reach all users at their level. This is a bit of an exaggeration and out of proportion, but I think my ideal would be one of the big tech companies should have bought out something like a super bowl ad. Something that actually conveys the idea "hey, we know you've used passwords since you were able to type on a keyboard, but here's new technology that's better and here's why" in plain language that the average person can understand. Unfortunately, XKCD 2501 continues to be relevant. [1] [1] https://xkcd.com/2501/ https://xkcd.com/2501/
- Al-Khwarizmi 10d agoThe average person? I have a Master's and PhD in CS, code regularly, and have followed and used all the cool technologies from the days of gopher, telnet and Mosaic to crypto, and lately LLMs. And I still don't have a clear enough picture of passkeys to know really basic things like "what if we have a family computer but each wants to access their private accounts and keep the others from accessing?", "what do I need do to login from an airport computer?" or "what should I do if my phone is stolen?" If it's that unclear to me, I can't imagine how it can be to the average user. The way they explain them is atrociously unclear, borderline negligent for services that nag people to activate it for accounts where they may hold valuable data for their personal lives. And while I don't want to spend much time finding out the details as long as I have the option to decline them, I suppose if they can't explain it and convince people of its advantages, it's because it's just bad tech.
- alt227 10d agoI cant upvote you enough for this very concise explanation of passkeys pain points.
- johanyc 9d ago> "what if we have a family Computer but each wants to access their private accounts and keep the others from accessing?" That's what OS level user accounts are for. Tbf > "what do Ineed do to login from an airport computer?" or "what should do if my phone is stolen?" Indeed I don't know the answers to these either if I wasn't syncing passkeys in 1password. Honestly we should educate people to use password managers more than any thing. It's also a smaller jump than to passkeys. Passkeys can be more of an advanced convenience feature after they get used to using password managers already.
- mikepurvis 10d agoSurely it's a pretty easy pitch to average Joe: Using a passkey takes the place of typing in a code they sent by text or email. That's a pain point in everyone's day that should make the benefit easy to understand.
- alt227 10d agook cool so when somebody logs into a site on their phone and sets up a passkey, then goes to their laptop and tried to log into the same account, how do you easily explain how to deal with this situation?
- kps 10d agoYou don't. A laptop might still be a general-purpose computer under the owner's control, and we discourage those.
- stetrain 10d agoWhat I have seen is that the site gives you a QR code to scan with your phone. People are already used to needing their phone to sign in via an Authenticator app or SMS code.
- jmbwell 10d agoI tell people a website is like a payment terminal. Your device is like your debit card. A password is like a PIN on the card. A Passkey is like a chip on the card. Logging into a site with your device is like putting your card into the terminal. The site can ask for a password the way the terminal asks for a PIN, but if your device supports Passkeys, that’s like your card having a chip, and it’ll use that instead. So think of Passkeys like using a chip card. I dunno how well this analogy works down to the last detail but it has gotten it across to all the parents I’ve used it with
- dgunay 10d agoDo most people understand why cards have a chip in them now?
- Telaneo 10d agoProbably not. The magnetic strip was easy to explain (it contains some info the terminal checks, it's functionally just a long password), but it's also pretty easy to explain why skimming was a problem. Explaining how chips fixed that (signing keys and cryptography) is probably beyond a 30 second explanation with Joe Schmo. Then again, I doubt most people care to know, which is why that explanation works. They're not going to ask 'where is the passkey in my computer?'.
- seirim 10d agoGreat analogy, am going to use that going forward, thank you.
- dboreham 10d agoAs implemented they also lack conceptual integrity: you get them somehow (where are they?), and somehow you can use them (how, exactly?) but you can't enumerate them anywhere, see them, see where they came from and what they can do for you.