8 ms·
Passkeys do marginally improve security against MITM and phishing attacks, but they are primarily for protecting the lowest common denominator from themselves:
by drtz 14d ago
Passkeys do marginally improve security against MITM and phishing attacks, but they are primarily for protecting the lowest common denominator from themselves: people who re-use passwords and/or don't use a password manager.
If you use multiple devices throughout the day, registering passkeys in all of these systems becomes a big headache with O(m*n) complexity, so putting the passkeys in a password manager is the only realistic solution. But this still breaks the login flow for a very common use case: how do I log in on a device that I don't own? With a password in a password manager I at least have the option of manually typing the password.
The biggest problem, though, is how users are pushed into it without any warning or knowledge of what they're signing up for. I've accidentally set up passkeys just by clicking an okay button a few times in the past and had to go back and figure out how to undo it after being blocked from login on another computer (which computer was I on again?).
- mystifyingpoi 14d ago> how do I log in on a device that I don't own? Sad reality is that such usecase is less and less common, thus, no one cares about it. I think majority of my friends would not be able to access their email, or facebook or alike, if they were forced to use my computer in emergency.
- Latty 14d agoWhich is a trade-off that makes sense for a lot of people. If you have multiple devices, many of which are portable and one you have on you all the time, the need for that is just way lower, so being more secure against commonplace automated widespread attacks is worth it to them.
- iamnothere 14d agoMany people are moving to only a single portable device that’s easily lost, broken, or stolen, without any understanding of backups or fallbacks for their accounts. And many are moving to virtual wallets like Cashapp rather than banks with a physical presence where you can take out money without a phone. It’s a bad situation.
- pixl97 14d agoHeh, this situation totally reminds me of politics. Person 1: "People that end up in this situation that can easily happen should be punished to the full extent of the law with no mercy!" [Exact situation happens to Person 1] Person 1: "This is the greatest injustice, do people have no empathy? I could not have avoided this situation!"
- fredm7 12d agoThat sounds deeper than politics… More like human nature.
- cj 14d agoIsn't there a workflow where you scan a QR code to confirm the pass key on your phone? I've definitely done this, but not sure if the workflow was at the OS or browser level. I'm honestly confused by all the negativity in the comments. Passkeys are great for convenience. Just leave your password login enabled as a backup. That defeats any security benefit, but oh well.
- dgunay 14d agoThere is. Doesn't work on every browser but it's really nice and I use it routinely.
- kps 14d ago> Isn't there a workflow where you scan a QR code to confirm the pass key on your phone? For people in this position, if they had their phone, they probably wouldn't be logging in on a computer anyway.
- limagnolia 14d agoThere are a lot of reasons why I might want to login on a computer I don't own to do something, rather than to use my phone. Having a keyboard is a major usability benefit for many types of work. Larger screen, printer. Software that is on the machine that can't run on my phone.
- kps 14d agoI agree with you; those are all reasons I only use my phone for on-the-go messaging or navigation. I'm against the idea that you should have to have a secure (against the owner) connected phone on your person at all times in order to sign in to a web service.
- vel0city 14d agoYou don't have to with passkeys. I use passkeys every day, they rarely involve using my phone.
- alienbaby 14d agoRubbish. Such use cases are extremely common anywhere it can't be expected everyone has access to their own device.
- megous 14d agoThat's actually a good use case for HW keys. Since untrusted computers are much more likely to have keyloggers/malware, etc. So you don't need to reset password and invalidate all sessions after each such login on an untrusted computer.
- epihelix 14d agoAnd that sounds fine, until you're traveling and your devices get stolen or lost. How, exactly, are you going to get into your email then, once passkeys become the only means of login? Because that moment is when you really do need to access your email, stat.
- jayknight 14d agoWhat services implement it like this? Don't services usually implement passkeys as a more secure alternative to a password, but password login is still available? Some sites allow passkeys as an option for MFA, so that could be an issue if the passkey is your only MFA option and MFA is required. But I imagine email would pretty much always be a fallback.
- basch 14d agoWhen was the last time you tried to log into something like Google, Apple, Microsoft etc without your phone nearby, on a fresh computer?
- mrweasel 14d agoDidn't Outlook.com famously rolled out passkeys with no recovery option and no option to sign in using username and password once enrolled. So if you lost your trusted device, you couldn't sign in, nor could Microsoft send you an email, because... Outlook.com is your email provider. I don't know if they fixed it, they probably did. Edit: Maybe not, because the recovery option at the end is just nuts: https://learn.microsoft.com/en-us/answers/questions/5454924/i-forgot-my-passkey-and-want-to-know-how-to-reset https://learn.microsoft.com/en-us/answers/questions/5454924/...
- mahboi 14d agoNothing but a memorized password works in this scenario, right?
- MrMetlHed 14d agoAnd not even that, now that I think about it. I have my very long Bitwarden password memorized but if my devices are all stolen I won't be able to get passed the 2-factor, so I'd still be screwed.
- makeitdouble 14d agoA variant of that is alternative accounts that properly live on a different device/context. For instance YouTubers usually have a different account for their channel than the one they use privately, and don't want their channel account logged in everywhere. That means having to log in as a guest when push comes to shove. And similar setups are common for most self-employed keeping a "work" account IMHO.
- deleted 14d ago[deleted]
- Latty 14d agoThe offer a strong protection against phishing attacks that would still get plenty of password manager users: fake websites. A passkey is strongly linked to a domain, so a fake site can't get that credential. Some password managers will only fill if a domain matches, but IRL the response I've seen from most users when it doesn't match is to assume the integration broke and manually copy/paste it in. I've also seen lots of them do stuff like happily autofill on any prefix of the domain, so your credential for `something.example.com` will autofill into `fake-something.example.com`.
- flerchin 14d agoHow did fake-something get injected as a subdomain?
- lapcat 14d ago> Some password managers will only fill if a domain matches, but IRL the response I've seen from most users when it doesn't match is to assume the integration broke and manually copy/paste it in. I've also seen lots of them do stuff like happily autofill on any prefix of the domain, so your credential for `something.example.com` will autofill into `fake-something.example.com`. Why would you trust the very same password managers that don't handle passwords properly to handle passkeys properly?
- 6P58r3MXJSLi 14d ago> Why would you trust the very same password managers that don't handle passwords properly to handle passkeys properly? Gell-Mann amnesia effect https://en.wikipedia.org/wiki/Michael_Crichton#%22Gell-Mann_amnesia_effect%22 https://en.wikipedia.org/wiki/Michael_Crichton#%22Gell-Mann_...
- judge2020 14d ago> how do I log in on a device that I don't own? This is solved by passkey-implementing software and devices (with Bluetooth) allowing you to log in with a QR code (Webauthn via CTAP hybrid transport). iOS and Android support this, and it’s generally not a locked-down thing if other devices wanted to do it too. The only use case left is in “how do I login if all my devices are stolen/fall into a body of water” in which there really isn’t an answer beyond “get (a|your) device back, sign back into your password manager, use that to get back into critical accounts”.
- 201984 14d agoWhat if the computer you want to log in on doesn't have Bluetooth? Probably most public computers (like ones in libraries) don't have it.
- limagnolia 14d agoThe website should display a qr code you can scan with your phone that allows you to then login, unfortunately a lot of sites don't implement this, and some don't implement backup codes. This isn't the fault of passkeys per se, but of poor implementations.
- 201984 14d agoHow does scanning the barcode with your phone log you into the computer? Does your phone need network access for that?
- jerkstate 14d agowhat good is a phone if it isn't on a network?
- cpburns2009 14d agoHave you ever been in a large building with awful cell reception and no wifi access?
- cryptoegorophy 14d agoiCloud Keychain? Is there a reason not to use it? Aside from having android.
- HaloZero 14d agoMy MIL setup a passkey accidentally on her Google account and now has no idea where it is. Removing it now requires her password which she’s also forgotten. But now for some reason on Google I can’t initiate any type of forgot your password flow because of how Google sets up things and I have zero clue where she stored the passkey.
- UltraSane 14d agoDoesn't the passkey have to be on her phone or computer?
- HaloZero 14d agoIt should be but haven’t checked her apple vault. I checked Google password manager and her windows password manager and there nothing in either. She might have used her phone and it’s in her iOS vault which I’ll check next. But this is what makes this entire passkey thing a mess. She’s 75, she didn’t do this on purpose and the ecosystem is just a mess
- ryandrake 14d agoEven the concept of "where on the PC" has been totally annihilated by OS vendors and app developers. Is it on the filesystem? Is it on The Cloud? Is it vaguely "In An App"? Is it in some "Secure Enclave"? Who the fuck knows anymore? And the apps are no help--they insist on blurring the lines between local and cloud, hiding full paths, and generally just saying "Don't worry about where your data actually is. We pinky swear to be able to find it for you!"
- HaloZero 14d agoWindows prompting her about Bluetooth for the pass key threw me too. I thought for sure she had clicked the wrong thing before I realized that somehow her widows pass key requires communicating to some device? Maybe her phone? No idea
- mikepurvis 14d agoI'm just storing my passkeys in 1password, which means they're synced across my two computers and phone and also means I gave up any kind of hardware security. Oh well.
- winstonwinston 14d ago> I've accidentally set up passkeys just by clicking an okay button a few times in the past and had to go back and figure out how to undo it after being blocked from login on another computer (which computer was I on again?). No doubt there exist services that do not offer recovery method for passkey or mfa enabled account. But this is entirely on them (the service) to blame for, not the passkeys or the users.
- kyleee 14d agoBad implementations of an otherwise sane/fine technology can sink the technology. Here’s to hoping that happens with passkeys
- throwaway27727 14d ago> how do I log in on a device that I don't own? You scan the qr code from your phone and it logs you in on that device. The experience is pretty amazing, honestly.
- xboxnolifes 14d agoThey mean if you dont have access to your devices.
- Bolwin 14d agoWhat if you don't own a phone?
- TacticalCoder 14d ago> Passkeys do marginally improve security against MITM and phishing attacks ... The tragedy of passkeys is that they're a step back from the security offered by the likes of Yubikeys. But because passkeys are pushed by both Google, Microsoft and Apple: there is is simply no fighting these three. It is impossible. Passkeys won not because they're better (they're not and the entire concept of "secret behind a hardware security module" that can be transferred to another system defeats the whole point of a HSM in the first place) but because the powers-that-be decided that passkeys are to be used. It's still a win: the commoners are better served with passkeys. But a secret in control of Google/Apple/Microsoft that can be backed up is not a secret I control: it's a complete step back from yubikeys. Passkeys won and we better get used to them (and, yup, there are usability issues as you mentioned).
- hexfish 14d agoWhy not just use a passkey backed by your Yubikey?
- dspillett 14d ago> The biggest problem, though, is how users are pushed into it without any warning or knowledge of what they're signing up for. My irritation is that I know what it is, and I've said no thanks many times, but I'm still asked regularly by the likes of Amazon, and they usually pick a time when I'm trying to order something quick¹. It is one of the growing number of things in life that simply have no “no” option, it is always “yes or later” - I wouldn't mind so much if “later” meant “I know the option exists, I'll ask for it if I change my mind, don't bother me again otherwise”. Call me cynical, but if companies are trying to nag me into something I very much doubt the main benefit is mine. I'm sure there are many people out there who go along with it simply because they are sick of being asked repeatedly. I also don't see the real benefit with the way things are often implemented anyway. When the credential recovery process is sending a magic email or text, making SMTP or SMS the weak link of the chain just as it often is for passwords so I'd be giving up my preferred workflows for no better security. ---- [1] A short while ago I actually ordered from somewhere else because of this, bitter twit that I am. “I wonder if I can get this almost certainly drop-shipped item on next day delivery via Prime?”, [goes to Amazon to check], [get passkey prompt], “sod it, I'll go back to the original place”.
- ProjectArcturis 14d agoI dropped Amazon entirely a couple years ago because they didn't provide any way at all to separate my credit card from my kid's Fire tablet and I didn't want to be on the hook for thousands in charges because he pushed the wrong button. It's remarkably easy! It has made basically no change to my life except that I'm a little smug about not using Amazon.
- gxs 14d agoWhat do you use instead? My main reason for using Amazon is the shipping which no one else can come close to Same or next day shipping on most things I order is wild, when something goes beyond a 2-3 days on Amazon it even feels odd And the “do you actually need the item/s that fast” isn’t the response I am looking for
- 14d ago
- section_me 14d ago> If you use multiple devices throughout the day, registering passkeys in all of these systems becomes a big headache This is why you use hardware keys which work across devices like yubikeys and the like. I have two of the old neos and two of the newer usb c + NFC enabled ones. No issues.
- moebrowne 14d agoSome would consider spending over $200 on hardware keys an issue.
- jazzyjackson 14d agoPeace of mind is a luxury good
- radlad 14d agoSony Playstation will only let you setup a passkey if you disable password auth. But I have not found any way to use my browser's passkey to login on my PS5. I can scan a QR code, but that requires logging into the mobile app with a passkey. And I can't add one to my mobile phone because I can't login on mobile... the passkey is on my laptop, and it won't autofill from 1Password (Android).
- jedbrooke 14d ago> But this still breaks the login flow for a very common use case: how do I log in on a device that I don't own? at least in Apple land, if you try to sign on on a device that you don’t own (let’s say a work laptop where you’re not signed in to your apple id) it’ll give you a QR code to scan with your iPhone and it’ll do faceID on your iphone then do some bluetooth handshake to use your passkey on the other device. I’m not sure if this is Apple exclusive or if android/windows/linux would be able to do the same
- pastel8739 14d agoOther OSes can do the same.
- jedbrooke 14d agoI’m a big dummy who commented before reading the article, this is actually called out there > The last option is to use “Hybrid Transport”, where you scan a QR code and connect via Bluetooth simultaneously to the computer. Whilst this option is secure and works in theory, reality is plagued with edge-cases where connections fail or Bluetooth is straight-up unsupported.
- rkagerer 14d agogo back and figure out how to undo it There's an undo? Could you elaborate?
- user3939382 14d ago[dead]
- Kinrany 14d agoIf passkeys were implemented properly, the would be most useful to relatively technical users that already use password managers. Ideally, the only real change is that a single text password is replaced with multiple non-text "passwords" that cannot be entered on the wrong website by accident. The problem is exactly that they're being forced on nontechnical users when the UX isn't even good enough yet to sell them to technical users.
- steezeburger 14d agoI had to mess with this just yesterday. I got a new cell phone and installed Microsoft Swiftkey and tried to login to Microsoft. It said my device's password or security manager would popup, but it never did and it never showed an option to login via password, just a mostly blank screen. I tried logging in from my laptop browser and it immediately tried using a passkey, but I've never created a passkey for Microsoft, so it errored out, still never showing an option for password login. I tried again and it errored out again and FINALLY showed the option to login via password. It had to fail 2 times to finally show the option for password login. I was finally able to login via password, then had to go to Microsoft's passkey management page to create a new passkey, store it in 1password, and use that on my phone. I'm a software engineer and it was annoying and time consuming and took a minute to figure out. How are non engineers supposed to even use this crap?
- antonvs 14d agoIt's gotten to the point where I assume "product manager" is a synonym for "incompetent person who breaks working products."
- jen20 14d agoIn the Apple ecosystem this is trivial - you select to sign in using a QR code which you scan with a device you do own. It works perfectly in my experience (of using them wherever possible for several years)
- thesuitonym 14d agoPasskeys are awesome if you're one person, with one account, on one device. As soon as any of those three aren't true, they're a huge pain in the ass.
- jasondigitized 14d agoThis. My simple brain is always like...."This passkey is going to be lost and only usable on this machine and I don't even trust that to work consistently because I do weird stuff sometimes"
- 9dev 14d ago> people who re-use passwords and/or don't use a password manager. So the vast majority of all humans on this very planet?
- ibrahima 14d ago> how do I log in on a device that I don't own? With a password in a password manager I at least have the option of manually typing the password. I agree with you 100%, although I will say that it seems like newer OSes (perhaps it depends on the desktop + mobile combination, or maybe Chrome + Android is enough, not sure) have a way for you to use a passkey from your phone by scanning a QR code. I still think it's not super user-friendly but it is a clever workaround at least. Most people are accustomed to scanning QR codes, so scanning a QR code from your phone to sign in seems like not too big of a leap. (Although I wonder if it conditions users to scan random QR codes to sign in which could be a bigger phishing problem lol...).
- ryanisnan 14d agoI haven't articulated my thoughts about passkeys nearly as eloquently, but you did an amazing job here. This really sums up a latent problem I've had with passkeys. Do you have a blog?
- OptionOfT 14d agoI have a passkey on CVS, but that YubiKey was eaten by the sewer. Thankfully I can still log-in with a password & text. But how to reset the passkey? No-one knows. Edit: I take that back, for some reason they stopped taking the password I used when setting up the account. It's only email or SMS with code verification + birth-date.
- catchnear4321 14d agoExcept this isn’t true? I use my github passkey on my phone to log in on my laptop by scanning a QR code. “My” laptop for work, which I wouldn’t put said passkey on.
- krsw 14d agoAs an IT manager weak and/or re-used passwords are an absolute scourge. Ideally every time you set a passkey you'd also add an OTP Authenticator factor as fallback. Passkeys are incredibly useful and relatively secure when pair with biometric authorization (touch/face ID). I agree with a lot of the points about consumer level use, but still think they're net positive compared with bad password (re)use. I'd advocate for email recover as a decent fallback, but there's only so much you can do when the average user won't establish a base line of security for their primary account and access point. Security is frustrating and it's hard to get people to do the bare minimum to establish secure access to their services.
- dwaite 14d ago> But this still breaks the login flow for a very common use case: how do I log in on a device that I don't own? With a password in a password manager I at least have the option of manually typing the password. This is meant to be solved by the cross-device flow - a QR code pops up that you scan, and a secure channel is established from that with your other device. [Disclosure: an editor of said standard] > The biggest problem, though, is how users are pushed into it without any warning or knowledge of what they're signing up for. On macOS/iOS, the system gives this prompt regardless of where your passkeys are being created/stored: Save a passkey? "<site>" supports passkeys, a stronger alternative to passwords that cannot be leaked or stolen. A passkey for "<username>" will be saved in "<provider>". There is a transparent upgrade option though that sites can request - basically when a site supports passwords and passkeys, they can request a password manager supporting both create and return a new passkey on password sign-in. > [...] and had to go back and figure out how to undo it after being blocked from login on another computer (which computer was I on again?). That's unfortunate. A site/service should absolutely not replace other passkeys, nor should it remove other sign-in options like passwords, without explicit user consent. The above credential upgrade flow makes that doubly so; even if someone relies on a password manager to manage and provide their credentials for a site, it very well may not be the singular piece of software that does so.
- raron 13d ago> This is meant to be solved by the cross-device flow - a QR code pops up that you scan, and a secure channel is established from that with your other device. That only works if the device has working camera and bluetooth. What if I want to log in from my new desktop PC to an account whose Passkey is stored on my old desktop PC?