3 ms·
> refuses to allow me to authenticate to it because it wants a passkey I don't have... it wants me to use an Android phone I (also) don't have And yet you love
by jmull 8d ago
> refuses to allow me to authenticate to it because it wants a passkey I don't have... it wants me to use an Android phone I (also) don't have
And yet you love passkeys? How much will you love them when you're locked out of something you can't do without?
- ethin 8d ago> And yet you love passkeys? Yes. The security benefit can't be overstated. > How much will you love them when you're locked out of something you can't do without? I certainly wouldn't be happy if this did happen, but it would be my stupidity (or the stupidity of those who implemented it on the service/platform where the problem occurred) which I would blame more than the fault of the tool. I do keep all passkeys in Bitwarden now so that's something at least.
- jmull 8d ago> The security benefit can't be overstated. Security benefit appears strongly overstated. Compared to using a password manager (including generated secure passwords for each account), there isn't a significant security benefit. passkeys require using a manager as well, so there isn't much point. > ...but it would be my stupidity... All people are stupid sometimes. A security flow that doesn't account for this very well isn't a very good security flow. (Related: everyone tends to be unlucky eventually, and, unfortunately, everyone becomes incapacitated/dies eventually. Security flows need to account for these as well. Not to mention that in my experience, no software company continues to offer a quality service at a reasonable price forever. You're lucky to get 10 years. Having access to my accounts tied to a single piece of software is likely to become a big pain at some point.)
- flumpcakes 8d ago> passkeys require using a manager as well, so there isn't much point. No they don't. I use hardware passkeys for all my important accounts. It's extremely easy.
- nulltype 7d agoI think this is probably one of the reasons people have very different passkey experiences. Hardware passkeys are great and software ones appear to be less great.
- tadfisher 8d agoPasskeys are somehow 100% seamless for me, except for two services that have somehow screwed up the implementation: Google, and Okta. In Google's case, they have made it so that if you _ever_ add a passkey to their password manager, it somehow refuses to work with a third-party password manager going forward. In Okta's case, the admin policy UI makes it next to impossible to have passkey-only login without their Fastpass app or an oldschool password login.