4 ms·
I think this is the biggest reason why these category of discussion happens in the first place, there is a gap between what technology is good for, whats its id
by sandeepkd 15d ago
I think this is the biggest reason why these category of discussion happens in the first place, there is a gap between what technology is good for, whats its ideal for and then the products motivation to push it on to the user assuming it would give a good name to the company.
Passkeys are one of the few protocols that supports against phishing (Accidentally giving away your credential to some rough site) so it has its benefits and more so for enterprise users.
It becomes challenging and is ill suited when its pushed to general public. A middle ground could have been to give it as an option to user instead of forcing it on the user. For some reason its not cool enough.
From a company's perspective
- Authentication is a friction and the discoverable credential (where you just click on username button and log in) reduces the friction for user, making it easier for user to make that purchase decision
- Account take over attempts (ATOs) do take a dip, saves quite a lot of resources on customer support side for the company
- tyre 15d agoIMO it’s well-suited to the general public! What is the average person’s threat model? Re-using passwords. What is their most common annoyance? They forget their passwords. Built-in password managers are great for this. But they’re not universal (e.g. I believe using Apple Passwords on Mac doesn’t carry over to Android.) Passkeys are amazing. They’re basically magic to the average person. No typing passwords; no remembering; simply vibing, securely. I don’t think people are regularly logging in to a huge number of accounts on other devices. Maybe they are! I doubt it.
- TeMPOraL 15d ago> What is the average person’s threat model? Re-using passwords. Wrong. As article points out, it's not having access to their account. Followed by not being able to easily delegate access to their account to a trusted third party (like a spouse, a friend). Password reuse addresses the first problem, however imperfectly. Ability to share password over any channel, including analog, addresses the second. Passkeys defeat both.
- jesseendahl 15d agoAccount recovery works the same with passkeys as with passwords. You click “I forgot/lost my passkey” and get a link sent you via email that lets you create a new one. Passkeys can also be shared with other people like spouses or friends, just like passwords.
- TeMPOraL 15d ago> Passkeys can also be shared with other people like spouses or friends, just like passwords. How? They're literally designed to not be, because they're trying to prevent phishing, and you cannot in general case distinguish phishing from legitimate delegation of authority.
- HappMacDonald 15d ago> Account recovery works the same with ... Huh, that is a really funny way to spell "the primary login method used by every not-tech-savvy person I have ever met before".
- TeMPOraL 14d agoOh right, I started to notice it too - couple non-tech people around me seem to treat "password reset" as default login flow, and definitely don't complain as much about auth flows as the rest. I guess that's one effective way to cope with security industry bullshit.
- duskdozer 14d agoThis would explain why so many places have been starting to force me to log in with an email instead of a password.
- hakavlad 15d ago>You click “I forgot/lost my passkey” and get a link sent you via email that lets you create a new one I don't trust my email provider.
- 15d ago
- sandeepkd 15d agoI guess it really depends on how one choses to define general public, probably an assumption has been made that everyone has their own personal device. > Built-in password managers are great for this. But they’re not universal (e.g. I believe using Apple Passwords on Mac doesn’t carry over to Android. 1.Only security keys (single device credentials) are what you can use across the device not the regular platform based one 2.Browser based password managers do provide you with that interoperability across the platforms and in fact the password manager as an supported passkey authenticator allows you do the same
- hulitu 13d ago> Passkeys are amazing. They’re basically magic to the average person. Passkeys are crap. They are just random password prompts to give a false sense of security.