Why passkeys are a step back for personal security: examining account lockout risks, platform lock-in, hardware key limits, and fragile recovery flows.
I think their biggest weakness is the vendor lock in. Using a 3rd party password manager is the best solution for most people, so they arent locked to their phone. But they are right in saying none of it is quite ready.
I think the article is forgetting, they are password replacements, not account recovery replacements. Realistically, people are just as likely to forget a password, and account recovery proceedures still have to be in place. I dont see the issue there.
Passkeys are good they are just being pushed before properly fully developed, but we are slowly getting there.
The main problem is if that you lose the device that’s physically attached to the passkey… You’ll lose your account.
I’d just prefer a biometrics-first approach.
Unless hackers started cutting people’s fingers, which is something just too risky for a rational hacker to do so it’s more than improbable, biometrics are way more secure, consistent, battle-tested and most important, more convenient and, by design, unforgettable.
How the fuck have you never heard of fingerprint copying?
Every fingerprint scanner which attempts to apply liveness detection has been fooled.
No biometrics is secure when used remotely. Ever. You can literally just replay the biometric data people send you after you create a phishing site and hack their accounts if it was sent raw.
That’s why you shouldn’t use exclusive on device storage for them, like Apple/Google want you to. Biometrics are shit, I prefer passwords if we are having no passkeys. I agree they are not perfect, but we can improve them and they will be a lot better than passwords for the majority of people.
Also, you wont lose your account, youll just have to go through a recovery process. Exactly the same as you would now if you forgot a password or lost a MFA code.
Don’t proper biometrics also lock you to a device? My phone isn’t sending my fingerprint anywhere, it’s comparing data against its baseline and then attesting that. If you did it any other way, then any data leak means you’re exposed literally forever.
Passkeys are just more convenient replacements to passwords, ideally suited for a password manager flow.
For most people, this works really well and is a lot better than remembering loads of passwords. It’s easier to get people to remember a single stronger password and use passkeys to login to services.
The whole lose access thing isnt as big of a deal breaker as you make it sound (It literally works the same as it does now with passwords). Considering the large amount of people that forget their passwords and constantly reset them, passkeys can help. There’s a reason popular sites just ask you for a code from an email now instead of even prompting for your password.
You want to use biometrics to individually login to services, great. But what about those of us who don’t want to rely on biometrics? That’s where passkeys do both jobs.
Biometrics is inherently not securable and the only viable method of using it ever is locally only to unlock a different secret, which actually can be secure.
Most biometrics is trivial to duplicate, fingerprints can replicated from photographs.
Biometrics are battle tested and got annihilated in every conflict. It’s a total loser.
I think their biggest weakness is the vendor lock in. Using a 3rd party password manager is the best solution for most people, so they arent locked to their phone. But they are right in saying none of it is quite ready.
I think the article is forgetting, they are password replacements, not account recovery replacements. Realistically, people are just as likely to forget a password, and account recovery proceedures still have to be in place. I dont see the issue there.
Passkeys are good they are just being pushed before properly fully developed, but we are slowly getting there.
The main problem is if that you lose the device that’s physically attached to the passkey… You’ll lose your account.
I’d just prefer a biometrics-first approach.
Unless hackers started cutting people’s fingers, which is something just too risky for a rational hacker to do so it’s more than improbable, biometrics are way more secure, consistent, battle-tested and most important, more convenient and, by design, unforgettable.
Naww… biometrics are easy to steal or coerce from people.
Lmao, easy to steal.
What’s going the hacker to do? Cut off your fingers or extract your eyeballs? 🤣🤣🤣🤣
How the fuck have you never heard of fingerprint copying?
Every fingerprint scanner which attempts to apply liveness detection has been fooled.
No biometrics is secure when used remotely. Ever. You can literally just replay the biometric data people send you after you create a phishing site and hack their accounts if it was sent raw.
That’s why you shouldn’t use exclusive on device storage for them, like Apple/Google want you to. Biometrics are shit, I prefer passwords if we are having no passkeys. I agree they are not perfect, but we can improve them and they will be a lot better than passwords for the majority of people.
Also, you wont lose your account, youll just have to go through a recovery process. Exactly the same as you would now if you forgot a password or lost a MFA code.
Biometrics are NOT shit.
And the recovery process is useless if you don’g have acess to your recovery method. Passkeys create the Ouroboros kind of situation.
Don’t proper biometrics also lock you to a device? My phone isn’t sending my fingerprint anywhere, it’s comparing data against its baseline and then attesting that. If you did it any other way, then any data leak means you’re exposed literally forever.
Passkeys are just more convenient replacements to passwords, ideally suited for a password manager flow.
For most people, this works really well and is a lot better than remembering loads of passwords. It’s easier to get people to remember a single stronger password and use passkeys to login to services.
The whole lose access thing isnt as big of a deal breaker as you make it sound (It literally works the same as it does now with passwords). Considering the large amount of people that forget their passwords and constantly reset them, passkeys can help. There’s a reason popular sites just ask you for a code from an email now instead of even prompting for your password.
You want to use biometrics to individually login to services, great. But what about those of us who don’t want to rely on biometrics? That’s where passkeys do both jobs.
Biometrics is inherently not securable and the only viable method of using it ever is locally only to unlock a different secret, which actually can be secure.
Most biometrics is trivial to duplicate, fingerprints can replicated from photographs.
Biometrics are battle tested and got annihilated in every conflict. It’s a total loser.