Why passkeys are a step back for personal security: examining account lockout risks, platform lock-in, hardware key limits, and fragile recovery flows.
I don’t know that OP is wrong per-se, but I think they’re overstated a bit.
Their statement that passkeys are better than people using the same password, but are a step back for people using a password manager, is maybe a bit much. It’s basically the same, but sometimes better.
Most of their drawbacks are the hardware implementations, but that’s already true of people using hardware 2FA, and corporate management, which is already a problem if you use Apple’s or Google’s existing baked-in password managers.
But if you don’t already have both of those problems, the standard is basically just “instead of having the password manager pretend to type in a box, what if they dumped something into the stream directly”, and that extends to what if the UI didn’t ask for anything and just said “hey, do you want to login? Just let me know and it’s done”
And, like, should you be able to export from Apple’s built in store to migrate? Absolutely, but if you never used Apple’s passkeys in the first place, because ugh gross, then it’s not a problem you need solved yet.
There is one problem I’ll admit, which is that it’s easier to make a sketchy password manager that just pretends to be a keyboard. I myself don’t actually use passkeys because I sync my passwords with git and use pass, which is cool and I love it. And then I type them using a dmenu script and xdotool, which is silly and I love it. But that doesn’t work with passkeys which I can definitely store in git, but would require a real actual connection between my browser and the tool, in a way that I don’t think currently exists.
But just because I can’t use my sketchy crap, doesn’t always mean it’s a step back 😛
The article is saying that while passkeys could theoretically be better, the current implementation is bad because it cedes power to centralized 3rd parties, entrenching users who now have no way out when that 3rd party is incompetent or corrupt.
But does it? There are non-centralized third parties you can already use. In fact besides my sketchy password manager, is it not the case that every password manager real people are already using, already support passkeys, so it’s the same power you were likely already ceding to whoever you were already ceding it to.
But in the meantime a database leak doesn’t compromise things anymore.
Unless I’m missing something? Which is highly possible.
Read the article, it’s all covered there. Open source password managers like bitwarden and keepass are ideal, but passkey support and integration with the OS is not there yet. With text passwords, you always had to fallback of copy and paste. With passkeys, OS integration is crucial.
My guess is that it may happen, or the big companies like Google or Apple can keep shifting the standards to keep the open source options outdated, like what Google already does with web standards.
I don’t know that OP is wrong per-se, but I think they’re overstated a bit.
Their statement that passkeys are better than people using the same password, but are a step back for people using a password manager, is maybe a bit much. It’s basically the same, but sometimes better.
Most of their drawbacks are the hardware implementations, but that’s already true of people using hardware 2FA, and corporate management, which is already a problem if you use Apple’s or Google’s existing baked-in password managers.
But if you don’t already have both of those problems, the standard is basically just “instead of having the password manager pretend to type in a box, what if they dumped something into the stream directly”, and that extends to what if the UI didn’t ask for anything and just said “hey, do you want to login? Just let me know and it’s done”
And, like, should you be able to export from Apple’s built in store to migrate? Absolutely, but if you never used Apple’s passkeys in the first place, because ugh gross, then it’s not a problem you need solved yet.
There is one problem I’ll admit, which is that it’s easier to make a sketchy password manager that just pretends to be a keyboard. I myself don’t actually use passkeys because I sync my passwords with git and use
pass, which is cool and I love it. And then I type them using a dmenu script and xdotool, which is silly and I love it. But that doesn’t work with passkeys which I can definitely store in git, but would require a real actual connection between my browser and the tool, in a way that I don’t think currently exists.But just because I can’t use my sketchy crap, doesn’t always mean it’s a step back 😛
The article is saying that while passkeys could theoretically be better, the current implementation is bad because it cedes power to centralized 3rd parties, entrenching users who now have no way out when that 3rd party is incompetent or corrupt.
But does it? There are non-centralized third parties you can already use. In fact besides my sketchy password manager, is it not the case that every password manager real people are already using, already support passkeys, so it’s the same power you were likely already ceding to whoever you were already ceding it to.
But in the meantime a database leak doesn’t compromise things anymore.
Unless I’m missing something? Which is highly possible.
Read the article, it’s all covered there. Open source password managers like bitwarden and keepass are ideal, but passkey support and integration with the OS is not there yet. With text passwords, you always had to fallback of copy and paste. With passkeys, OS integration is crucial.
My guess is that it may happen, or the big companies like Google or Apple can keep shifting the standards to keep the open source options outdated, like what Google already does with web standards.