Why passkeys are a step back for personal security: examining account lockout risks, platform lock-in, hardware key limits, and fragile recovery flows.
The article is saying that while passkeys could theoretically be better, the current implementation is bad because it cedes power to centralized 3rd parties, entrenching users who now have no way out when that 3rd party is incompetent or corrupt.
But does it? There are non-centralized third parties you can already use. In fact besides my sketchy password manager, is it not the case that every password manager real people are already using, already support passkeys, so it’s the same power you were likely already ceding to whoever you were already ceding it to.
But in the meantime a database leak doesn’t compromise things anymore.
Unless I’m missing something? Which is highly possible.
Read the article, it’s all covered there. Open source password managers like bitwarden and keepass are ideal, but passkey support and integration with the OS is not there yet. With text passwords, you always had to fallback of copy and paste. With passkeys, OS integration is crucial.
My guess is that it may happen, or the big companies like Google or Apple can keep shifting the standards to keep the open source options outdated, like what Google already does with web standards.
The article is saying that while passkeys could theoretically be better, the current implementation is bad because it cedes power to centralized 3rd parties, entrenching users who now have no way out when that 3rd party is incompetent or corrupt.
But does it? There are non-centralized third parties you can already use. In fact besides my sketchy password manager, is it not the case that every password manager real people are already using, already support passkeys, so it’s the same power you were likely already ceding to whoever you were already ceding it to.
But in the meantime a database leak doesn’t compromise things anymore.
Unless I’m missing something? Which is highly possible.
Read the article, it’s all covered there. Open source password managers like bitwarden and keepass are ideal, but passkey support and integration with the OS is not there yet. With text passwords, you always had to fallback of copy and paste. With passkeys, OS integration is crucial.
My guess is that it may happen, or the big companies like Google or Apple can keep shifting the standards to keep the open source options outdated, like what Google already does with web standards.
I did read the article, but I guess “remains especially inconsistent” sounded less dire than perhaps the reality is.