Passkeys were invented by engineers with zero understanding of consumer brain(twitter.com)
twitter.com
Passkeys were invented by engineers with zero understanding of consumer brain
https://twitter.com/nikitabier/status/2079787406300266743
https://xcancel.com/nikitabier/status/2079787406300266743
780 comments
I do not know how to use a Passkey in a way that won’t impede how I log in to systems. I’ve been in tech for 26 years, and I understand the Public/private key behind what a Passkey is. Here’s what I don’t understand:
I access a website through at least four different devices (my iPad, iPhone, Windows Desktop computer, and MacBook Pro) and three different browsers on each device (Brave, Firefox, Safari) , and I use LastPass. If I accidentally set up a passkey on my phone (let’s say I use Safari one day instead of my go-to, Brave), can I still log in without that passkey on other devices? Is there a way to ensure that passkey can be used on other devices? Can I add another passkey on another device? How many passkeys can I set up for a particular site/app? I have at least 6 different combination of browser/devices in use.
I don’t want to use Passkeys because I don’t the answers to those questions, and I don’t know whether each website/app that has set up Passkeys has decided the answers to those questions in the same way as the others. For now, I’m going to stick with LastPass and use Passwords; because no matter whether I lose my device or not or whether I’m on my own devices or not, I can be sure I’ll be able to get into a site/app.
Edit: One final consideration, my spouse and I share user/name passwords for some things (notably Pandora and our Amazon Prime account) since they don’t handle things like family logins well; how do both my wife and I use amazon or Pandora with passkeys? Do we each set up passkeys? How do I get her Pass if that’s not an option?
I access a website through at least four different devices (my iPad, iPhone, Windows Desktop computer, and MacBook Pro) and three different browsers on each device (Brave, Firefox, Safari) , and I use LastPass. If I accidentally set up a passkey on my phone (let’s say I use Safari one day instead of my go-to, Brave), can I still log in without that passkey on other devices? Is there a way to ensure that passkey can be used on other devices? Can I add another passkey on another device? How many passkeys can I set up for a particular site/app? I have at least 6 different combination of browser/devices in use.
I don’t want to use Passkeys because I don’t the answers to those questions, and I don’t know whether each website/app that has set up Passkeys has decided the answers to those questions in the same way as the others. For now, I’m going to stick with LastPass and use Passwords; because no matter whether I lose my device or not or whether I’m on my own devices or not, I can be sure I’ll be able to get into a site/app.
Edit: One final consideration, my spouse and I share user/name passwords for some things (notably Pandora and our Amazon Prime account) since they don’t handle things like family logins well; how do both my wife and I use amazon or Pandora with passkeys? Do we each set up passkeys? How do I get her Pass if that’s not an option?
The first time I got asked by a site if I wanted to use a passkey I immediately googled what they were and... never really found the answer, not in the 5mins I devoted to being distracting from my task at hand anyway.
"magic fairy dust to login to apps." is the most accurate description I've seen.
Unlike a password or a TOTP token, I know how those work, I know its my responsibility to keep track of them. If my passkey is on my phone what happens if I lose my phone? Do I need a unique passkey per device? How do I rotate them? What if a device gets stolen?
I'm so glad I'm not alone in thinking these are so poorly explained.
"magic fairy dust to login to apps." is the most accurate description I've seen.
Unlike a password or a TOTP token, I know how those work, I know its my responsibility to keep track of them. If my passkey is on my phone what happens if I lose my phone? Do I need a unique passkey per device? How do I rotate them? What if a device gets stolen?
I'm so glad I'm not alone in thinking these are so poorly explained.
It’s quite the opposite. Passkeys are phenomenal for a lot of consumers. Based on this thread, it’s the engineers who understand authentication in the first place and have their own system (eg password manager) that are confused.
Consider a user in the Apple ecosystem: you are already conditioned to just do Touch ID or Face ID when asked. I was on Amazon the other day, it prompted randomly for “want to set up a passkey to sign in easier”? I set it up and now I can easily sign in to Amazon on my mac or iphone with zero friction.
For the normal consumer this is not a replacement for “dig out my password manager and copy-paste/autofill my password”, it’s a replacement for “oh it’s prompting for my password again” -> proceed to type your shared password for all sites.
Consider a user in the Apple ecosystem: you are already conditioned to just do Touch ID or Face ID when asked. I was on Amazon the other day, it prompted randomly for “want to set up a passkey to sign in easier”? I set it up and now I can easily sign in to Amazon on my mac or iphone with zero friction.
For the normal consumer this is not a replacement for “dig out my password manager and copy-paste/autofill my password”, it’s a replacement for “oh it’s prompting for my password again” -> proceed to type your shared password for all sites.
Like some folks already commented here, even as someone who has been working in tech for 20+ years, I find Passkey confusing. I understand the key aspect in computer science term, but I don't know how to use it across devices. Another big worry is that if I tie that to a physical key, then I might lose it (because it's physical) and never get it back.
FWIW: I find passkeys to be a very simple and easy to use concept.
Simple: it's like a password that I don't have to type in
Easy to use: because I use 1Password and just have it installed on everything. On Android, it can be set as the default passkey provider so, even on mobile, I am using passkeys shared across devices.
Is this "less secure" because I'm sharing the keys through 1Password. I suppose, at some level. But before that, I was simply sharing passwords through 1Password in the exact same way. So, I don't think my security posture has changed any.
What has changed is the UX and IMO for the better. Now I don't have to generate/fill/copy-paste text strings for user names or passwords. 1Password knows what site I'm on and usually responds automatically when I'm in a passkey context. If I have more than one passkey available, because I have multiple accounts (for something like Google Workspace), it shows me options and I pick the one I want.
Honestly, it's mostly a "just works" system and I like it a lot better than passwords.
YMMV, of course.
Simple: it's like a password that I don't have to type in
Easy to use: because I use 1Password and just have it installed on everything. On Android, it can be set as the default passkey provider so, even on mobile, I am using passkeys shared across devices.
Is this "less secure" because I'm sharing the keys through 1Password. I suppose, at some level. But before that, I was simply sharing passwords through 1Password in the exact same way. So, I don't think my security posture has changed any.
What has changed is the UX and IMO for the better. Now I don't have to generate/fill/copy-paste text strings for user names or passwords. 1Password knows what site I'm on and usually responds automatically when I'm in a passkey context. If I have more than one passkey available, because I have multiple accounts (for something like Google Workspace), it shows me options and I pick the one I want.
Honestly, it's mostly a "just works" system and I like it a lot better than passwords.
YMMV, of course.
With physical U2F key, I could explain to my 78 year-old-parents "this is a physical key needed to access your account. Think of it like the front door key to your house. Don't lose it or lend it to anyone. We should have a couple of backup keys too." And they got completely understood and added it to all of their accounts. This was not hard. People assumed consumers were too stupid to do this without even giving them a chance.
It seems to me like those who like passkeys/consider them simple are those who entrust all their credentials to proprietary cloud software vendors that sync them to all their devices.
Those of us who are not comfortable with that and want to keep our credentials offline and sync/backup them ourselves have questions about how the registration/backup/sharing flows work exactly.
I see this as part of a trend together with remote attestation, age verification, CSAM scanning, restricting sideloading, etc that will lead to most interactions over the internet only being allowed if big tech and/or government can verify the participants, the contents, and the hardware and software used.
Even among techies, many support these developments, so it is just a matter of time before we have no choice but to join the former group.
Those of us who are not comfortable with that and want to keep our credentials offline and sync/backup them ourselves have questions about how the registration/backup/sharing flows work exactly.
I see this as part of a trend together with remote attestation, age verification, CSAM scanning, restricting sideloading, etc that will lead to most interactions over the internet only being allowed if big tech and/or government can verify the participants, the contents, and the hardware and software used.
Even among techies, many support these developments, so it is just a matter of time before we have no choice but to join the former group.
The website for my HSA required me to set up a passkey last time I logged in. I set it up on my work laptop and my work password manager, which means I can now no longer access my account from my personal computer. This is fantastic, just what I wanted
UX is not the problem with Passkeys. Passkeys were designed to align with the interests of BigTech, who are bent on stopping the abomination that is general computing devices in the hands of consumers and forcing them into their walled gardens. The language that is used for taking away freedoms is the same as always, safety. Where we ended up with Passkeys is an operating model that is suitable for corporate devices, i.e. the user can only do what the owners of the device allow them to. Suboptimal UX is downstream from that problem.
I think portability is very confusing: they rolled out passkeys with no device portability (device-bound) and only recently added it (CXP). So for anyone with multiple devices it was a relative disaster - why should my Windows PC hold a device-bound passkey to anything? How do I login on Linux or macOS?
Picking a password manager to do portability also means another kind of lockin, though maybe you can live with that kind if you really trust the company. Even so, the password managers all seem to be competing to have relaxed security, so that vault and account passwords are the same, or you are asked to type your master password into a webpage - surely we didn't replace per-site passwords with this?
I mostly love passkeys to be honest even though I use multiple browsers across multiple devices and OSes (iOS, Chromebook, Linux, macOS, Xbox, etc). Bitwarden’s support is (finally) pretty good.
My problem is that I manage a lot of accounts for my family which makes passkeys a nightmare. If I’m out and a kid gets chucked into a login flow that happens to require a passkey, I can’t text a password and TOTP code to the adult with them. I know that’s terrible opsec but the reality is people share accounts and passkeys are designed to thwart that.
My problem is that I manage a lot of accounts for my family which makes passkeys a nightmare. If I’m out and a kid gets chucked into a login flow that happens to require a passkey, I can’t text a password and TOTP code to the adult with them. I know that’s terrible opsec but the reality is people share accounts and passkeys are designed to thwart that.
Throwing my hat in the ring, I think passkeys were also invented by engineers with zero understanding of the average developer: https://etodd.io/2026/04/06/passkeys-are-too-hard/
I think about this a lot when using our corporate SSO tool.
When I hit the button to log into Slack, there are like, 3 popups in succession - the last one ultimately asking for my fingerprint. Then when I give it, there is a flurry of web pages that get loaded and redirects that happen until finally Slack pops up again.
There isn't any realistic world in which I check each window to make sure everything is happening right and I am not being MitM'd.
I'm a fairly technical person, and I would be unable to perceive the difference between a really tight security environment and my computer being hijacked.
When I hit the button to log into Slack, there are like, 3 popups in succession - the last one ultimately asking for my fingerprint. Then when I give it, there is a flurry of web pages that get loaded and redirects that happen until finally Slack pops up again.
There isn't any realistic world in which I check each window to make sure everything is happening right and I am not being MitM'd.
I'm a fairly technical person, and I would be unable to perceive the difference between a really tight security environment and my computer being hijacked.
I keep seeing people working on Passkeys get real defensive when told they don't make sense to people.
I've worked in tech 12+ years and I _hate_ when a Passkey prompt comes up, its only ever slowed me down.
But the devs who work on them are quite rabid, and keep dismissing real criticism of their implementation.
I've worked in tech 12+ years and I _hate_ when a Passkey prompt comes up, its only ever slowed me down.
But the devs who work on them are quite rabid, and keep dismissing real criticism of their implementation.
> I run a tech company and I have no idea what a passkey is and at this point I’m too afraid to ask
I thought I was the only one!
I thought I was the only one!
Passkeys are just SSH keys in how they work. We've been doing this since the 90's. The only people that use SSH keys are the Linux savvy users and those who are forced to via an enterprise solution for vaulting.
The average person doesn't know anything about this stuff nor do they care. I also have yet to see a Passkey solution that didn't also have a password on it and a nice little box letting people choose to use the password instead of the passkey. They just added a new layer on top of all the old ones and created confusion. Now people use password and passkey interchangably in conversations and no one knows what they are talking about.
The average person doesn't know anything about this stuff nor do they care. I also have yet to see a Passkey solution that didn't also have a password on it and a nice little box letting people choose to use the password instead of the passkey. They just added a new layer on top of all the old ones and created confusion. Now people use password and passkey interchangably in conversations and no one knows what they are talking about.
Yes, a bit of a mess. As the only practical way for most to use is with a password manager. So essentially, all your accounts still have a real password, just you enter that into your password manager app. So if your device is every compromised and someone has your master password then you are screwed.
And of course, passkeys on most all sites don't really improve security since someone can just choose to login with user/pass instead since presumably very few sites allow you to have just passkey.
Also if you use a password manager you may get locked into using that platform. Or ideally using a third party one but then having to pay a subscription, or using an open source option that is not ideal for the average person.
If one uses a passkey as intended and without a password manager and the site truly only supports logging in via your passkey, for all the touted benefits of passkeys, that would be a nightmare if a person loses access to their device, etc.
And of course, passkeys on most all sites don't really improve security since someone can just choose to login with user/pass instead since presumably very few sites allow you to have just passkey.
Also if you use a password manager you may get locked into using that platform. Or ideally using a third party one but then having to pay a subscription, or using an open source option that is not ideal for the average person.
If one uses a passkey as intended and without a password manager and the site truly only supports logging in via your passkey, for all the touted benefits of passkeys, that would be a nightmare if a person loses access to their device, etc.
I signed into my Playstation account on a new phone. It told me to make a passkey. Its safe. So i said ok.
Later I tried to sign into my Playstation account on my computer and I couldn't. It said I needed to use my passkey.
I went back on my phone and deleted my passkey.
FWIW, Nintendo seems to have nailed the concept of passkey. I can sign in anywhere. If I'm on a new device, i just use my email password and 2FA.
I dont know why so many vendors find the need to complicate this. A secure solution implemented poorly can potentially be worse than an insecure solution.
One more anecdote on that front — I worked the help desk at a medical school during college. The IT department had their fun password requirements (number, special character, blood of a virgin, change every month, etc). Every single person who came to the help desk had their password written down on a sticky note on their laptops. These were med students , doctors, staff... everyone.
At some point these admins have to ask themselves whether they're actually helping people be more secure or if you're just making them jump through hoops.
Later I tried to sign into my Playstation account on my computer and I couldn't. It said I needed to use my passkey.
I went back on my phone and deleted my passkey.
FWIW, Nintendo seems to have nailed the concept of passkey. I can sign in anywhere. If I'm on a new device, i just use my email password and 2FA.
I dont know why so many vendors find the need to complicate this. A secure solution implemented poorly can potentially be worse than an insecure solution.
One more anecdote on that front — I worked the help desk at a medical school during college. The IT department had their fun password requirements (number, special character, blood of a virgin, change every month, etc). Every single person who came to the help desk had their password written down on a sticky note on their laptops. These were med students , doctors, staff... everyone.
At some point these admins have to ask themselves whether they're actually helping people be more secure or if you're just making them jump through hoops.
Passkeys are a nightmare for techies that want to understand and manage their stuff. They were optimized for people who neither can nor want to understand, they just press the button that the screen tells them to press and live inside someone's closed ecosystem.
For that use case, they work fine, and they create enormous lock-in, because now moving out of that ecosystem breaks everything. One might argue that that means they're perfectly engineered for what they are meant to do...
For that use case, they work fine, and they create enormous lock-in, because now moving out of that ecosystem breaks everything. One might argue that that means they're perfectly engineered for what they are meant to do...
My take: (1) I've had passwords handled pretty well for a long time now: same password manager for something like 15 years; (2) companies are pushing pretty hard to get me to use passkeys instead.
From (2) I assume that the companies see benefits to themselves. I don't care about benefits to them. I don't see much in the way of benefits to me, so I'm not changing anything if I don't have to.
I'll admit to not having looked into passkeys all that much. Someday, I might. But for the time being, I don't see much point. I imagine that eventually I'll be more or less forced to deal with passkeys in at least some contexts. Will leave that for later.
For now, it's all a big "no thanks" from me.
From (2) I assume that the companies see benefits to themselves. I don't care about benefits to them. I don't see much in the way of benefits to me, so I'm not changing anything if I don't have to.
I'll admit to not having looked into passkeys all that much. Someday, I might. But for the time being, I don't see much point. I imagine that eventually I'll be more or less forced to deal with passkeys in at least some contexts. Will leave that for later.
For now, it's all a big "no thanks" from me.
I use Apple based passkeys to log into everything I can now. I have given it virtually no thought since all my relevant accounts and rolled out support. My non-technical close friends and family (consumer brains) have also done the same. I imagine it is a different case for non-Apple device users, but in the Apple case, passkeys are zero friction and truly life-enhancing for anyone who logs into things
I find it difficult to explain how to use password manager to non-IT person. Whatever I say, they say it is not secure. No amount of explanation will change their mind. They prefer to keep their passwords in their physical note book hidden in the safe (yes, they open the safe etc each time they need to log in somewhere when they get logged out).
As someone with ADHD a passkey is something I can lose easily and I don't want my accounts to be tied to any specific device. What if I have to upgrade my laptop tomorrow because one I use got bricked? Sounds like an absolute nightmare.
Password on the other hand I can remember for dozens of services, each very long.
As someone with ADHD a passkey is something I can lose easily and I don't want my accounts to be tied to any specific device. What if I have to upgrade my laptop tomorrow because one I use got bricked? Sounds like an absolute nightmare.
Password on the other hand I can remember for dozens of services, each very long.
Passkeys are a vector for locking your logins to Big Tech ecosystems. They support device attestation, which means the service you are logging in to can require you to only use certain Passkey clients such as those provided by Google, Apple or Microsoft. The Passkey spec authors also maintain a list of "naughty clients"[1], which are clients that allow the user to manage their own data how they want. Services could choose to block those clients for "security reasons," justifying the decision to force you to use one of the Big Tech providers.
Until device attestation is removed or strongly curtailed in the spec, I suggest you do not create any Passkeys. Which sucks, because it's otherwise a pretty cool tech.
[1] https://passkeys.dev/docs/reference/known-issues/
More sources here: https://www.smokingonabike.com/2025/01/04/passkey-marketing-...
Until device attestation is removed or strongly curtailed in the spec, I suggest you do not create any Passkeys. Which sucks, because it's otherwise a pretty cool tech.
[1] https://passkeys.dev/docs/reference/known-issues/
More sources here: https://www.smokingonabike.com/2025/01/04/passkey-marketing-...
Passkeys are a political play aimed at bolstering government support. They’re the privacy sabotaging arm of Digital ID. They go hand in hand with “age” verification. It’s all the same play. Get your identity, get your access credentials, give it to the prying eyes.
This comment section is the best example of all time of the arrogance of Big Tech and its employees. Please try to take a second thinking outside of your bubble before commenting ridiculous stuff.
Yes, as a wealthy American, you "live in the Apple ecosystem". 99% of the world doesn't. And guess what, they're affected by passkeys all the same. They use a Windows laptop, and either an Android phone or iPhone. A lot of people even have an Android phone and an iPad. And no laptop at all. But at work or school they have to use Windows.
It's quite simple. Besides people "living in a single ecosystem" (discussed above, this is almost nobody), passkeys are only viable (i.e. not very painful to use) if you use a dedicated cross-platform password manager. Yet people who use those - which too is a globally negligible percentage - are exactly the people who tend to have near nothing to gain from passkeys, and only to lose. The majority of them is tech-savvy and they use auto-generated unique passwords. In that scenario, the minuscule improvement in security is meaningless and not worth it.
Ironically, this comment section shows exactly why passkeys are a shit show. Half the people here are exactly those who are coming up with this shit in their FAANG jobs, happily part of the global 1% (of which their tech-illiterate grandma too is part of), and they have no idea or care in the world for the remaining 99%. Unless of course this was simply a land grab for lock-in, which is about as likely.
Yes, as a wealthy American, you "live in the Apple ecosystem". 99% of the world doesn't. And guess what, they're affected by passkeys all the same. They use a Windows laptop, and either an Android phone or iPhone. A lot of people even have an Android phone and an iPad. And no laptop at all. But at work or school they have to use Windows.
It's quite simple. Besides people "living in a single ecosystem" (discussed above, this is almost nobody), passkeys are only viable (i.e. not very painful to use) if you use a dedicated cross-platform password manager. Yet people who use those - which too is a globally negligible percentage - are exactly the people who tend to have near nothing to gain from passkeys, and only to lose. The majority of them is tech-savvy and they use auto-generated unique passwords. In that scenario, the minuscule improvement in security is meaningless and not worth it.
Ironically, this comment section shows exactly why passkeys are a shit show. Half the people here are exactly those who are coming up with this shit in their FAANG jobs, happily part of the global 1% (of which their tech-illiterate grandma too is part of), and they have no idea or care in the world for the remaining 99%. Unless of course this was simply a land grab for lock-in, which is about as likely.
I really don't get passkeys and how they are supposed to be safer.
Currently I save all login tuples to Bitwarden and store OTP secrets onto Aegis. Could have been 1password and authy, it's irrelevant. The thing is, I only get pwned if both are compromised.
Now with ubiquitous passkeys in Bitwarden if someone has access to my vault unencrypted it's already endgame.
Currently I save all login tuples to Bitwarden and store OTP secrets onto Aegis. Could have been 1password and authy, it's irrelevant. The thing is, I only get pwned if both are compromised.
Now with ubiquitous passkeys in Bitwarden if someone has access to my vault unencrypted it's already endgame.
Okay, I'm a tech nerd I admit it, but for my personal authentication life I find passkeys to make sense.
All my passwords and SSH key are already in Bitwarden. When a site starts supporting passkeys, I add that to Bitwarden as well. Now, instead of logging in by auto-filling my username and password, I just press the passkey login button (that hopefully exists) and click on the Bitwarden popup to select the account. It's less button presses for me, and I cannot be phished, nor can my passkeys be leaked on the dark web. All thanks to some fancy cryptography.
Okay, sure, if someone steals my Bitwarden vault by snatching my laptop while it's unlocked or something, I end up pretty screwed. That security aspect did not change, so I still use TOTP for all important services.
Also, I've made one invite-only web app where single-use invite codes and passkeys are the only ways to log in. It was not too hard, it was fun, actually. And I get the peace of mind that account sharing is pretty much impossible were a bad actor able to get their hands on an invite, as is hacking other people's accounts.
(Okay, I concede that I've had to help multiple people who find passkeys confusing as a result of this whimsical decision, and that it just might be that nobody is using my web app for real. So I'm just speaking from nerd privilege here... But it works well, trust me!!)
All my passwords and SSH key are already in Bitwarden. When a site starts supporting passkeys, I add that to Bitwarden as well. Now, instead of logging in by auto-filling my username and password, I just press the passkey login button (that hopefully exists) and click on the Bitwarden popup to select the account. It's less button presses for me, and I cannot be phished, nor can my passkeys be leaked on the dark web. All thanks to some fancy cryptography.
Okay, sure, if someone steals my Bitwarden vault by snatching my laptop while it's unlocked or something, I end up pretty screwed. That security aspect did not change, so I still use TOTP for all important services.
Also, I've made one invite-only web app where single-use invite codes and passkeys are the only ways to log in. It was not too hard, it was fun, actually. And I get the peace of mind that account sharing is pretty much impossible were a bad actor able to get their hands on an invite, as is hacking other people's accounts.
(Okay, I concede that I've had to help multiple people who find passkeys confusing as a result of this whimsical decision, and that it just might be that nobody is using my web app for real. So I'm just speaking from nerd privilege here... But it works well, trust me!!)
My biggest issues with Passkeys is how inconsistently they are implemented and how opaque they attempt to be.
I understand SSH keys, I've been using them for decades, I know where they live, I know how to secure them.
Passkeys are murky as fuck. Is your PW manager supported? Do they sync? Where are they stored? How can I move to another PW manager if I want to in the future? Can I have more than 1 passkey per site? And the list goes on.
I _know_ some of you out there can answer some/all of the questions above but it's mostly on a per-site basis. Passkeys take too much of the control out of my hands and I don't like that.
Even more than that, I hate how they are trying to be pushed on me at every turn. Login -> Want to save a passkey (but they never call it that, they use some other confusing euphemism)? I click "No" and then it proceeds to pop 1Password's UI, then I dismiss that and it opens Chrome's passkey save UI, I dismiss that, and then it opens the OS's passkey UI. It's incredibly disrespectful and unclear.
I never use anything but 1Password but somehow everyone (OS and Browser) try to reach their grubby hands in. This is what scares me, I don't like having to be on high-alert to not accidentally save a passkey in Chrome or Safari and not realize until I'm on a different device and notice it's not in 1Password.
Lastly I trust the developers implementing passkeys... none, I trust them none, zero, zilch. I don't trust them to pick the right defaults, I don't trust their recovery options, and I know they will always pick the configuration that benefits them and not me.
No, for now I'll stick with my as-long-as-you-let-me-make-my-password random passwords which I never copy/paste into random website and be perfectly safe, thank you.
I understand SSH keys, I've been using them for decades, I know where they live, I know how to secure them.
Passkeys are murky as fuck. Is your PW manager supported? Do they sync? Where are they stored? How can I move to another PW manager if I want to in the future? Can I have more than 1 passkey per site? And the list goes on.
I _know_ some of you out there can answer some/all of the questions above but it's mostly on a per-site basis. Passkeys take too much of the control out of my hands and I don't like that.
Even more than that, I hate how they are trying to be pushed on me at every turn. Login -> Want to save a passkey (but they never call it that, they use some other confusing euphemism)? I click "No" and then it proceeds to pop 1Password's UI, then I dismiss that and it opens Chrome's passkey save UI, I dismiss that, and then it opens the OS's passkey UI. It's incredibly disrespectful and unclear.
I never use anything but 1Password but somehow everyone (OS and Browser) try to reach their grubby hands in. This is what scares me, I don't like having to be on high-alert to not accidentally save a passkey in Chrome or Safari and not realize until I'm on a different device and notice it's not in 1Password.
Lastly I trust the developers implementing passkeys... none, I trust them none, zero, zilch. I don't trust them to pick the right defaults, I don't trust their recovery options, and I know they will always pick the configuration that benefits them and not me.
No, for now I'll stick with my as-long-as-you-let-me-make-my-password random passwords which I never copy/paste into random website and be perfectly safe, thank you.
Passkeys bother me because they depend on the availability of another device. That just won't cut it for a lot of folks, especially people that are prone to losing devices. It's also annoying to have to deal with the 50,000 places that are fighting to keep your passkeys, leading to fragmentation and uncertainty as to where these credentials are stored.
Haphazardly implementing passkeys also has big problems - one vendor I use implemented them rather badly and randomly one day, completely removing the previously-solid password/MFA setup they had, replacing it with a "you are required to confirm on your phone with no other alternative" passkey, which was really annoying. I don't like my logins messed with. Passwords/MFA, while not perfect, work very well for most people, myself included. Passkeys still feel like they are in a very immature state.
Haphazardly implementing passkeys also has big problems - one vendor I use implemented them rather badly and randomly one day, completely removing the previously-solid password/MFA setup they had, replacing it with a "you are required to confirm on your phone with no other alternative" passkey, which was really annoying. I don't like my logins messed with. Passwords/MFA, while not perfect, work very well for most people, myself included. Passkeys still feel like they are in a very immature state.
I think the problem was that there wasn't a "Best Practices" way of using them when they were launched, which really prevented describing them in a consumer-friendly way.
And web site implementors couldn't follow that golden path, or describe the golden path, so there's fragmentation in usage and meanings and practices, making it far more confusing.
I love passkeys, I want to eliminate any and all password-based logins and switch entirely to passkeys. It's such a better experience, it's a "physical" key that can be backed up to multiple devices, and thinking of it like a key for a physical lock really gets at the core of its capabilities. But locks can be used in many many ways! Maybe you need to open the lock and still tell the guard a password, which is weird, but how most websites still operate.
And web site implementors couldn't follow that golden path, or describe the golden path, so there's fragmentation in usage and meanings and practices, making it far more confusing.
I love passkeys, I want to eliminate any and all password-based logins and switch entirely to passkeys. It's such a better experience, it's a "physical" key that can be backed up to multiple devices, and thinking of it like a key for a physical lock really gets at the core of its capabilities. But locks can be used in many many ways! Maybe you need to open the lock and still tell the guard a password, which is weird, but how most websites still operate.