We’re building an interactive resource to demystify passkeys for both the general public and more technical users.
We’re aggregating questions to ensure our FAQ and interactive guides cover "how do I use this?" type questions from non-technical users as well as the real-world edge cases that more technical people care about.
Some prompts:
• What questions do you get from friends and family?
• What are the biggest hurdles you've faced when using them?
• What are your technical "how does this actually work"-type questions?
We’d love your input. Any and all feedback is welcome!
> The essay has a condescending attitude towards the normie computer user who can't possibly be expected to know, but it's precisely the normie computer user who would never get the stupid idea of "cleaning up" their passkeys in the first place -- that's something only a nerd with a neurotic attitude to their computer would do.
Thanks for the feedback. That certainly wasn't the intention. It was more about the average user not remembering specific details about their passkeys. Which I do stand by. If you have some suggested text to help clarify that, happy to update the post.
You can use any credential manager you choose. It is an open ecosystem. If you don't want to use a cloud service, don't. You can self-host many credential managers. There are also many solutions that just use a local database.
I'm the guy you're talking about. Always easy to crap on people when you selectively quote what they said. The core pieces you left out are:
> I don't quite understand why requiring file protection/encryption can't be a temporary minimum bar here.
> or at a minimum require file protection/encryption.
If you think helping users to be safe online (which includes putting basic safeguards in place, like not leaving hundreds of unencrypted private keys on someone's desktop or downloads folder in plain text) isn't an important part of designing solutions for global scale, then we think about things very differently.
Not really. The attestation model defined for workforce (enterprise) credential managers/authenticators doesn't really work in practice for consumer credential managers.
A passkey is a discoverable credential (aka resident key) in spec terminology. But the type of credential has no relationship to attestation (which is not used in the consumer passkey ecosystem).
Not sure how stating that my (an individual) opinions on a topic are evolving is interpreted as "threatened the KeypassXC developers".
If you've been following along, you'll have seen that I am actually one of the biggest advocates of the open passkey ecosystem, and have been working really hard to make sure all credential managers have a level playing field.
Always happy to chat directly if you have concerns!
This is one of the core use cases for why FIDO Cross-Device Authentication was created. To be able to use a passkey to sign in on a shared device, a device you don't control, or a device where you just need temporary access to something.
Not exactly. For example, the default credential manager on Android is Google Password Manager, which works on Windows, macOS, iOS, and Ubuntu. There are also dozens of other third party choices.
https://forms.gle/wmaydkzmUp2eKfJG7
Original post: https://news.ycombinator.com/item?id=47852849