Static

I don't like passkeys

First reported by Hawksley.dev ·

The signal ●○○○ Compiled by AI from Hawksley.dev and Hacker News
Why you might care

Your accounts face a higher risk of permanent lockout or ban than phishing if you rely solely on passkeys.

What happened

Ethan Hawksley, a computer science student, argues that while passkeys offer strong protection against phishing and data breaches by being bound to specific sites, they present significant risks for individual users. The primary concerns highlighted are permanent account lockout, automated account bans by platforms like Apple and Google, and the inconvenience and cost of managing hardware keys due to account limits. Hawksley points out that passkeys eliminate phishing via fake login screens but do not address the security of account recovery methods, which remain the weakest link. He suggests that for personal use, a combination of randomly generated passwords managed by a third-party password manager and a separate TOTP app offers a more balanced approach to security and user control, unlike the current limitations of passkey ecosystems.

What it means

While passkeys offer enhanced security against traditional phishing attacks and server-side breaches, their practical implementation introduces significant user-side risks. The author contends that the inability to back up passkeys to hardware keys, coupled with platform-specific syncing mechanisms tied to OS accounts (like Apple or Google), creates a substantial risk of irreversible account lockout should those primary accounts be banned or compromised. This scenario, along with the expense and scalability issues of managing numerous hardware keys due to their limited account capacity, makes passkeys a less ideal solution for individual users compared to enterprise environments.

The current passkey ecosystem is deemed immature for widespread personal adoption, with fragmentation and inconsistent user experiences across different operating systems and third-party password managers. Even with emerging APIs, seamless integration into native applications and cross-device autofill remains a challenge. The author posits that current recovery methods, often SMS or email-based, do not improve with passkeys, leaving the ultimate account security dependent on these weaker channels. He advocates for a hybrid approach using password managers and TOTP apps as a more robust and flexible alternative for individuals until the passkey ecosystem matures.

AI-written summary. May contain errors.

Tech