news.volyx.in

Passkeys were invented by engineers with zero understanding of consumer brain (twitter.com)

577 points by ksec · 36 days ago · 780 comments on HN

Article summary

The article discusses the concept of passkeys, a new form of security that uses a fingerprint or face recognition to log in to apps, and how it was invented by security engineers with little understanding of consumer behavior. The author argues that passkeys are confusing and may not be as secure as they seem. Many people are unsure about how to use passkeys and are concerned about losing access to their accounts. The article highlights the need for a better understanding of passkeys and their implications.

Main themes

  • Passkey security
  • Consumer understanding
  • Biometric authentication
  • Password management
  • Device compatibility

What commenters say

  • Passkeys are essentially the same as SSH keys, but with added restrictions on management and portability.
  • The push for passkeys may be driven by sinister motives, such as tracking user behavior across multiple sites.
  • Passkeys can be confusing and may not be suitable for users who access accounts from multiple devices and browsers.
  • The setup and enrollment process for passkeys is often cumbersome and unclear, leading to frustration and mistrust.
  • Some argue that passkeys are a more secure form of authentication, while others believe they are not as secure as they seem due to potential vulnerabilities.
  • The use of passkeys may be paternalistic, limiting user freedom and autonomy in managing their own security.
  • Passkeys may not be as effective in preventing phishing attacks as claimed, and may even introduce new security risks.