14 pointsby speckx2 hours ago7 comments
  • rf15an hour ago
    In my experience, for most basic services, Passkeys are absolute overkill: Your ability to recover your account without too much hassle usually beats having a key explicitely tied to physical hardware (even worse, your phone that you carry around in public). Besides, passkeys are also often used by companies like Microsoft to peddle their apps, because of course you have to have specific apps for it.

    Makes me all feel like passkeys are largely a convenient security excuse for vendor lock-in and siphoning personal information. OTP-Generators seem to be more generally applicable and less phone or company-bound.

    • bombcaran hour ago
      Passkeys “done right” via Apple Keychain however it does it seems to work well enough for the normies.

      Being able to sign in with touchID is amazing

    • robgoughan hour ago
      On the other hand, all the little services I'm building for myself are passwordless and use passkeys with emailed codes for setup/reset.

      Passwords were a really poor solution to the problem of security, they didn't take the human factor into account. After a rocky start, I'm now finding passkeys super easy and convenient to use. Far more convenient than OTP codes.

      I appreciate that if you're OS/browser doesn't integrate nicely with passwords you might be in for a bad time. I'm having a great time with 1Password, though I believe native apple handles them nicely now too – and I suspect this is true of any modern password manager (even the ones built into the browser).

  • VCFundedGenYeran hour ago
    Passkeys are a solid idea in theory - in practice they are a confusing mess. Basic users are incredibly confused by them. My recommendation still continues to be a very strong password + app based MFA.
  • treetalkeran hour ago
    I sometimes consider the number of man-hours wasted every year by companies (such as Amazon and Dropbox) that repeatedly offer to convert passwords to passkeys, despite having already been declined (once, or even dozens or hundreds of times).
    • rf152 minutes ago
      This reminds me of the number of man-hours wasted on logging in into Microsoft accounts - bonus points for "No, this app only" being hit after the session timeout of the login session so you have to log in _again_. (instead of being able to make that decision any time you like, because, you know, you've already authenticated yourself)
  • tomjen3an hour ago
    For a company this may be a good idea, but for consumers this is a nightmare. It will be so easy to get locked out of your account.
  • mrbluecoatan hour ago
    wordy ad
  • DylanMerigaud2 hours ago
    Good point.
  • joekrill40 minutes ago
    [dead]