this post was submitted on 26 Sep 2026
389 points (94.9% liked)

Technology

88272 readers
3109 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] muzzle@lemmy.zip 37 points 1 day ago (2 children)

For users who previously reused passwords across all their sites, passkeys are a huge step-up.

That is exactly why passkeys are a good thing. Basically everyone reused passwords everywhere.

[–] qevlarr@lemmy.world 59 points 1 day ago (3 children)

A password manager is better than passkeys in 2026

[–] arrowMace@lemmy.world 1 points 11 hours ago (1 children)

It's a false dichotomy to have one or the other. I use passkeys as a quicker and more convenient way to log in to some sites, but I still have passwords in my password manager as a fallback.

[–] Scrollone@feddit.it 2 points 11 hours ago (1 children)

Some websites prevent you from using a password if you set up a passkey.

Pass keys are horrible.

[–] Flagstaff@programming.dev 3 points 10 hours ago

It seems like what's actually horrible would be those websites' implementation. But yeah, I'm definitely sticking with a manager.

[–] Glitchvid@lemmy.world 3 points 20 hours ago (1 children)

Really depends on what you mean by passkey, since it's actually a fairly vague term for a bundle of technologies.

I don't really care for password manager passkeys; just use a password, all it really does is save you from needing to enter a username in a login flow.

But I'm a big fan of hardware 2fa using non-resident keys ("passkey" lite); I'll use a regular login flow with a password manager, then the 2FA step with a hardware token. Basically bulletproof (ditto if you secure your PW manager with hw 2fa) and painless.

[–] Natanael@infosec.pub 2 points 11 hours ago

Even pw synced passkeys at least have the benefits of both being phishing resisting + replay protected, as well as being able to use the TPM chip for extra local protection.

Hardware keys are logically simpler though

[–] Natanael@infosec.pub 11 points 1 day ago (1 children)

Some password managers can sync passkeys for you! Bitwarden can handle it

[–] Redjard@reddthat.com 4 points 21 hours ago (1 children)

android doesn't allow 3rd party apps to use passkeys nor autofill 2fa consistently. For passkeys, you are forced to use google services for it, or loose access, making it pointless. TOTP codes meanwhile can at least be copied and pasted manually from a password manager.

[–] Natanael@infosec.pub 1 points 11 hours ago* (last edited 11 hours ago) (1 children)

https://developer.android.com/identity/passkeys/manage-passkeys

Actually not, 3rd party Android apps can act as passkeys providers

With Bitwarden you can even do your own self hosted sync of passkeys

https://bitwarden.com/blog/bitwarden-passkeys-mobile/

Any app where it doesn't work has chosen to not use the right API

[–] Redjard@reddthat.com 2 points 8 hours ago (1 children)

It's android version dependent. Only 14 and up support 3rd party providers.

Passkeys are supported on devices that run Android 9 (API level 28) or higher.

On many devices, Credential Manager stores passkeys to Google Password Manager by default. Users can choose other password managers as its passkey providers in the System Settings on Android 14 or higher.

Given the slowness of android version rollouts, this will be an issue for a long time.

I also think supporting older androids is pushing apps to do it the "wrong" way and making it google specific.

[–] Zak@lemmy.world 1 points 5 hours ago

14 and up seems to be about 80% of users, and I suspect there's a correlation between people who want to use passkeys with a third party password manager and being within two major versions of current.

[–] Cort@lemmy.world 14 points 1 day ago (5 children)

Maybe 5 or 10 years ago, but who doesn't use a password manager these days? They generate random passwords and remember them for you

[–] Bluescluestoothpaste@sh.itjust.works 1 points 13 hours ago (1 children)

I just remember my passwords idk lol. I never understood the logic of a password manager, someone hacks your manager they have everything in your life? Rather just run the risk of getting hacked one account at a time rather than they all get hacked at once when they get my password manager.

[–] Flagstaff@programming.dev 2 points 10 hours ago* (last edited 10 hours ago)

So make the manager's password massive. There, that complete sentence just now is over 30 characters long and could literally be a password. You can double up security with a secret file that you must locate on your PC, in KeePass, at least. You can also add notes about entries, track more than just website accounts, etc. It's just too much brainpower to remember individual websites' passwords. All important ones have 2FA anyway.

Managers are local to your computer so you likely messed up big-time if it got hacked, whereas websites can get hacked entirely out of our control.

[–] muzzle@lemmy.zip 30 points 1 day ago (1 children)

Do you know any non tech people, especially over 40? Literally none of them uses a password manager.

[–] Cort@lemmy.world 3 points 1 day ago (1 children)

Most of the non-techy people I know use the password manager built into their Web browser at the very least.

[–] WhyJiffie@sh.itjust.works 3 points 14 hours ago

"use" I bet it just saves everything automatically, and they don't even know their passwords are there. just "oh look, my password has appeared, lets click it!"

[–] nullroot@lemmy.world 17 points 1 day ago (1 children)
[–] Cort@lemmy.world 5 points 1 day ago (1 children)

Huh I thought it was going to be the correcthorsebatterystaple comic

[–] nullroot@lemmy.world 4 points 1 day ago

In my experience you're more likely to find a sticky note on the desk with passwords than someone using a password manager, 2fa, or an ounce of 'common' sense.

[–] GreyEyedGhost@piefed.ca 3 points 1 day ago

My current employer will not authorize the use of a password manager. I have a key fob for my Microsoft account, and another account does phone verification. I use one password. If they don't want to put the effort in for account security then neither do I. I use a password manager for nearly all my other accounts.

[–] laranis@lemmy.zip 5 points 1 day ago

So we should be using passkeys to access our password managers that generate random passwords and remember them for us! Ultimate protection.