this post was submitted on 26 Sep 2026
389 points (94.9% liked)
Technology
88272 readers
3109 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
There is still nothing better than passwords.
I don't want my access to be tied to a specific device. Devices get lost, or break.
I don't want someone to be able to use my face or finger or eyeball to access my data. You can legally be compelled to unlock a device with your biometric security.
So current biometric security sucks. And passkeys suck.
Also, though...passwords suck for all the reasons that we all already know.
There has to be some better method that the owner can have full agency over, I just don't know what. I don't have the answers.
Hardware security keys is the other option. The FIDO2 ones are compatible with most sites using passkeys.
This pretty much matches my feeling for the last 20 years or so. Passwords suck and are outdated technology. But every single alternative that has been developed over the years has sucked more, not less. They all have single-point-of-failure, vendor lock-in, assumptions about your “device”, etc.
There's a fantastic paper from a while ago that did a great job of covering what you're getting at. It's one of the most cited papers in password security research. Basically, everything we've ever found sucks but passwords seem to suck the least. Great read if you have the time - https://www.cl.cam.ac.uk/techreports/UCAM-CL-TR-817.pdf
That is a damn nice paper, thanks for sharing that! The comparison table is, if a little wacky-looking at first glance, a pretty great overview. I skimmed it for the abstract and conclusion but now I think it's worth reading it in full.
Every attempt at using passkeys has been a step into murkier, less easily understood, less convenient security.
Passkeys may be a "step up" from password + TFA in terms of usability, but there's such a variety of implementations and explanations of how those implementations "keep me secure" - I feel like any idiot who grabs my phone when I'm not looking and can follow my unlock finger smudges on the screen can use my pass keys... No thanks.