this post was submitted on 26 Sep 2026
389 points (94.9% liked)

Technology

88253 readers
3140 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
(page 2) 50 comments
sorted by: hot top controversial new old
[–] DJKJuicy@sh.itjust.works 28 points 1 day ago (5 children)

There is still nothing better than passwords.

I don't want my access to be tied to a specific device. Devices get lost, or break.

I don't want someone to be able to use my face or finger or eyeball to access my data. You can legally be compelled to unlock a device with your biometric security.

So current biometric security sucks. And passkeys suck.

Also, though...passwords suck for all the reasons that we all already know.

There has to be some better method that the owner can have full agency over, I just don't know what. I don't have the answers.

[–] MangoCats@feddit.it 12 points 1 day ago

Every attempt at using passkeys has been a step into murkier, less easily understood, less convenient security.

Passkeys may be a "step up" from password + TFA in terms of usability, but there's such a variety of implementations and explanations of how those implementations "keep me secure" - I feel like any idiot who grabs my phone when I'm not looking and can follow my unlock finger smudges on the screen can use my pass keys... No thanks.

load more comments (4 replies)
[–] audaxdreik@pawb.social 146 points 1 day ago (1 children)

This article does a great job of articulating a lot of the uncomfortableness I have around passkeys. I've always said they make a lot more sense in an corporate environment but the level of control you lose in a personal setting is not commensurate with the protections and possible lock-in they offer.

I just don't like passkeys. They are an overly technical solution to what is mostly a human problem.

[–] fushuan@lemmy.blahaj.zone 44 points 1 day ago (2 children)

Idk, when I want to log into my personal GitHub a bitwarden window opens from the extension, I click the GitHub profile I wanna sign in, and I do.

It's a great implementation since it's not linked to a physical device and it lets me authenticate in place. It's still MFA, it's just more comfy.

[–] anguo@piefed.ca 56 points 1 day ago (8 children)

It's not MFA if all you need is your bitwarden password.

[–] surfrock66@lemmy.world 23 points 1 day ago (1 children)

Unless your bitwarden has MFA and locks after an amount of time commensurate with your security needs

[–] plateee@piefed.social 10 points 1 day ago (3 children)

True, but how does GitHub know your bitwarden has MFA? It only knows something has a valid credential.

[–] Natanael@infosec.pub 8 points 1 day ago

Github doesn't need to know how you implement it, just that your browser is handling it (and in this case the browser lets Bitwarden handle it lol)

load more comments (2 replies)
load more comments (7 replies)
[–] voyagertest@retrofed.com 9 points 1 day ago (1 children)

This would be great if it worked consistently.

In reality, extensions work in some browsers but not others, on some websites but not others, and with passwords at least you can fall back to copying and pasting, or even typing, if auto-fill isn't working in the context for whatever reason. With a passkey not only are you SOL, but it will delay your ability to move onto the password option if there is one.

The devils in the (implementation) details.

load more comments (1 replies)
[–] muzzle@lemmy.zip 37 points 1 day ago (12 children)

For users who previously reused passwords across all their sites, passkeys are a huge step-up.

That is exactly why passkeys are a good thing. Basically everyone reused passwords everywhere.

[–] Cort@lemmy.world 14 points 1 day ago (6 children)

Maybe 5 or 10 years ago, but who doesn't use a password manager these days? They generate random passwords and remember them for you

[–] muzzle@lemmy.zip 30 points 1 day ago (2 children)

Do you know any non tech people, especially over 40? Literally none of them uses a password manager.

load more comments (2 replies)
[–] nullroot@lemmy.world 17 points 1 day ago (1 children)
[–] Cort@lemmy.world 5 points 1 day ago (1 children)

Huh I thought it was going to be the correcthorsebatterystaple comic

[–] nullroot@lemmy.world 4 points 1 day ago

In my experience you're more likely to find a sticky note on the desk with passwords than someone using a password manager, 2fa, or an ounce of 'common' sense.

load more comments (4 replies)
load more comments (11 replies)
[–] hummingbird@lemmy.world 89 points 1 day ago (1 children)

Sadly did not dig into the whole "the other side decides which device you are allowed to use" topic, a feature inherently build into passkeys.

[–] Schal330@lemmy.world 16 points 1 day ago (1 children)

I think that is only an issue based on what Passkey attestation is configured by the relying party? From what I have read a lot of public facing companies implementing it will have passkey attestation statements configured as None, which typically means there isn't an authenticator certificate verification.

[–] Natanael@infosec.pub 5 points 1 day ago

Only companies issuing their own passkeys on company hardware has a reason to enable attestation (forcing use of company approved devices throughout). Any public facing service has no reason to use attestation.

[–] warm@kbin.earth 63 points 1 day ago (10 children)

I think their biggest weakness is the vendor lock in. Using a 3rd party password manager is the best solution for most people, so they arent locked to their phone. But they are right in saying none of it is quite ready.

I think the article is forgetting, they are password replacements, not account recovery replacements. Realistically, people are just as likely to forget a password, and account recovery proceedures still have to be in place. I dont see the issue there.

Passkeys are good they are just being pushed before properly fully developed, but we are slowly getting there.

load more comments (10 replies)
[–] Lutra@lemmy.world 17 points 1 day ago (1 children)

The trap: Putting any 3rd party between you and your access.
It's a 3 card monte game, but with security.

Roleplay: Mr. Jonsith did you know your house is vulnerable? Your simple little key can be used by anyone to get in to your house. Security!? Our Keypass system will super secure your house. You give us your key, and when you want access, you come to one of our 5 in town locations, request access from us by showing us this new key here, and we will let you into your house.

[–] adarza@lemmy.ca 7 points 1 day ago

next year: "In order to lower our costs and keep your monthly rate low, the five locations near you are being consolidated into a single location in Farawayville."

another year later: "In order to lower our costs and keep your monthly rate low, our physical locations are being migrated to an online presence accessible through the HahaTrickedYou app, now available in your app store."

seven months after that: the app doesn't work. web site disappears. company goes under.

[–] shortwavesurfer@lemmy.zip 21 points 1 day ago (1 children)

I am using my password manager, which is keepass.

I have tried adding pass keys to it, and have had mixed success. On some websites, it seems to work fine, and then on others, it seems to break miserably, and made me return back to a password.

I like the idea of passkeys, because then you don't have a shared secret between you and the website, and you get a different key for every single website using public-private key cryptography. That's fantastic, but the implementation still needs some work.

[–] uhmbah@lemmy.ca 9 points 1 day ago

They're going to have to pry my keepass out of my cold, dead hands.

[–] pleksi@sopuli.xyz 11 points 1 day ago (1 children)

I dont understand the issue. Arent passkeys and password in any case just stored in a pw manager nowadays?

[–] Nerdulous@lemmy.zip 5 points 1 day ago (1 children)

He talks about that if you read the article

load more comments (1 replies)
[–] xylogx@lemmy.world 12 points 1 day ago (1 children)

The problem he is describing here is mostly with enrollment and account recovery and not so much passkeys. The risk of getting locked out of accounts exists whether or not you use passkeys. Code based authenticators are not any better in this regard. Enrollment and recovery are the hardest part of identity. Passkeys are meant to address phishing risks specifically. I would love to see us do better on account recovery whether or not passkeys get adopted. The thing is, passkeys adoption is pretty slow and it has little to do with the issues described in this article. People just find it complicated and confusing. Until it is dead simple and the default, it will not find broad adoption.

load more comments (1 replies)
[–] Lutra@lemmy.world 12 points 1 day ago

Companies have had 13,000+ Data breaches in the last 5 years. Lets all put our access in one of those, so that when some thief get access to one, they get access to everything.

"But Lutra, they won't have access-access the pieces arent all there .. blah blah blah"

Oh, cool, Lets put all our access in one of those, so when they get access to one, they lock us all out of everything.

[–] Ertain@feddit.online 10 points 1 day ago

I'm not the biggest fan of passkeys, either.

[–] aesthelete@lemmy.world 10 points 1 day ago

Me neither | aesthelete

[–] psycotica0@lemmy.ca 18 points 1 day ago* (last edited 1 day ago) (4 children)

I don't know that OP is wrong per-se, but I think they're overstated a bit.

Their statement that passkeys are better than people using the same password, but are a step back for people using a password manager, is maybe a bit much. It's basically the same, but sometimes better.

Most of their drawbacks are the hardware implementations, but that's already true of people using hardware 2FA, and corporate management, which is already a problem if you use Apple's or Google's existing baked-in password managers.

But if you don't already have both of those problems, the standard is basically just "instead of having the password manager pretend to type in a box, what if they dumped something into the stream directly", and that extends to what if the UI didn't ask for anything and just said "hey, do you want to login? Just let me know and it's done"

And, like, should you be able to export from Apple's built in store to migrate? Absolutely, but if you never used Apple's passkeys in the first place, because ugh gross, then it's not a problem you need solved yet.

There is one problem I'll admit, which is that it's easier to make a sketchy password manager that just pretends to be a keyboard. I myself don't actually use passkeys because I sync my passwords with git and use pass, which is cool and I love it. And then I type them using a dmenu script and xdotool, which is silly and I love it. But that doesn't work with passkeys which I can definitely store in git, but would require a real actual connection between my browser and the tool, in a way that I don't think currently exists.

But just because I can't use my sketchy crap, doesn't always mean it's a step back 😛

load more comments (4 replies)
[–] sunbeam60@feddit.uk 24 points 1 day ago (6 children)

Love them.

Using 1Password for sync.

Never ever failed to connect to QR code passkey request, even on weird corporate networks.

Portability has gotten so much better - there’s now a defined standard for portability that passkey providers are implementing.

Honestly I cannot understand the criticism at all.

load more comments (6 replies)
load more comments
view more: ‹ prev next ›