Hacker News·4 min read·medium

I don't like passkeys

E
ethanhawksley
I don't like passkeys
AI Summary

The author argues that while passkeys offer superior protection against phishing, they present significant risks for individual users, such as permanent account lockout and lack of backup options. The piece criticizes the tech industry's aggressive push for passwordless authentication as a one-size-fits-all solution.

Why it matters

This perspective highlights the tension between high-level security protocols and the practical usability and recovery needs of everyday users.

Dive DeeperCreate a free account to unlock

For the past few years, the tech industry has kept pushing passkeys as the ultimate solution to logging in. Many Big Tech companies “helpfully” inform you every time you sign in how much easier and effortless passkeys are. The only way to make them stop is either to concede and set up a passkey or dig into the settings to find the off-switch.

Google goes as far as to name the setting “Skip password when possible” (opens in a new tab) , and Microsoft advertises that you should make your account passwordless (opens in a new tab) .

Passkeys are a fantastic technology. Since they are bound to the site they are created for, they cannot be phished by a hacker’s fake login screen. If a site suffers a data breach, passkeys are asymmetric and cannot be recovered from the server-side details.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologyculture

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in