I don't like passkeys

The author argues that while passkeys offer superior protection against phishing, they present significant risks for individual users, such as permanent account lockout and lack of backup options. The piece criticizes the tech industry's aggressive push for passwordless authentication as a one-size-fits-all solution.
Why it matters
This perspective highlights the tension between high-level security protocols and the practical usability and recovery needs of everyday users.
For the past few years, the tech industry has kept pushing passkeys as the ultimate solution to logging in. Many Big Tech companies “helpfully” inform you every time you sign in how much easier and effortless passkeys are. The only way to make them stop is either to concede and set up a passkey or dig into the settings to find the off-switch.
Google goes as far as to name the setting “Skip password when possible” (opens in a new tab) , and Microsoft advertises that you should make your account passwordless (opens in a new tab) .
Passkeys are a fantastic technology. Since they are bound to the site they are created for, they cannot be phished by a hacker’s fake login screen. If a site suffers a data breach, passkeys are asymmetric and cannot be recovered from the server-side details.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in