Passkeys Are a Step Back for Personal Security

I don't like passkeys

Passkeys Are a Step Back for Personal Security

Passkeys are great for enterprises but a poor fit for individuals. The biggest risks for personal users are permanent lockout, automated bans, and device loss, not phishing. Hardware keys can't be backed up and have account limits; synced passkeys tie you to Apple or Google, so an account ban locks you out everywhere. The ecosystem is still too immature for personal use.

For users who previously reused passwords across all their sites, passkeys are a huge step-up. For everybody else, it is currently a step back.
  1. drtz

    Passkeys do marginally improve security against MITM and phishing attacks, but they are primarily for protecting the lowest common denominator from themselves: people who re-use passwords and/or don't use a password manager.

    If you use multiple devices throughout the day, registering passkeys in all of these systems becomes a big headache with O(m*n) complexity, so putting the passkeys in a password manager is the only realistic solution. But this still breaks the login flow for a very common use case: how do I log in on a device that I don't own? With a password in a password manager I at least have the option of manually typing the password.

    The biggest problem, though, is how users are pushed into it without any warning or knowledge of what they're signing up for. I've accidentally set up passkeys just by clicking an okay button a few times in the past and had to go back and figure out how to undo it after being blocked from login on another computer (which computer was I on again?).

  2. hannasanarion

    The point about poor support for 3rd party managers is so frustrating. Because this is correct, that is the obvious solution for the normal user, but passkey implementations somehow do not know how to deal with it.

    Amazon prompts me to create a passkey everytime I log in, even when I logged in with a passkey, because my passkeys live in Bitwarden rather than my OS or browser.

    And the confusing mechanism hurts there too: I'm always a little bit afraid that i'm somehow more in danger because I keep them in a vault that's shared on all my devices rather than a TPM, because whenever the protocol is explained the "it can't leave your device" part is highlighted as the main source of the security, except.... mine obviously do leave my device, with the vault, so.....

  3. nunez

    I respectfully disagree with the author!

    Passkeys have been a massive quality-of-life improvement. Yes, there's the minimal risk of lockout if you lose access to the passkey (though almost every site I've used that implements pk's lays it on top of their traditional user/pass auth flow), but generally speaking most people use iCloud or their Google account to store their passkeys, and because those sync everywhere, this isn't a real risk.

    I love not needing to deal with 1Password's autofill being flakey and having to CMD-C/CMD-V passwords/passphrases/OTPs on these sites.

    I like Yubikeys as well but they are super inconvenient by comparison when dealing with multiple devices. Setting them up is also very user-unfriendly in general; doubly so compared to passkeys.

    Now, what I'd REALLY F'IN LOVE to see go away is the passwordless/magic link auth flow wherein you authenticate by clicking a magic link that gets sent to your email or text message inbox.

    "Emails are super easy to hack and we're still not sure whether text messages are safe to send on US carriers, so let's have everyone click on a link sent by email or text so that they don't have to deal with those pesky passwords that iOS or Android will automatically suggest for them." Like, what?

  4. projektfu

    Multiple sites (e.g. Microsoft) currently ask me to use the passkey to log in after I enter my username, but the passkey doesn't seem to be stored anywhere. I usually will end up scanning the QR code to check if it's on my phone and get a negative answer. Then I have to go through the regular password + 2FA ritual I was already ready to use. After that, I am not given the option to store a passkey on the device I am currently using or on my phone. Process repeats next time. So much fun using passkeys.

    I think there are two sites where I can actually log in using them.

    I also don't like the way the pop-up is always so automatic and interrupting. Why not a button like other ways to log in?

  5. elteto

    While the technology itself may be great (I don't really know since I don't use them) it has been co-opted by the tech conglomerates as another form of isolating and walling off users into their ecosystems.

    And honestly, nowadays, if tech companies are pushing really hard for something then that is an immediate red flag for me and it bears more scrutiny. One of those "if you see them running that way you run the opposite way".

  6. littlecranky67

    I try to boycott passkeys due to built-in attestation feature in the standard. Not active now, but given how Google+Apple already use the passkey feature to lock you into their ecosystems, it is just a matter of time until their service will require that the passkey is attested from a non-rooted Google or Apple device. I think this will especially be true for Google to prevent AI scraping bots. Turning this on does not require anything, once passkeys are widely used, Apple, Google and Co. simply can flip a switch.

  7. joshstrange

    I continue to avoid passkeys but it's becoming an incredibly dense minefield. Certain sites try to trick me into adding one each time I log in and I have to be careful to dismiss the 1Password prompt, then dismiss the chrome prompt, then dismiss the OS-level prompt (all back-to-back). It's so incredibly user-hostile.

  8. Liftyee

    YES. This exactly. I work across multiple devices, some of which are nonstandard/uncommon (Linux, Xiaomi China ROM, ...) and I've NEVER had passkeys work properly - yet everything constantly prompts me to add one. Even if they did work, I'd have to carry around hardware keys or register each computer separately. And the lack of backups if a device is lost/broken is definitely a larger concern for me than being phished of my TOTP keys.

  9. torstenvl

    > To an individual, the greatest risks are instead permanent account lockout, automated account bans, and device loss. By using passkeys, you gain better security against man-in-the-middle attacks but face the higher probability scenario of losing access to your accounts.

    I'm glad to see this view becoming more mainstream. Passkeys are grotesquely insecure.

    The only possible way to consider them more secure is if phishing attacks were more common and more damaging than lockout, which is so implausible that I reject the idea that someone could take that position in good faith.

  10. verytrivial

    In a corp environment, it is the business's problem when a user's passkey devices fails. In a personal environment, it is the user's problem. Specialized knowledge and preventive processes in the corp environment aren't present in the personal context, and saying "pretty please" to Google or Apple when something goes wrong is usually a waste of time. I 100% agree with TFA -- "damage expectation" is probably higher with passkeys.

More from this day

2026-09-18