Why passkeys are a step back for personal security: examining account lockout risks, platform lock-in, hardware key limits, and fragile recovery flows.

853 points•ethanhawksley•13 days ago•819 comments•

819 comments

drtz13 days ago
Passkeys do marginally improve security against MITM and phishing attacks, but they are primarily for protecting the lowest common denominator from themselves: people who re-use passwords and/or don't use a password manager.

If you use multiple devices throughout the day, registering passkeys in all of these systems becomes a big headache with O(m*n) complexity, so putting the passkeys in a password manager is the only realistic solution. But this still breaks the login flow for a very common use case: how do I log in on a device that I don't own? With a password in a password manager I at least have the option of manually typing the password.

The biggest problem, though, is how users are pushed into it without any warning or knowledge of what they're signing up for. I've accidentally set up passkeys just by clicking an okay button a few times in the past and had to go back and figure out how to undo it after being blocked from login on another computer (which computer was I on again?).

dspillett12 days ago
> The biggest problem, though, is how users are pushed into it without any warning or knowledge of what they're signing up for.

My irritation is that I know what it is, and I've said no thanks many times, but I'm still asked regularly by the likes of Amazon, and they usually pick a time when I'm trying to order something quick¹. It is one of the growing number of things in life that simply have no “no” option, it is always “yes or later” - I wouldn't mind so much if “later” meant “I know the option exists, I'll ask for it if I change my mind, don't bother me again otherwise”. Call me cynical, but if companies are trying to nag me into something I very much doubt the main benefit is mine. I'm sure there are many people out there who go along with it simply because they are sick of being asked repeatedly.

I also don't see the real benefit with the way things are often implemented anyway. When the credential recovery process is sending a magic email or text, making SMTP or SMS the weak link of the chain just as it often is for passwords so I'd be giving up my preferred workflows for no better security.

----

[1] A short while ago I actually ordered from somewhere else because of this, bitter twit that I am. “I wonder if I can get this almost certainly drop-shipped item on next day delivery via Prime?”, [goes to Amazon to check], [get passkey prompt], “sod it, I'll go back to the original place”.

ProjectArcturis12 days ago
I dropped Amazon entirely a couple years ago because they didn't provide any way at all to separate my credit card from my kid's Fire tablet and I didn't want to be on the hook for thousands in charges because he pushed the wrong button. It's remarkably easy! It has made basically no change to my life except that I'm a little smug about not using Amazon.
sandeepkd12 days ago
I think this is the biggest reason why these category of discussion happens in the first place, there is a gap between what technology is good for, whats its ideal for and then the products motivation to push it on to the user assuming it would give a good name to the company.

Passkeys are one of the few protocols that supports against phishing (Accidentally giving away your credential to some rough site) so it has its benefits and more so for enterprise users.

It becomes challenging and is ill suited when its pushed to general public. A middle ground could have been to give it as an option to user instead of forcing it on the user. For some reason its not cool enough.

From a company's perspective

  - Authentication is a friction and the discoverable credential (where you just click on username button and log in) reduces the friction for user, making it easier for user to make that purchase decision

  - Account take over attempts (ATOs) do take a dip, saves quite a lot of resources on customer support side for the company
Telaneo12 days ago
> My irritation is that I know what it is, and I've said no thanks many times, but I'm still asked regularly by the likes of Amazon

The people responsible show a distinct lack of understanding when it comes to consent.

nntwozz12 days ago
> The biggest problem, though, is how users are pushed into it without any warning or knowledge of what they're signing up for.

Gf just logged in to hotmail without knowing her password because of a popup. I tried to explain but there was no understanding to be had.

This is how the world works. You either understand it or suffer it unknowingly.

FireBeyond12 days ago
Amazon and PayPal are horrible for this. Clicking out of the dialogs and modals to actually get logged in? (Shout out to PayPal for a dark pattern that implies "continue to login" but is actually "continue to set up PassKeys", and you actually need to "cancel" to actually login).
HaloZero12 days ago
My MIL setup a passkey accidentally on her Google account and now has no idea where it is. Removing it now requires her password which she’s also forgotten. But now for some reason on Google I can’t initiate any type of forgot your password flow because of how Google sets up things and I have zero clue where she stored the passkey.
brandon27212 days ago
Ran into the same issue with my dad the other day. Has a passkey set up on his Google account. Bear in mind that he doesn’t know what a passkey is, so Google obviously sent him through a pattern at one point to get him to create one.

He didn’t have access to it the other day and we needed access to his account. He didn’t remember his password, and we were unable to reset it because you need the passkey! No other options to authenticate for a reset were available.

Add in the fact that I was trying to help him with this by long distance call and you can imagine the frustration.

UltraSane12 days ago
Doesn't the passkey have to be on her phone or computer?
steezeburger12 days ago
I had to mess with this just yesterday.

I got a new cell phone and installed Microsoft Swiftkey and tried to login to Microsoft. It said my device's password or security manager would popup, but it never did and it never showed an option to login via password, just a mostly blank screen. I tried logging in from my laptop browser and it immediately tried using a passkey, but I've never created a passkey for Microsoft, so it errored out, still never showing an option for password login. I tried again and it errored out again and FINALLY showed the option to login via password. It had to fail 2 times to finally show the option for password login.

I was finally able to login via password, then had to go to Microsoft's passkey management page to create a new passkey, store it in 1password, and use that on my phone.

I'm a software engineer and it was annoying and time consuming and took a minute to figure out. How are non engineers supposed to even use this crap?

antonvs12 days ago
It's gotten to the point where I assume "product manager" is a synonym for "incompetent person who breaks working products."
judge202012 days ago
> how do I log in on a device that I don't own?

This is solved by passkey-implementing software and devices (with Bluetooth) allowing you to log in with a QR code (Webauthn via CTAP hybrid transport). iOS and Android support this, and it’s generally not a locked-down thing if other devices wanted to do it too.

The only use case left is in “how do I login if all my devices are stolen/fall into a body of water” in which there really isn’t an answer beyond “get (a|your) device back, sign back into your password manager, use that to get back into critical accounts”.

20198412 days ago
What if the computer you want to log in on doesn't have Bluetooth? Probably most public computers (like ones in libraries) don't have it.
darkwater12 days ago
>This is solved by passkey-implementing software and devices (with Bluetooth) allowing you to log in with a QR code (Webauthn via CTAP hybrid transport).

Ok but how do I share my Netflix or Spotify accounts for example with those?

basch12 days ago
What if my phone is dead? Stolen?

In the same vein as 2fa, going up to a fresh computer and trying to log into anything is now a nightmare. Every service has a 2fa that somehow loops into another provider that also has 2fa.

And some 2fa, if not many, make accounts weaker. Apple's solution to get around 2fa is to put in SOMEBODY ELSES phone number that I trust, as a backdoor. It's an insane solution. And its normalized, and nobody questions it.

epihelix12 days ago
Awesome. I'll just find the thief and ask nicely, shall I?
deaton12 days ago
Sign in with a QR code is dangerous though because at that point theres very little stopping QR phishing and forwarding the bluetooth request to your browser. See the most common Discord scam.
mystifyingpoi13 days ago
> how do I log in on a device that I don't own?

Sad reality is that such usecase is less and less common, thus, no one cares about it. I think majority of my friends would not be able to access their email, or facebook or alike, if they were forced to use my computer in emergency.

epihelix12 days ago
And that sounds fine, until you're traveling and your devices get stolen or lost. How, exactly, are you going to get into your email then, once passkeys become the only means of login? Because that moment is when you really do need to access your email, stat.
alienbaby12 days ago
Rubbish. Such use cases are extremely common anywhere it can't be expected everyone has access to their own device.
cj12 days ago
Isn't there a workflow where you scan a QR code to confirm the pass key on your phone?

I've definitely done this, but not sure if the workflow was at the OS or browser level.

I'm honestly confused by all the negativity in the comments. Passkeys are great for convenience. Just leave your password login enabled as a backup. That defeats any security benefit, but oh well.

Latty12 days ago
Which is a trade-off that makes sense for a lot of people. If you have multiple devices, many of which are portable and one you have on you all the time, the need for that is just way lower, so being more secure against commonplace automated widespread attacks is worth it to them.
makeitdouble12 days ago
A variant of that is alternative accounts that properly live on a different device/context.

For instance YouTubers usually have a different account for their channel than the one they use privately, and don't want their channel account logged in everywhere.

That means having to log in as a guest when push comes to shove. And similar setups are common for most self-employed keeping a "work" account IMHO.

hannasanarion13 days ago
The point about poor support for 3rd party managers is so frustrating. Because this is correct, that is the obvious solution for the normal user, but passkey implementations somehow do not know how to deal with it.

Amazon prompts me to create a passkey everytime I log in, even when I logged in with a passkey, because my passkeys live in Bitwarden rather than my OS or browser.

And the confusing mechanism hurts there too: I'm always a little bit afraid that i'm somehow more in danger because I keep them in a vault that's shared on all my devices rather than a TPM, because whenever the protocol is explained the "it can't leave your device" part is highlighted as the main source of the security, except.... mine obviously do leave my device, with the vault, so.....

jasonjayr13 days ago
Yet, the Apple + Google implementations will sync passkeys between your devices. "Securely", of course. (I've seen first hand how Apple implements this, and it seems.... sound)

Sites can request hardware-bound tokens, which would block any software based password managers. It's an option in the protocol but one not yet widely utilized.

XorNot13 days ago
Which is a problem.

It should not be in the protocol. And I don't trust Apple and Google not to lock it away from me.

I want my own open source manager and if that is attempted I want it to lie about it.

cryptoegorophy12 days ago
So is there a problem with Apple or no?
jeroenhd13 days ago
> Amazon prompts me to create a passkey everytime I log in, even when I logged in with a passkey, because my passkeys live in Bitwarden rather than my OS or browser.

What setup are you using? Because I don't have that problem on Linux + Firefox at all

hannasanarion12 days ago
Linux, Mac, and Windows (i happen to use all three regularly for work, hobbies, gaming), Firefox + Bitwarden.

It's totally possible there's something specific about my situation, or the way it was set up in the first place that enables this, idk, but somebody else replied saying they have the same experience so it's not just me.

And even if it was just me, it's still clearly something wrong on the provider's implementation, because it should not be possible for software to sidetrack the user into a passkey enrollment flow, when that user logged in with a passkey to open the current session.

Gareth32112 days ago
> Amazon prompts me to create a passkey everytime I log in, even when I logged in with a passkey, because my passkeys live in Bitwarden rather than my OS or browser.

I haaaaaate this. And every time I'm like, "do I not already have one??" Passkey implementation has been half-assed by everyone.

qlte12 days ago
I don't have any issues using Bitwarden as the default password manager on any of my devices, except the occasional Android/Google issue with apps where it opens the Chrome passkey store and doesn't prompt for Bitwarden.

But websites pretty much universally trigger the Bitwarden passkey prompt, or I can bypass via the popup and go to the OS passkey manager.

tzs12 days ago
> Amazon prompts me to create a passkey everytime I log in, even when I logged in with a passkey, because my passkeys live in Bitwarden rather than my OS or browser.

I use 1Password and Amazon does not prompt me like that. However I do have two passkeys for Amazon, one in 1Password and one in Apple Passwords. There's not enough data yet to say if it happens to you because of something not working right between Bitwarden and Amazon, or something about Amazon doesn't work right if you don't have a passkey in your OS passkey store.

Might be worth adding a passkey for Amazon to your OS passkey store and see if the problem goes away. If it does, blame Amazon. If it does not, report it as a possible bug in Bitwarden (altough it still could be an Amazon bug that just happens to mess with Bitwarden but not 1Password).

randomblock112 days ago
It's amazon, I have 1password and it always asks me to create another security key
elteto13 days ago
While the technology itself may be great (I don't really know since I don't use them) it has been co-opted by the tech conglomerates as another form of isolating and walling off users into their ecosystems.

And honestly, nowadays, if tech companies are pushing really hard for something then that is an immediate red flag for me and it bears more scrutiny. One of those "if you see them running that way you run the opposite way".

reddalo13 days ago
Exactly. That's why I'll never use passkeys: they're just another way to force us into a commercial walled garden.

Passwords with 2FA are simply better and more freedom friendly.

Shank12 days ago
I store my passkeys in KeePassXC and I have absolutely no feeling of being walled into any garden, personally.
apexalpha12 days ago
I just bought a passkey... It's a USB device, completely separate from any big conglomerates.
jwcrux12 days ago
How do you see passkeys as a walled garden but not 2FA? You presumably store your 2FA seed in a password manager.
alibrarydweller12 days ago
I did a deep dive on this since progressively more places are taking a hard line about Passkeys.

The most flexible, independence preserving thing to do is to use a third party password manager like Bitwarden, and make that the default passkey flow for your devices. If desired, you can self-host something like Vaultwarden so that you can both keep the keys independent of third parties and walled gardens and also propagate them to other client devices.

To be clear I'd much rather not have learned / implemented any of this, and I don't use passkeys unless forced, but this seems like a valid coping strategy.

spider-mario13 days ago
It’s a bit ironic that Apple is the one that lets you export them.
rcxdude13 days ago
They're also not supporting device attestation which would allow websites to insist on particular implementations of passkeys.
93po12 days ago
But only to other approved apps
mschuster9113 days ago
> And honestly, nowadays, if tech companies are pushing really hard for something then that is an immediate red flag for me and it bears more scrutiny.

The reason is the ever increasing number of hijacks of social media presences and code hosting portals, with the latter being a serious financial threat. Done right, passkeys stay in the Secure Enclave, at least for anything Apple and most of the Android sphere. There is no reasonable way to obtain login credentials for accounts protected by passkeys without physical access to the user's device(s).

zamadatix13 days ago
The doubt is more "how will tech companies use passkeys as an excuse to do something stupid" than "passkeys themselves must have inherent problems because tech companies are pushing them".

Passkeys could be the savior of all security problems worldwide from a capability point of view and tech companies would still ruin it by trying to force ways it pushes you into their ecosystem instead of just being whats both secure and convenient.

As an example, I have 3 different passkey _APPS_ on my phone and cannot go down to one because of various reasons with each (such as MS authenticator, forced for integrating to Microsoft at work).

iso163113 days ago
> There is no reasonable way to obtain login credentials for accounts protected by passkeys without physical access to the user's device(s).

Click "I lost my device", enter contact, get a reset link via email/sms

TeMPOraL12 days ago
Very solid points, and I love the focus on the fact that passkeys are addressing threats irrelevant to regular people, while ignoring those that matter. But I think it's still incomplete, because it's missing the biggest blind spot in design:

Password sharing is a feature, not a bug.

Security industry failed to implement the most basic feature one does with access control at individual level, which is delegation of authority. Physical security in form of "bearer" devices, such as keys, credit/debit cards, transit tickets (except those newfangled ones bound to photo ID), etc. all support this by default.

Ad-hoc delegation of authority is a normal thing to do, something we do all the time without thinking. Asking your kid or friend to do groceries for you? You hand them your debit card and give the PIN. Need a nanny to walk your kid from school and stay with them until you're back? You make them a copy of your house keys.

This carried over naturally to technology realm. A colleague needs to get some data that happens to exist only on your machine, while you're away? In normal non-corporate places, you just write the password on a post-it and give it to them, or put it in a drawer and tell them to go look there.

Security industry failed to provide a reasonable alternative path for over four decades now, and instead continues to deny the very existence of the need for ad-hoc delegation of authority. Passkeys are a bad choice for regular users largely because they're designed to prevent delegation - on top of the other issue, that the author correctly recognized, which is that by far the biggest threat to regular user is that of loss of access to account.

fortyninenine12 days ago
On a system I'm designing, you can provide a 2nd (or 3rd, 4th) password, which affords an user of said username/password combination a subset of the permissions _you_ have, which stops working after a date.

This has made multiple product owners cry. I am wondering if it would make sense to add a 2ndary action prompting the user at the eol for this secondary credential asking them if it went fine, to try and collect some information on how popular the feature is.

raphman12 days ago
Oh cool. Would you mind expanding a bit on the implementation? I have been thinking about a generic auth system like this for some time.
TeMPOraL12 days ago
That's nice and I applaud you for attempting to solve it in a user-friendly way.

Sadly, because that'll come off as unusual to 99%+ of your userbase, you'll probably face challenges explaining this to the users, and it'll skew statistics you gather here. Chicken and egg problem, really :(.

john_strinlai12 days ago
>passkeys are addressing threats irrelevant to regular people

phishing is very relevant to regular people

TeMPOraL12 days ago
Not really that much in comparison to losing access when needed. It's relevant to corporate employees, where phishing is worthwhile to attackers, while losing access means creating a ticket on internal helpdesk and having rest of the day off.
zbentley11 days ago
All true, but there's a wrinkle with delegating auth in computer systems--the same wrinkle that comes up when thinking about digital data as property/copyrightable etc.: when you delegate auth, you copy the access; you don't loan it. So every digital delegated-auth scenario is like your "make a copy of your house keys" example, not your "loan out your debit card" example.

If we extend the metaphor, this would be like making a copy of your keys and handing those out every time someone other than you needed access to your house. Dinner guest? Key copy. Neighbor dropping off a borrowed tool? Key copy. Relative from out of town visiting? Key copy.

In the same way that I think most homeowners would look askance at passing out so many copies of their keys, delegated digital auth is troublesome. Nontechnical users are unlikely to pay attention to "what clients are using delegated credentials for which actions" dashboards. Revocation, while technically easy, isn't something that I think most casual users will be mindful of, resulting in endless growth in the list of principals with access to a resource (just like the "sharing passwords" scenario we have now). Time-based auto-revocation will be an annoyance for delegates who only need to access a resource rarely, resulting in exasperated administrators rubber-stamping new-delegate-credentials requests.

I don't know if there's a good solve here. Shared passwords might be the local maximum of convenience and security, but that feels pretty bad.

qlte12 days ago
You can add multiple passkeys in the vast majority of websites that support them. There's nothing in the spec that prevents or discourages allowing multiple credentials. I do it on every site I care about so I can fallback to the OS passkey store if I lost access to my Bitwarden account for whatever reason.
TeMPOraL12 days ago
Much like with 2FA apps, most of the sites I've seen - including big names - support only one app and one passkey at a time.
nunez12 days ago
I respectfully disagree with the author!

Passkeys have been a massive quality-of-life improvement. Yes, there's the minimal risk of lockout if you lose access to the passkey (though almost every site I've used that implements pk's lays it on top of their traditional user/pass auth flow), but generally speaking most people use iCloud or their Google account to store their passkeys, and because those sync everywhere, this isn't a real risk.

I love not needing to deal with 1Password's autofill being flakey and having to CMD-C/CMD-V passwords/passphrases/OTPs on these sites.

I like Yubikeys as well but they are super inconvenient by comparison when dealing with multiple devices. Setting them up is also very user-unfriendly in general; doubly so compared to passkeys.

Now, what I'd REALLY F'IN LOVE to see go away is the passwordless/magic link auth flow wherein you authenticate by clicking a magic link that gets sent to your email or text message inbox.

"Emails are super easy to hack and we're still not sure whether text messages are safe to send on US carriers, so let's have everyone click on a link sent by email or text so that they don't have to deal with those pesky passwords that iOS or Android will automatically suggest for them." Like, what?

kyle-rb12 days ago
> Emails are super easy to hack

Source? And if somebody hacks my Gmail account, won't they be able to access my Google-synced passkeys?

Magic link auth isn't any less secure than any site that has a password-reset flow.

nunez12 days ago
A family member installed an app into their Android phone from the Play Store.

It was innocent enough until it asked for a truckload of permissions, like being able to change the launcher, which they ofc tapped "Allow" to since permission request fatigue is real and still a bit of an unsolved problem.

So the app delivered on its promise and changed their phone's launcher. It had a fake Gmail widget that showed them their mail but, of course, wasn't actually tied to the actual Gmail app and was an easy way of getting a refresh token for their account.

Bingo bango bongo: their email was now at risk.

They changed their password after I told them to right away upon them asking me to look at their phone because "it was slow."

> Magic link auth isn't any less secure than any site that has a password-reset flow.

Which is exactly the problem. Cloning someone's SIM/eSIM and immediately performing password resets is a well-known security issue.

rdsubhas12 days ago
> what I'd REALLY F'IN LOVE to see go away is the passwordless/magic link auth flow

This seems really naive? That's the only flow that's at the basis if you get locked out. What else, do you put people on the phone to verify people by asking their name and date of birth? That's even worse!

stetrain12 days ago
I think they're referring to sites where that is the only way to sign in, which I have seen a few of. Basically you can never register a password or passkey, every sign in requires going to your email and waiting for the link to arrive.
nunez12 days ago
For services that have your PII or payments details, yeah, that should be the only way to do a reset. Super inconvenient but much less so than dealing with stolen identity or credit cards.
boronine12 days ago
Majority of websites use email to authenticate (“forgot password” flow). Passwords/passkey is just an optional convenience for quicker login.
madog12 days ago
> Yes, there's the minimal risk of lockout if you lose access to the passkey (though almost every site I've used that implements pk's lays it on top of their traditional user/pass auth flow)

Exactly, if you lose your passkey you just sign in with your password like you did previously. I'm yet to find an app/website that has passkeys only and no passwords.

Seems like a total non-issue to me.

morgoo12 days ago
One of the big benefits of passkeys is that you can completely remove the ability to log in with a password!
epihelix12 days ago
Ok, so the big security risk that passkeys are supposedly designed to stop, is actually still there?

If you can still be phished, remind me what the point of any of this was, again?

qlte12 days ago
Yes, at this point I have probably saved literal hours in time added up by being able to skip MFA prompts on sites/apps I use regularly via a passkey login flow. It was becoming ridiculous how often I'd hit a "verify who you are with your phone/email" gate even on services I use constantly, a gigantic waste of time.

Read the full thread on Hacker News →

Related stories