this post was submitted on 26 Sep 2026
408 points (95.1% liked)

Technology

88348 readers
3585 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
top 50 comments
sorted by: hot top controversial new old
[–] Evotech@lemmy.world 18 points 3 days ago

You know what u don’t like. Fucking xøcode sent to my email or a «magic link».

Srsly fuck off. Let me type my password

[–] audaxdreik@pawb.social 150 points 4 days ago (1 children)

This article does a great job of articulating a lot of the uncomfortableness I have around passkeys. I've always said they make a lot more sense in an corporate environment but the level of control you lose in a personal setting is not commensurate with the protections and possible lock-in they offer.

I just don't like passkeys. They are an overly technical solution to what is mostly a human problem.

[–] fushuan@lemmy.blahaj.zone 46 points 4 days ago (3 children)

Idk, when I want to log into my personal GitHub a bitwarden window opens from the extension, I click the GitHub profile I wanna sign in, and I do.

It's a great implementation since it's not linked to a physical device and it lets me authenticate in place. It's still MFA, it's just more comfy.

[–] anguo@piefed.ca 53 points 4 days ago (8 children)

It's not MFA if all you need is your bitwarden password.

[–] surfrock66@lemmy.world 27 points 4 days ago (4 children)

Unless your bitwarden has MFA and locks after an amount of time commensurate with your security needs

load more comments (4 replies)
load more comments (7 replies)
load more comments (2 replies)
[–] hummingbird@lemmy.world 90 points 4 days ago (2 children)

Sadly did not dig into the whole "the other side decides which device you are allowed to use" topic, a feature inherently build into passkeys.

load more comments (2 replies)
[–] ouch@lemmy.world 35 points 4 days ago (5 children)

Good article.

Currently passkeys are too much of a vendor lock-in to big tech.

Bitwarden support alone does not change that.

[–] Clusterfck@lemmy.sdf.org 21 points 3 days ago (5 children)

Microsoft 365 implementation of passkeys is sacrilegious somehow.

It requires only the Authenticator app from Microsoft and can use nothing else to create the passkey. The way this is implemented on iOS means that Authenticator comes up as an autofill option BUT IT ONLY SUPPORTS M365 and is useless for anything else. Leave it to Microsoft to take an open standard and bastardize it to the point of it being MORE CONVENIENT to just type a damn password.

load more comments (5 replies)
[–] turmacar@lemmy.world 22 points 4 days ago (5 children)

I agree the passkey user experience needs work, but man do I enjoy it over the haphazard 'passwordless' website login that just sends you an email.

I get it, they're just skipping an attack vector and basically relying only on '2FA'. But now I have to go to a different app/tab, copy a code, and return to the site instead of letting the password manager fill stuff in for me. Some, like kickstarter, let you still have a 2FA code enabled so you have to grab your code from whichever authenticator and go to your email. Really nice login experience out of nowhere one day. \s

load more comments (5 replies)
load more comments (3 replies)
[–] kestrel7_7@lemmy.world 10 points 3 days ago

I appreciate this article. Passkeys kinda came out of nowhere to me and I haven’t liked them since day one. So it’s nice to have my gut feeling vindicated with some actual info.

[–] dropdrip@lemmy.ml 21 points 3 days ago* (last edited 3 days ago)

This isn't a good article @ouch. It's dull, meandering and conflates issues.

Both Apple and Google want your identity anchored to their operating systems.

That's true regardless of passkeys and why is Microsoft excluded here?

Logging into accounts on devices you own is the ideal scenario for passkeys. When you have to handle a colleague’s computer, it gets much more inconvenient. You could plug in a hardware key, but you don’t always have access to the ports.

What sort of drivel is this? Is anyone reading the article? I doubt it. Sorry, I'm not logging into important accounts on a colleague's computer, regardless of being unable to squat and plug in a usb-dongle. The last statement even concedes that passkeys are an improvement for 99% of the user-population. It's an improvement for 100% of the user-population. Like usual this is just drivel generated from friction around 'newness'. It's different--which automatically becomes scary for some users. The writing is just not coherent and there's zero critique on passkey's design and technicalities, of which there are things to criticize.

Get a physical passkey and if you have more than 100 accounts you have a problem. Buy two and use one as a backup in case you lose your first. Keep it in a safe and if you forget your safe's combination... well, I guess we should abolish safes too: terrible account recovery support there. Yikes!

Passkey's themselves can be protected with a PIN--the software I've used does not limit it to numbers. It can be your 'master password' if you want. This is a technical complaint of mine as all software I've used reference it as a PIN (personal identification number), which means numbers only. Except other characters are allowed. I'm not sure what the official spec. states.

[–] warm@kbin.earth 63 points 4 days ago (10 children)

I think their biggest weakness is the vendor lock in. Using a 3rd party password manager is the best solution for most people, so they arent locked to their phone. But they are right in saying none of it is quite ready.

I think the article is forgetting, they are password replacements, not account recovery replacements. Realistically, people are just as likely to forget a password, and account recovery proceedures still have to be in place. I dont see the issue there.

Passkeys are good they are just being pushed before properly fully developed, but we are slowly getting there.

load more comments (10 replies)
[–] Passerby6497@lemmy.world 30 points 4 days ago (7 children)

I really wish that SQRL had taken off, as it solved most of the problems noted. It was effectively passkeys that you generated on the fly based on your private key (which you can back up and restore to other platforms if necessary) and the website domain by scanning a QR code (or clicking rh QR code if your on the same device) and sends the signed challenge to the website to auth you.

No need to login to your manager on random systems, no issues with platform lock-in, no worries about dedicated hardware, no worry about losing your access if your device dies (assuming you backup your shit).

load more comments (7 replies)
[–] muzzle@lemmy.zip 38 points 4 days ago (12 children)

For users who previously reused passwords across all their sites, passkeys are a huge step-up.

That is exactly why passkeys are a good thing. Basically everyone reused passwords everywhere.

[–] qevlarr@lemmy.world 60 points 4 days ago (6 children)

A password manager is better than passkeys in 2026

[–] Natanael@infosec.pub 14 points 4 days ago (5 children)

Some password managers can sync passkeys for you! Bitwarden can handle it

load more comments (5 replies)
load more comments (5 replies)
load more comments (11 replies)
[–] DJKJuicy@sh.itjust.works 31 points 4 days ago (5 children)

There is still nothing better than passwords.

I don't want my access to be tied to a specific device. Devices get lost, or break.

I don't want someone to be able to use my face or finger or eyeball to access my data. You can legally be compelled to unlock a device with your biometric security.

So current biometric security sucks. And passkeys suck.

Also, though...passwords suck for all the reasons that we all already know.

There has to be some better method that the owner can have full agency over, I just don't know what. I don't have the answers.

[–] MangoCats@feddit.it 13 points 4 days ago

Every attempt at using passkeys has been a step into murkier, less easily understood, less convenient security.

Passkeys may be a "step up" from password + TFA in terms of usability, but there's such a variety of implementations and explanations of how those implementations "keep me secure" - I feel like any idiot who grabs my phone when I'm not looking and can follow my unlock finger smudges on the screen can use my pass keys... No thanks.

load more comments (4 replies)
[–] jj4211@lemmy.world 7 points 3 days ago (1 children)

One complaint I have is browser insistence that a site must have a proper certificate to work at all.

I provide self hosted software with passkey support and probably over 90 percent of my users never set up property certificates due their private networks. So the passkey function is impossible for them.

Which means they must use passwords. Which are far worse in this scenario. The practical risk either way is arguably low for them, but to take a more mitm/phishing resistant technique and then force it to not work because mitm or phishing might be in play...

[–] isVeryLoud@lemmy.ca 3 points 2 days ago (2 children)

I literally just completed a Secure Code Warrior formation mandated by work, and one of the videos states "websites with expired certificates transit your information unencrypted, leaving you exposed to hackers" 🤦 like bruh you're supposed to know better, you teach cybersecurity for fuck's sake.

[–] jj4211@lemmy.world 2 points 1 day ago (1 children)

I've met two sorts of dedicated cybersecurity experts:

The sort that only understands how to click 'scan' in various tools and repeat output and browser error messages without understanding nuance. Had a fun incident where the nuance really mattered in interop with a popular product in my niche, company said we must not implement the interop because it was hopelessly insecure. When I pushed back on the nuance (folks behind the 'vulnerable' tech had way much more sway in the market than we did), got told I should really educate myself and read the paper on the vulnerability to understand that my proposol to workaround it was impossible. For one glorious moment in my career, I got to tell them to look at the paper again and specifically the author (I had written up the vulnerability in the first place). After a brief shock though, he still went back to even though I may have found it and explained in key detail, I still must not understand the implications...

Then there's those that understand and can engage in nuance, but will still say inaccurate stuff, because they've learned being accurate and precise with the lay person doesn't work too well, and easier to just say "big scary" instead of explaining precisely the threat model and rationale. I will confess on a number of threads I have seen this happen and let it go without correction because correcting wouldn't have changed the core of the material, but would make the discussion go on even longer and waste more time. I personally can't bring myself to outright say the wrong things, but I do understand why it's the more practical strategy sometimes.

[–] isVeryLoud@lemmy.ca 1 points 1 day ago (1 children)

I'm the kind of 'tism where I can't get myself to tell white lies and will argue up and down until the truth prevails... sometimes to my own detriment, but I really like to understand the underlying mechanisms and the nuance underneath things, otherwise I feel lied to, and I thusly can't get myself to feel like I am deceiving others.

Please share the paper, I'm curious!

[–] jj4211@lemmy.world 2 points 1 day ago

I'm trying to stay too anonymous, the paper is of super niche interest and the vulnerability comes down to a popular configuration being vulnerable, but a hardened configuration is possible, but requires randomizing some data that folks tend to leave non-random because it's the lazier way to set that up and it wasn't formerly recognized that the randomness of the data had security implications.

[–] LodeMike@lemmy.today 3 points 2 days ago* (last edited 2 days ago) (2 children)

Computing and by extension cybersecurity has a lot of mouth-breather idiots because it's so new.

[–] jj4211@lemmy.world 3 points 1 day ago

It's not so new anymore, however, it is widely known as an "easy" way to a strong six-figure salary, so we have a lot of gold-rush mouth-breather idiots that never would have gotten into this in the first place if not for the dollar signs. Really started to turn south around the time dot-com inspired early career people to get in on the bubble.

[–] isVeryLoud@lemmy.ca 2 points 2 days ago (1 children)

I think you a word, "cybersecurity" perhaps?

[–] LodeMike@lemmy.today 2 points 2 days ago

Oops. Thanks.

[–] jobbies@lemmy.zip 6 points 3 days ago
[–] shortwavesurfer@lemmy.zip 21 points 4 days ago (1 children)

I am using my password manager, which is keepass.

I have tried adding pass keys to it, and have had mixed success. On some websites, it seems to work fine, and then on others, it seems to break miserably, and made me return back to a password.

I like the idea of passkeys, because then you don't have a shared secret between you and the website, and you get a different key for every single website using public-private key cryptography. That's fantastic, but the implementation still needs some work.

load more comments (1 replies)
[–] sunbeam60@feddit.uk 25 points 4 days ago (6 children)

Love them.

Using 1Password for sync.

Never ever failed to connect to QR code passkey request, even on weird corporate networks.

Portability has gotten so much better - there’s now a defined standard for portability that passkey providers are implementing.

Honestly I cannot understand the criticism at all.

load more comments (6 replies)
[–] Lutra@lemmy.world 17 points 4 days ago (1 children)

The trap: Putting any 3rd party between you and your access.
It's a 3 card monte game, but with security.

Roleplay: Mr. Jonsith did you know your house is vulnerable? Your simple little key can be used by anyone to get in to your house. Security!? Our Keypass system will super secure your house. You give us your key, and when you want access, you come to one of our 5 in town locations, request access from us by showing us this new key here, and we will let you into your house.

load more comments (1 replies)
[–] whoisearth@lemmy.ca 9 points 3 days ago

🎶Security is Theatre🎶

[–] psycotica0@lemmy.ca 18 points 4 days ago* (last edited 4 days ago) (4 children)

I don't know that OP is wrong per-se, but I think they're overstated a bit.

Their statement that passkeys are better than people using the same password, but are a step back for people using a password manager, is maybe a bit much. It's basically the same, but sometimes better.

Most of their drawbacks are the hardware implementations, but that's already true of people using hardware 2FA, and corporate management, which is already a problem if you use Apple's or Google's existing baked-in password managers.

But if you don't already have both of those problems, the standard is basically just "instead of having the password manager pretend to type in a box, what if they dumped something into the stream directly", and that extends to what if the UI didn't ask for anything and just said "hey, do you want to login? Just let me know and it's done"

And, like, should you be able to export from Apple's built in store to migrate? Absolutely, but if you never used Apple's passkeys in the first place, because ugh gross, then it's not a problem you need solved yet.

There is one problem I'll admit, which is that it's easier to make a sketchy password manager that just pretends to be a keyboard. I myself don't actually use passkeys because I sync my passwords with git and use pass, which is cool and I love it. And then I type them using a dmenu script and xdotool, which is silly and I love it. But that doesn't work with passkeys which I can definitely store in git, but would require a real actual connection between my browser and the tool, in a way that I don't think currently exists.

But just because I can't use my sketchy crap, doesn't always mean it's a step back 😛

load more comments (4 replies)
[–] mlg@lemmy.world 10 points 4 days ago

Passkeys and 1FA were always just a duct tape solution for users resuing basic passwords without having to set a stronger password requirement or relying on users to use a strong password.

I think Chrome and Firefox should have decided on making an API for their builtin password generation and filling functions, that way any password manager would be able to integrate with foolproof functionality out of box.

People already use browser auto gen passwords for the reason that its faster and usually has an account sync built in. Now it would work with any 3rd party solution as well which covers enterprise and security minded users as well.

Users won't use a password manager if it means you have to manually make an entry everytime you make an account.

[–] xylogx@lemmy.world 13 points 4 days ago (1 children)

The problem he is describing here is mostly with enrollment and account recovery and not so much passkeys. The risk of getting locked out of accounts exists whether or not you use passkeys. Code based authenticators are not any better in this regard. Enrollment and recovery are the hardest part of identity. Passkeys are meant to address phishing risks specifically. I would love to see us do better on account recovery whether or not passkeys get adopted. The thing is, passkeys adoption is pretty slow and it has little to do with the issues described in this article. People just find it complicated and confusing. Until it is dead simple and the default, it will not find broad adoption.

load more comments (1 replies)
load more comments
view more: next ›