Why Passkeys Aren't Ready for Personal Use — Yet
Passkeys solve a real problem: because the credential is cryptographically bound to a specific site and stored as an asymmetric key pair, phishing pages can’t capture it and a server breach can’t leak it. That makes them an excellent fit for corporate environments where the primary threat is credential theft. For individuals, though, the author argues the calculus is different. The most likely ways ordinary people lose access to accounts aren’t man-in-the-middle attacks but automated bans, permanent lockout, and lost devices — and passkeys can make those failure modes worse. Worse still, the phishing protection can breed false confidence, since an account is only as secure as its weakest recovery path (SMS, email links, security questions), which often remains a soft target.
The practical storage options each have drawbacks. Hardware keys can’t be backed up — credentials can only be added or deleted, never copied — so resilience means buying and enrolling multiple keys across every site, and discoverable-credential slots cap out at roughly 25 to 300 accounts per key. Synced passkeys tie your identity to Apple or Google, meaning an account ban can wipe access to every third-party login at once, and cross-provider export remains immature. Third-party managers like Bitwarden or KeePassXC are the promising long-term path, but OS-level integration and autofill outside the browser are still inconsistent. Edge cases like signing in on someone else’s machine expose the gaps further, with QR-code Bluetooth ‘hybrid transport’ frequently failing in practice.
The author’s bottom line: enterprises have good reason to adopt passkeys now, but the consumer ecosystem isn’t mature enough. For most individuals, the day-to-day risk of lockout outweighs the AiTM threat that passkeys defend against, so a combination of randomly generated passwords in a third-party manager plus an independent TOTP app offers better control and portability. Passkeys are a clear upgrade for people who reused passwords everywhere — but for everyone else, they’re currently a step backward.
Read the full article
Continue reading at Hacker News →This is an AI-generated summary. Read the original for the full story.