Passwords have problems, but passkeys have more (world.hey.com)
from exu@feditown.com to technology@beehaw.org on 16 Oct 2024 06:59
https://feditown.com/post/744773

cross-posted from: feditown.com/post/744772

#technology

threaded - newest

ranandtoldthat@beehaw.org on 16 Oct 2024 09:24 next collapse

I use a password manager with passkey support and still disabled all my passkeys. The user experience for passkeys is so much worse even when support exists.

Mihies@programming.dev on 16 Oct 2024 11:57 next collapse

What’s the problem with combination of manager and passkeys?

ranandtoldthat@beehaw.org on 18 Oct 01:28 collapse

Just answered in a different comment.

state_electrician@discuss.tchncs.de on 16 Oct 2024 13:00 next collapse

Really? I just used a passkey for the very first time with Google and Bitwarden and it worked quite nicely. What about passkeys is worse for you?

ranandtoldthat@beehaw.org on 18 Oct 01:28 collapse

Just answered in a reply to a different comment.

ericjmorey@beehaw.org on 17 Oct 2024 13:45 next collapse

I’d like to hear more about the specifics if the issues you ran into. I keep delaying my options to start using passkeys because it’s a lot to take in at once and the only services implementing them seem to be the most important ones that I really don’t want to experiment with my ability to acess them. I haven’t even been looking at the details of each service’s implementation.

ranandtoldthat@beehaw.org on 18 Oct 01:27 collapse

It’s a combination of issues. First is compatibility issues. Like logging in on mobile web or app with a passkey doesn’t reliably work for me. It might have been due to the password manager, but for some things the option wasn’t even there afaict. If I’m going to really switch to passkeys, I want it to work more reliably.

The second is usability. Passwords in a password manager are a 2 click entry on the username or password form field. Password managers have streamlined this system over the past decade.

Passkeys, ironically, required more steps when pulling from the password manager, including required clicks in less convenient places. I hope these types of issues get ironed out eventually.

Mihies@programming.dev on 18 Oct 06:15 collapse

Yeah, both feels like password manager issues. Which one do you use?

Lem453@lemmy.ca on 17 Oct 2024 17:18 collapse

How do you login from a device that doesn’t have Bitwarden on it if you have passkeys.

For example a friend’s computer etc

With a password I can type the 20 or so digits of the password. Can’t really be done with a passkey as far as I know

ranandtoldthat@beehaw.org on 18 Oct 01:32 collapse

When I was trying out passkeys, things allowed either passkey or password still. But yes, I think this need partially reduces the security benefit of passkeys.

smeg@feddit.uk on 16 Oct 2024 12:18 next collapse

Using a security key as a password manager passkey seems to resolve this issue (I think?), but I guess the issue is more a problem for the casual user who wouldn’t bother with a security key!

ericjmorey@beehaw.org on 17 Oct 2024 13:42 collapse

Can you elaborate on what it means to use a security key as a password manager? I’m not sure if I understand what you mean.

smeg@feddit.uk on 17 Oct 2024 14:24 collapse

Whoops, I meant “passkey”, I’ll edit my original comment

pglpm@lemmy.ca on 17 Oct 2024 14:05 next collapse

The current security philosophy almost seems to be: “In order to make it secure, make it difficult to use”. This is why I propose to go a step further: “In order to make it secure, just don’t make it”. The safest account is the one that doesn’t exist or that can’t be accessed by anyone, including its owner.

bownage@beehaw.org on 18 Oct 13:27 collapse

Yeah but then we can’t sell you ppu licenses.

pglpm@lemmy.ca on 18 Oct 14:06 collapse

😂

Boomkop3@reddthat.com on 18 Oct 15:12 collapse

Normalize having a usb key on your keychain! Like a yubikey or something