frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Passkeys are a trap. Do not use them

https://nonfunctional.substack.com/p/passkeys-are-a-trap-do-not-use-them
63•laurex•56m ago

Comments

shmerl•42m ago
> What’s important to know is that unlike with any other kind of login credential, you do not have ultimate control over your passkeys.

Use proper password managers, like keepassxc. Then you have control. But problem is that not all sites support that. If you can't use the above - then yes, passkeys are bad, especially if they become mandatory.

turtletontine•31m ago
If you keep reading the article, you’ll see that the claim is current (unattested) passkeys are a stepping stone to “attested passkeys”. Attested passkeys would require remote attestation with OS, TPM, and password manager all working together, and would allow websites to require things like hardware backed non transferable passkeys that you don’t control. This has always been my suspicion and I do think it’s worth worrying about.
skybrian•33m ago
Ideally, passkeys should be cattle, not pets. You should have more than one per account, saved to more than one password manager. Then it's fine if they're not copyable because you can get another.
Arainach•19m ago
> more than one password manager

I'm sorry, what? Who has more than one password manager (other than a personal/work split)? That's absurd and not something anyone I've heard of would put up with

JasonSage•16m ago
Want to guess how many non-tech individuals save passwords in Chrome on desktop and in iOS on their iPhone?
cowboylowrez•16m ago
if I can't have two password managers for redundancy then none it is.
drhagen•32m ago
Can someone tell why the whole standard for authentication on the web is not just this:

me: Can you show me my stuff?

website: HTTP 401, who are you? I understand EasyAuth 1.0, if that is good for you.

me: Sure, here's my EasyAuth 1.0: Hi <website>, I'm <user_id>. The time is <timestamp>. Signed, <digital_signature>.

drhagen•24m ago
Ok, I guess you also need a way to say "Oh, and next time I talk to you I'll use public key <public_key>."
ajross•16m ago
Because you or someone needs to publish "<digital_signature>" in a way that cannot be forged, stolen, MiTM'd, or otherwise compromised. Basically the key generating that signature just becomes another password, far more difficult to use in practice, and sharing all the same disadvantages.

So no one implements it for site-local login. Even the biggest sites like Amazon, for example, still use old-school passwords+2FA.

The way secure auth works for small sites is that a third party[1] authenticates you, who the website trusts more than mere users. And that's where all the complexity comes up. You need something secure stored on your known-secure device, a password alone won't do.

[1] In practice Google or Meta. Occasionally Apple or Microsoft. Everyone else is noise.

david_shaw•31m ago
This is a (very long and) well-written treatise against passkeys in their common and disparate forms. It's worth reading, and brings up several interesting and often concerning points.

I don't agree with the conclusion, though.

TOTP is great, flexible, and keeps the user in control; however, using a passkey in a flexible password manager (Bitwarden, keepass, 1Password, etc) really does continue to give the user control. And the user experience is dramatically easier than filling in TOTP codes.

To advocate for TOTP over passkeys, we're already relying on an application to generate those numbers (authenticator apps, password managers, etc). I see no reason to not simply continue using those pieces of software to manage passkeys, too.

lukeschlather•22m ago
I can't use a passkey on a device unless I can install my password manager on that device and I am comfortable giving that device access to my passkeys. Passwords are simply unparalleled in their flexibility. You're never going to be locked out because <bluetooth, your TPM, your phone, ...> isn't working today.

I think the bit about TOTP was mostly a joke, the problem with passkeys is that they're billed as a replacement for passwords but they mix lots of MFA concerns in and make interoperability essentially impossible a lot of the time.

Grombobulous•18m ago
But you can be locked out if the provider decides you need to change your password after a breach, or you forget the password, or you enter the wrong password in too many times.

They’re both equally disposable. You can reset a password just like you can reset a passkey.

nonfunctional•20m ago
I completely agree that KeePassXC and other password managers give you total user control, and they do support "passkeys" -- but crucially, not all kinds of passkeys. KeePassXC has no remote attestation support, nor hardware-backing support, and nor do I think it should.

My claim is not that passkeys couldn't give you control in principle. It's that the standard readily allows for websites to prevent you from being allowed to exercise that control, and the unclear messaging and UX around passkeys means most users will not even notice should this happen.

Havoc•31m ago
Knowing how big tech works this will get forced down throats desired or not
Cider9986•27m ago
Passkeys make it feel like the site is trying to get more info about me; it seems harder to maintain multiple accounts with passkeys. They feel worse for anonymity than a password where you know exactly what you're pasting into the site.

Although this isn't true because actually with a password you have to choose how to generate it and everyone chooses different ways.

nonfunctional•15m ago
My understanding is that TOTP and physical security keys both share very little information about you. Perhaps passkeys, being part of a standard that the FIDO Alliance keeps updating, may some day be expected to reveal considerably more information. And the limited number of remote-attestation-approved passkey managers might someday all start start volunteering such information regardless.
Grombobulous•15m ago
I don’t know if it’s productive for me to talk about how a headline is off-putting, but I’m going to mention it because, well, it’s a headline, and a headline is a strong first impression.

Is the audience of this article the kind of people who are already using passkeys and like them? Because, if so, we’re starting at a deficit here. The author is out to get my beloved passkeys that have saved me so much time and pain.

Are passkeys perfect? No. Are they even very good for no-technical users? Absolutely not…they’re incredibly confusing for that kind of person if you ask me.

However, for my workflow, I’ll take them over a password+2FA type of situation where logging in is such an annoyance. The security part of the discussion is very interesting and a lot of the things in this article is stuff that I never knew before.

The issue is that putting on my user hat, I just don’t care. As long as my accounts are reasonably secure I’m much more concerned about ease of use and workflow.

wry_xy•15m ago
I've been complaining about passkeys for a long time and it was driving me crazy that it seemed to be the one thing that Big Tech, tech-savvy people, and normies were all on the same page about. The recent PR push a few months back was overwhelming.

Passkeys in theory are great, but the capabilities of the spec are worrying. Defaults can and do change, and when they do, so follows 99% of the population, and then you find yourself either getting blocked out of services because your hardware/software doesn't comply, or you give in.

But on the other end, it might not matter anyways. Apple, Google, Cloudflare, are already pushing similar garbage and now you increasingly have to scan a QR code that verifies your mobile hardware to use a desktop.

bmitch3020•10m ago
I've yet to voluntarily enable passkeys, for the main reason that I want portability, and not to be tied to any single device that can be lost. I want to be able to backup and lock my credentials in a safe. I also want to control the strength of my credentials for different services, and I don't consider my thumbprint used to unlock my phone to be as strong as a long password in a password manager.

The first time I was forced to use a passkey implemented within the vendor's app (3rd party password managers were not an option). I quickly closed that account.

The second time was an app that popped up a passkey opt-in in the middle of a bunch of transaction screens. I quickly realized the error, but there was no easy undo. The opt in was one green button in the middle of the screen. Turning it back off required digging through settings to find the security option to disable, and then confirm my choice multiple times. That process also signed out all my other devices.

The fact that companies are resorting to dark patterns and forced requirements, where my money is held hostage, should be pretty good evidence of how poorly the passkey rollout is going.

FilmHunch – Describe a movie in your own words and get matching films

https://filmhunch.com/
1•eduardoalba•22s ago•0 comments

Calculate your p[DOOM], An interactive article to think critically about AI risk

https://jesserichardson78.medium.com/calculate-your-probability-of-doom-6bd18de3e0e4
1•routelastresort•50s ago•1 comments

A Chicago-area college told Flock to remove its cameras. The company refused

https://chicago.suntimes.com/education/2026/10/09/to-protect-immigrant-students-a-chicago-area-co...
1•smurda•1m ago•0 comments

Postgres FDW: Pushdown is a negotiation

https://clickhouse.com/blog/postgres-fdw-pushdown-negotiation
1•saisrirampur•2m ago•0 comments

Concrete Problems in AI Safety

https://arxiv.org/abs/1606.06565
1•yusufozkan•9m ago•0 comments

Google Data Centers around the world

https://datacenters.google/locations/
2•andsoitis•10m ago•0 comments

Show HN: Shpyrd – A new type of cloud for AI era

https://www.shpyrd.io
2•patricknegri•14m ago•3 comments

JulianFlux: Electrodynamic vector retrieval and causal routing for AI

https://github.com/julianjohnson-web/julianflux-research
1•julianflux•16m ago•0 comments

HPE Unveils the First of the Next Generation of ProLiants for the AI Era

https://www.nextplatform.com/compute/2026/10/08/hpe-unveils-the-first-of-the-next-generation-of-p...
1•rbanffy•22m ago•0 comments

Fingerprints Are the New Cookies

https://royfish.dev/fingerprints-are-the-new-cookies
1•royfish•22m ago•0 comments

Google is illegaly cutting forest to build data centers

https://www.theguardian.com/technology/2026/oct/06/google-datacentres-finland-temporary-halt-envi...
3•heyimada•22m ago•1 comments

Don't feel sorry for millennials. They are living it up now

https://economist.com/finance-and-economics/2026/10/11/dont-feel-sorry-for-millennials-they-are-l...
1•andsoitis•23m ago•1 comments

Not Deciphering The Voynich Manuscript

https://www.lesswrong.com/posts/Adxnsud5siZTRAaT3/not-deciphering-the-voynich-manuscript
1•optimalsolver•26m ago•0 comments

We Are Post-Human

https://www.noemamag.com/we-are-already-post-human/
1•whiteblossom•27m ago•0 comments

Amazon in talks to buy AI startup Decart for around $7B, WSJ reports

https://www.reuters.com/business/retail-consumer/amazon-talks-buy-ai-startup-decart-around-7-bill...
1•mraniki•27m ago•0 comments

Jensen Huang thinks AI is going great

https://www.nytimes.com/2026/10/07/opinion/jensen-huang-ai-tech-nvidia.html
4•bookofjoe•29m ago•2 comments

Why We Built the Food Corridor and Why Our Business Model Matters

https://www.thefoodcorridor.com/blog/why-we-built-the-food-corridor/
1•mooreds•30m ago•0 comments

MTCP 2026-10-10 Release Notes

https://www.brutman.com/mTCP/mTCP_2026-10-10_Release_Notes.html
1•accrual•31m ago•1 comments

Linux on iPhone 11

https://www.patreon.com/partshacker/posts/linux-boots-on-172091834
2•nullagent•32m ago•0 comments

Recursive self-improvement through collective intelligence

https://pub.sakana.ai/mass/
3•hardmaru•34m ago•0 comments

Shredding JSON columns gave Logfire up to 1000x faster queries

https://pydantic.dev/articles/dynamic-shredding-2026-01-26
1•acossta•37m ago•1 comments

Inside McDonald's push to have AI price your Big Mac

https://www.reuters.com/business/inside-mcdonalds-push-have-ai-price-your-big-mac-2026-09-29/
3•colinprince•40m ago•2 comments

Asking the Dutch Central Government a question on X

https://www.government.nl/service/contact/public-information-service/twitter
1•andsoitis•40m ago•0 comments

It looks like Wing Commander 3 is getting a remaster

https://www.pcgamer.com/games/sim/it-looks-like-wing-commander-3-is-getting-a-remaster-after-ea-p...
1•howard941•42m ago•0 comments

AI Risk – Users Guide (Part V): Trust Is the Product

https://sdarchitect.blog/2026/10/11/ai-risk-users-guide-part-v-trust-is-the-product/
1•SanjeevSharma•43m ago•0 comments

Beginning of the Ende

https://blog.webb.page/WM-105
2•NetOpWibby•43m ago•0 comments

Small town's students set criteria in hunt for new principal

https://www.rnz.co.nz/life/lifestyle/don-t-hide-in-your-office-hokitika-schoolchildren-set-princi...
3•colinprince•44m ago•0 comments

US Agency to Rewrite Rules to Address Vehicle Headlight Glare

https://www.reuters.com/world/us/us-agency-rewrite-rules-reduce-vehicle-headlight-glare-2026-10-06/
2•m463•45m ago•1 comments

A college told Flock to remove its cameras. The company refused

https://www.opencampus.org/2026/10/09/to-protect-immigrant-students-a-chicago-area-college-told-f...
2•DeepLogin•46m ago•0 comments

A college tried to cancel its Flock Safety contract and it refused

https://www.theverge.com/tech/1009411/elgin-community-college-flock-safety-cameras
5•sbulaev•49m ago•0 comments