Hacker News new | ask | show | jobs
by dx034 707 days ago
I don't like passkeys. I'm not sure if I'm using it wrong, but it feels like entering a TOTP is so much faster and easier than using passkeys. It was always easy to enter a 6 digit code and have some back-up codes printed somewhere. Passkeys might be superior in some ways, but feel much harder to use. But then again, I'm also not an average user.
2 comments

I don't like the idea of passkeys if they cannot be backed-up or are non-portable locked away in a walled garden and possibly on stored on some corporate cloud in some unknown manner. When they can be backed-up, are portable, and have an explicit security policy, then I'll consider them.

For example, Bitwarden is able to act as a passkey provider on iOS and can store the passkey secret key gunk into a password record. I tried it out on a couple of minor services that have username & password login alternatives.

Do you still think it's easier to type in a 6 digit code that is on your mobile while you're browsing with your desktop (compared to Touch ID / Face ID with passkeys)?
Absolutely, takes me less than 10 seconds. And the process is transparent. Passkeys don't really seem to be faster.
No, I also have my passwords synced to me desktop. my phone is usually in a different room when I am on my desktop.