Hacker News new | ask | show | jobs
by krupan 370 days ago
Can we be done with passwords yet? I see far too many sites offering a passkey option
2 comments

Sure, here's my public ssh key: public.swiley.net/id_rsa.pub I've been using this with everything important and was just waiting for everyone else to realize it was better.

Oh no wait, you wanted some retarded Windows/Apple thing that needs biometrics, locks everything to your pay for service/hardware, and has a worse security model.

Nevermind just use a password.

I agree that passkeys are overly complicated, but they are in no way a worse security model than passwords. That is ludicrous. The password security model is an incredibly low bar to clear if you want better security.

Also, passkeys work fine on systems other than Windows/Apple

If you have a password manager, what is the point of passkeys?

I was having this discussion earlier with a friend and we could not think of a compelling case. They seem less portable and harder to use on multiple devices or new devices. The only thing I could think of was protection against copied sites, but most users using password managers also block ads which should block most scam sites and password managers just need to have more messaging for if you try to fill in credentials on a site that is different from the site information saved with the password

Malicious website that looks like your bank can't get you to tell it your passkey, but you can type in your password.

(WebAuth checks the domain before signing)