Hacker News new | ask | show | jobs
by wenc 356 days ago
> I don’t have a good mental model for what a passkey is or how it works. And again, like most users if I don’t really understand what’s going on I’m just not gonna bother with it.

Sites kept asking me if I would like to setup a passkey, and I didn't have a good mental model for what it was either.

Turns out it's like PGP of the 1990s -- public/private key but for auth instead of email encryption.

Public/private key is not the of easiest ideas for a lay man to understand (though some YouTube videos explain it well).

All users want to know is that it keeps their information safe.

Like modern credit cards -- they use public/private keys, but the messaging is "your credit card number is kept safe," not this is based on PKI.