It's a key, what else do non-technical people need to know?

Ironically on macOS we used to have an app called Keychain which unfortunately was effectively renamed to Passwords for non-technical users.

It's a digital key.

Unlike physical objects they may reside in a TPM, a software vault, an export/backup, or any combination thereof. You may or may not be able to recover or migrate them, depending on where/how they were made.

Therefore you may need multiple per service, or maybe not. Services which only allow one may end up locking you out with no recourse. You get to find out.

None of this is obvious or self explanatory to normies.

That's false. It's a digital key and it doesn't matter where it's stored. My key is on iCloud and it can be unlocked with my many recovery methods and contacts https://support.apple.com/en-us/102641

As for normies, passkeys or passwords it doesn't make a difference. Either you have people who use love1969 everywhere or those who constantly lose their passwords.

All passkeys accounts for normies require an email or phone number, which is what you can use to recover a password or passkey exactly the same way.

Where passkeys are stored is as important as where physical keys are stored.

People must understand security controls, at least at a surface level, in order to effectively manage and trust them. Passkeys fail that test.

Probably because these caveats and weird behaviours are platform-dependent, not really the passkey’s fault.

Passkeys really are not any more difficult to explain than 2-factor authentication. Anyone who’s currently been able to actually create an Apple or Google account and successfully navigate their devices up to a passkey screen will be able to grok how it works.

People around here really ought to stop thinking users are complete idiots. Hell, you don’t even to scroll that far to read people calling users “normies” for crying out loud. What is this? High school?

I don't care about the theoretical sufficiently advanced keypass implementation that works perfectly. I want to know about the half baked ones in the real world that I'll have to deal with.

Do you know how many Google and Apple accounts my boomer parents have?

Roughly one per smart-phone that they've ever used. They don't know the passwords or even the email address of any of them, not even the latest.

Tell me how passkeys makes this any worse. If one's digital life is a mess, there's no magic solution to it.

Arguably Yubikey and similar are better. Even vanilla passwords are at least understood by my parents, despite their confusion over account proliferation. Passkeys are a step backward for them, even more so in light of account confusion.

You obviously dont have to deal with anybody who doesnt know how or want to use computers.

The keychain and passwords app are separate and keychain still exists

I always operated under the assumption that the passwords app was just a more casual view into the keychain

Maybe that's a bad assumption

They're separate stores. I was under the same assumption until I tried to use `security` to get a saved password. It doesn't work, and as far as I know there is no CLI for the Passwords app's store.

[dead]