Passkeys remind me of ipv6 in that they are a "solution" coming from the supply-side, without (apparently) having done any research in what motivates actual users (and what would motivate them to switch).

<<ducks>>

They make sense as a technology for businesses & their users. In that scenario, the owner of the account is not the user, but the business. It makes sense for the business to be able to place strong restrictions on how & where the user may log in, it fixes a lot of real problems businesses may have thanks to sloppy user behavior, and the business is also motivated to provide a way to fix broken logins. It's a good solution for that scenario.

But for regular end users where services are primarily motivated to take money from those users and lock them into their ecosystems, they are a usability disaster and yet another exploitation vector.

It's one solution for two very different usecases, and it just does not work. There is an approach that could work for end users who own their own accounts, but they need to go back to the drawing board and rewrite the protocol with the assumption that the keystore is hostile to the user's interests. That means strong guarantees on key portability so users can migrate away from hostile keystores, and absolutely no ability for services to restrict the user's choice in passkey provider software.

> and the business is also motivated to provide a way to fix broken logins. It's a good solution for that scenario.

This is a big part of it. An employee at a business will be able to talk to someone in person and say 'I can't login. Can you reset my password?' or whatever equivalent, and be made whole. Even if the business is is made up of 10000 people and the identity of the employee is for some reason in question, the situation can still be resolved with a passport or a driver's licence.

Google is never going to make you whole again if you're locked out of your account, unless you're a celebrity and make a stink. There is no help desk where you can prove who you are (and even if you could, would you want to? That's a whole second domain of problems that I'm not sure will ever be solved completely).

I think passkeys were made to work in mind with complete idiots (here's a pop-up, tap it, now you have access to website without password, don't think about where it was saved or that it exists at all). I can understand parts of IPv6 like Router Advertisement being like that but there is so much customizability for the user that I can't really see them being similar that way.

To make it about security on both sides: IPv4 NAT is idiot-proof. IPv6 replaced that with a firewall that may or may not be default-deny.

Except they never considered that "complete idiots" could lose access to their phone's passkeys.

They did, that's why they sync

Right... just let me pull out my non-existent spare phone when mine breaks or gets lost.

It'll work if you have a laptop on the same account, iCloud or 1password or whatever else. If you only had a phone, you set the account up again on your new phone.

How does a person sync their passkeys between devices?

Nah, TOTP was like ipv6. Passkeys have their UI issues, but at least they had syncing day 1, so they're now a serious contender to SMS auth.

[flagged]

[flagged]