The average person? I have a Master's and PhD in CS, code regularly, and have followed and used all the cool technologies from the days of gopher, telnet and Mosaic to crypto, and lately LLMs. And I still don't have a clear enough picture of passkeys to know really basic things like "what if we have a family computer but each wants to access their private accounts and keep the others from accessing?", "what do I need do to login from an airport computer?" or "what should I do if my phone is stolen?"
If it's that unclear to me, I can't imagine how it can be to the average user.
The way they explain them is atrociously unclear, borderline negligent for services that nag people to activate it for accounts where they may hold valuable data for their personal lives. And while I don't want to spend much time finding out the details as long as I have the option to decline them, I suppose if they can't explain it and convince people of its advantages, it's because it's just bad tech.
> "what if we have a family Computer but each wants to access their private accounts and keep the others from accessing?"
That's what OS level user accounts are for. Tbf
> "what do Ineed do to login from an airport computer?" or "what should do if my phone is stolen?"
Indeed I don't know the answers to these either if I wasn't syncing passkeys in 1password. Honestly we should educate people to use password managers more than any thing. It's also a smaller jump than to passkeys. Passkeys can be more of an advanced convenience feature after they get used to using password managers already.
I cant upvote you enough for this very concise explanation of passkeys pain points.