I love passkeys. Really. They completely eliminate the need for a password and OTP in most cases (when actually used as they were intended and not as a second factor only), although I always set up both in case. Although I will never, ever like how Google does it. I set up my first Google account with them and now Google absolutely refuses to allow me to authenticate to it because it wants a passkey I don't have (and of course there's no way of not using said passkey) or it wants me to use an Android phone I (also) don't have (I traded it in a couple years ago). And, of course, it provides absolutely no way around that problem. So eventually I just gave up and created a new one for the (rare) times I do need a Google account for anything.
> refuses to allow me to authenticate to it because it wants a passkey I don't have... it wants me to use an Android phone I (also) don't have
And yet you love passkeys? How much will you love them when you're locked out of something you can't do without?
Passkeys are somehow 100% seamless for me, except for two services that have somehow screwed up the implementation: Google, and Okta. In Google's case, they have made it so that if you _ever_ add a passkey to their password manager, it somehow refuses to work with a third-party password manager going forward. In Okta's case, the admin policy UI makes it next to impossible to have passkey-only login without their Fastpass app or an oldschool password login.
> And yet you love passkeys?
Yes. The security benefit can't be overstated.
> How much will you love them when you're locked out of something you can't do without?
I certainly wouldn't be happy if this did happen, but it would be my stupidity (or the stupidity of those who implemented it on the service/platform where the problem occurred) which I would blame more than the fault of the tool. I do keep all passkeys in Bitwarden now so that's something at least.
> The security benefit can't be overstated.
Security benefit appears strongly overstated. Compared to using a password manager (including generated secure passwords for each account), there isn't a significant security benefit. passkeys require using a manager as well, so there isn't much point.
> ...but it would be my stupidity...
All people are stupid sometimes. A security flow that doesn't account for this very well isn't a very good security flow.
(Related: everyone tends to be unlucky eventually, and, unfortunately, everyone becomes incapacitated/dies eventually. Security flows need to account for these as well. Not to mention that in my experience, no software company continues to offer a quality service at a reasonable price forever. You're lucky to get 10 years. Having access to my accounts tied to a single piece of software is likely to become a big pain at some point.)
> passkeys require using a manager as well, so there isn't much point.
No they don't. I use hardware passkeys for all my important accounts. It's extremely easy.
I think this is probably one of the reasons people have very different passkey experiences. Hardware passkeys are great and software ones appear to be less great.