“I don’t like passkeys”

Passkeys are a fantastic technology. Since they are bound to the site they are created for, they cannot be phished by a hacker’s fake login screen. If a site suffers a data breach, passkeys are asymmetric and cannot be recovered from the server-side details.

This leads to passkeys being the perfect fit for a corporate environment, but a poor fit for personal security. To an individual, the greatest risks are instead permanent account lockout, automated account bans, and device loss. By using passkeys, you gain better security against man-in-the-middle attacks but face the higher probability scenario of losing access to your accounts.

Phishing through the standard login flow is eliminated by passkeys, but it creates a false sense of security. An account’s security is still dictated by the weakest recovery method: SMS, email links, security questions, and so on. If these recovery methods aren’t enabled, then the risk of permanent lockout remains for the user.

↫ Ethan Hawksley

I’ve always felt something was off about passkeys, and have never used them. They’ve become – or were always intended to be – tools for further lock-in by especially Google and Apple, tying their entire usage flow to their respective operating systems. They also don’t seem to work well if you often work on devices not your own, which is a major hassle. None of these shortcomings come into play when using a traditional password manager, even if they require more manual work.

Just let me use a password manager with random password generation, instead of trying to force passkeys down my throat.

3 Comments

  1. 2026-09-19 8:28 am
  2. 2026-09-19 9:01 am
  3. 2026-09-19 9:56 am

Leave a Reply