I don't like passkeys
5 hours ago
- Passkeys are praised by Big Tech but primarily suited for corporate environments, not personal security.
- Personal risks include permanent account lockout, automated account bans, and device loss, outweighing anti-phishing benefits.
- Recovery methods (SMS, email) remain weak links; passkeys create a false sense of security.
- Hardware keys cannot be backed up, have limited account capacity (25–300), and require multiple expensive keys.
- Synced passkeys (Apple/Google) tie identity to OS accounts; if the account is banned, all passkeys are lost.
- Third-party passkeys via password managers face fragmented autofill and platform compatibility issues.
- Passkeys fail on shared or borrowed devices due to hardware, trust, or Bluetooth connectivity problems.
- For most individuals, a password manager with random passwords plus a separate TOTP app is currently safer and more flexible.