Passkey technology is elegant, but it’s most definitely not usable security

May Be Interested In:Private eye accused of hacking American climate activists loses U.K. extradition fight


Dialog box finally allows the creation of a passkey on a security key.

The dueling dialogs in this example are by no means unique to macOS.

Too many cooks in the kitchen

“Most try to funnel you into a vendor’s sync passkey option, and don’t make it clear how you can use other things,” Brown noted. “Chrome, Apple, Windows, all try to force you to use their synced passkeys by default, and you have to click through prompts to use alternatives.”

Bruce Davie, another software engineer with expertise in authentication, agreed, writing in an October post that the current implementation of passkeys “seems to have failed the ‘make it easy for users’ test, which in my view is the whole point of passkeys.”

In April, Son Nguyen Kim, the product lead for the free Proton Pass password manager, penned a post titled Big Tech passkey implementations are a trap. In it, he complained that passkey implementations to date lock users into the platform they created the credential on.

“If you use Google Chrome as your browser on a Mac, it uses the Apple Keychain feature to store your passkeys,” he wrote. “This means you can’t sync your passkeys to your Chrome profile on other devices.” In an email last month, Kim said users can now override this option and choose to store their passkeys in Chrome. Even then, however, “passkeys created on Chrome on Mac don’t sync to Chrome in iPhone, so the user can’t use it seamlessly on Chrome on their iPhone.”

Other posts reciting similar complaints are here and here.

In short, there are too many cooks in the kitchen, and each one thinks they know the proper way to make pie.

I have put these and other criticisms to the test over the past four months. I have used them on a true heterogeneous environment that includes a MacBook Air, a Lenovo X1 ThinkPad, an iPhone, and a Pixel running Firefox, Chrome, Edge, Safari, and on the phones, a large number of apps, including those for LinkedIn, PayPal, eBay, Kayak, Gmail, Amazon, and Uber. My objective has been to understand how well passkey-based authentication works over the long term, particularly for cross-platform users.

share Share facebook pinterest whatsapp x print

Similar Content

Kristin Cavallari opens up about going a date with Morgan Wallen – and the 1 thing that threw her
Kristin Cavallari opens up about going a date with Morgan Wallen – and the 1 thing that threw her
Death at the Front Door: Who Shot Heidi Firkus?
Death at the Front Door: Who Shot Heidi Firkus?
New Delhi vows to flatten monster garbage pile in Indian capital
New Delhi vows to flatten monster garbage pile in Indian capital
Photos show how Air Force One has changed through the years
Photos show how Air Force One has changed through the years
Rat cake
From pickle everything to rat cakes, expect these food trends in 2025
NTSB Provides Update on Investigation Into Mid-Air Collision at DCA
NTSB Provides Update on Investigation Into Mid-Air Collision at DCA
Unscripted News: Where Reality Hits Hard | © 2024 | Daily News