Skip to content
  • facebook.com
  • twitter.com
  • t.me
  • instagram.com
  • youtube.com
Prep Music Log
Subscribe
  • Home
  • Tech
  • Music
  • Apple
  • Gaming
  • Home
  • Biz & IT
  • Passkey technology is elegant, but it’s most definitely not usable security
Passkey technology is elegant, but it’s most definitely not usable security
Posted inBiz & IT Features login passkeys passwords phishing Security signin

Passkey technology is elegant, but it’s most definitely not usable security

Posted by Samara December 30, 2024

Dialog box finally allows the creation of a passkey on a security key.

The dueling dialogs in this example are by no means unique to macOS.

Too many cooks in the kitchen

“Most try to funnel you into a vendor’s sync passkey option, and don’t make it clear how you can use other things,” Brown noted. “Chrome, Apple, Windows, all try to force you to use their synced passkeys by default, and you have to click through prompts to use alternatives.”

Bruce Davie, another software engineer with expertise in authentication, agreed, writing in an October post that the current implementation of passkeys “seems to have failed the ‘make it easy for users’ test, which in my view is the whole point of passkeys.”

In April, Son Nguyen Kim, the product lead for the free Proton Pass password manager, penned a post titled Big Tech passkey implementations are a trap. In it, he complained that passkey implementations to date lock users into the platform they created the credential on.

“If you use Google Chrome as your browser on a Mac, it uses the Apple Keychain feature to store your passkeys,” he wrote. “This means you can’t sync your passkeys to your Chrome profile on other devices.” In an email last month, Kim said users can now override this option and choose to store their passkeys in Chrome. Even then, however, “passkeys created on Chrome on Mac don’t sync to Chrome in iPhone, so the user can’t use it seamlessly on Chrome on their iPhone.”

Other posts reciting similar complaints are here and here.

In short, there are too many cooks in the kitchen, and each one thinks they know the proper way to make pie.

I have put these and other criticisms to the test over the past four months. I have used them on a true heterogeneous environment that includes a MacBook Air, a Lenovo X1 ThinkPad, an iPhone, and a Pixel running Firefox, Chrome, Edge, Safari, and on the phones, a large number of apps, including those for LinkedIn, PayPal, eBay, Kayak, Gmail, Amazon, and Uber. My objective has been to understand how well passkey-based authentication works over the long term, particularly for cross-platform users.

Last updated on December 30, 2024
Samara
View All Posts

Post navigation

Previous Post
After 60 years of spaceflight patches, here are some of our favorites After 60 years of spaceflight patches, here are some of our favorites
Next Post
You can love or hate AI, but it’s killed crappy 8GB versions of pricey PCs and Macs You can love or hate AI, but it’s killed crappy 8GB versions of pricey PCs and Macs

Recent Posts

  • Squid Game trailer anchors Netflix Tudum event
  • Breaking down why Apple TVs are privacy advocates’ go-to streaming device
  • Research roundup: 7 stories we almost missed
  • Trump pulls Isaacman nomination for space. Source: “NASA is f***ed”
  • German police say they’ve identified Trickbot ransomware kingpin

Recent Comments

No comments to show.

Archives

  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • September 2024
Copyright 2025 — Prep Music Log. All rights reserved. Bloghash WordPress Theme
Scroll to Top