back

by porridgeraisin·1y ago·view on hn ↗
> And once that’s done, the data suggests there will be no turning back:

> Users are three times more successful signing in with passkeys than with passwords (98% versus 32%).

> 99% of users who start the passkey registration flow complete it.”

I suspect this is because primarily tech oriented folks use passkeys today, and they are fairly unlikely to have trouble logging in with any method.

4 comments
Hilariously that 32% may well include all the bots doing stuffing attacks.
Also probably includes all the times my company has made me change my password. It always takes a good week before I remember that my old password isn't the one anymore.
It’s because it’s easier. Here’s what an Apple user experiences for creating an account or signing in:

1. Tap the login with Face ID button

2. Tap to approve it

It’s even faster than using a password manager without MFA but safer than password+MFA, and you aren’t spending any time goofing around with some poser’s password complexity policy or rotating your password when their servers are breached.

for real, it's so much better i've started using it everywhere, to the point where if a service asks me for a password i get really annoyed.

no i don't remember this random string i typed in months ago and no i don't want to have to type in the password to unlock my password manager for the 82349th time

this whole thread is perplexing, a forum full of tech people bitching about something that's more secure and more convenient

> a forum full of tech people bitching about something that's more secure and more convenient

I don't trust a cloud vendor to own my entire digital life, and I don't want to have to stand up and maintain my own super complex self-hosted passkey service. Passwords are easy, just stuff them in an encrypted text file. I have no idea how to self-manage passkeys.

With iOS, at least, you just backup your phone (locally, no need for iCloud).
That still means I have to depend on Apple to get access to my services, no?
Your keys are synchronized locally. You’re depending on apple to activate new devices.
Hmm, let me try to put this another way: how can I use passkeys such that at no point does my login go through a third party in between me and the service I'm trying to use?
... until you drop your phone in the toilet, that is. Then be prepared to spend weeks resetting passkeys.
I recently had a phone with a bunch of passkeys on it die unexpectedly. I didn't spend weeks resetting passkeys. I just logged into things with my hardware token on my keyring until all the sites I cared to use on my phone had fresh passkeys.

Or if my keyring was in the other room, I'd use the passkey on my laptop or desktop.

Most phones are waterproof and if your toilet holds your phone, laptops/desktops, and recovery keys it’ll also take your password vault because it’s an actually a black hole.
I currently have moat passwords synced with firerox. If I lose or break a device currently, I can restore from another, synced, device. If while using passkeys I lose or break my device, then what?
Any of your other devices will still work, as will your recovery codes, for getting a new device synced.
How would that work without a homogenious setup? Won't all devices need to be with Apple or Microsoft (etc)? Or is there a standard/cross platform solution?
Passkeys are already standard, enabled by default in all the popular web browsers, and thus already widely used by non-technical people (path of least resistance).
I've got to admit I found that 32% claim staggering. Does anyone know the source of that and what exactly was measured?