Update 2025 Jan: This article says “The problem with passkeys is that they’re essentially a halfway house to a password manager, but tied to a specific platform in ways that aren’t obvious to a user at all, and liable to easily leave them unable to access … their accounts.”. Also, another link (from Proton’s blog) saying the same thing.
I came across a very interesting article that basically says the whole passkey thing has been enshittified now.
Before I get to the details, my conclusion is that passkeys are still viable, but not really necessary. The plain old “passwords+proper password manager+good backups” combo is still more than good enough for most people (including myself). Passkeys are better only because they use asymmetric keys, so the server does not need to store anything secret, but if you use a proper password manager that’s not relevant to you.
And as I said in an earlier blog post, password managers can now do passkeys also so you have the best of both worlds! Just stay away from the google/apple ecosystems in any way shape or form!!
And finally, a hardware key is immune to host compromise (virus, trojan, etc.), so in high risk situations that is better.
Anyway, getting back to the article…
Before KeePassXC came out with passkey support, I’d been railing against passkeys due to the potential for it being a huge availability problem for unwary users.
But it turns out there are far deeper and more fundamental issues – issues which I was not aware of because I refuse to use chrome and use only open source apps on my phone and don’t trust google at all. The article linked at the top is by someone who authors the main rust library for webauthn, and yet his conclusion basically is “go use a password manager and normal passwords” :-(
There are two separate but related issues here:
The end result is this hugely favours software-based passkeys (like Android/Chrome – “platform authenticators”), over actual hardware security keys (“roaming authenticators”).
For a quick explanation of resident keys: see https://fy.blackhats.net.au/blog/2023-02-02-how-hype-will-turn-your-security-key-into-junk/#what-is-a-resident-key. TLDR: a resident key takes up space on the device, and it is somewhat “discoverable” – you may not even need to type in a username to use it! In my opinion it’s mostly a gimmick. Non-resident keys are equally secure, and should be the norm.
Where this becomes an issue is that a hardware security key (such as the Yubikey) has limited space for resident keys (max 20-30 or so), while a software authenticator (i.e., Android, Chrome, iOS) has infinite capacity for resident keys.
So if you create a system where resident keys are needlessly and artifically mandated, then people will flock to the platform authenticators (Android, Chrome, iOS), creating huge vendor lockin!
Some quotes:
Since then Passkeys are now seen as a way to capture users and audiences into a platform. What better way to encourage long term entrapment of users then [sic] by locking all their credentials into your platform, and even better, credentials that can’t be extracted or exported in any capacity.
The article goes on to describe the problem in much more detail, and concludes:
At this point I think that Passkeys will fail in the hands of the general consumer population. We missed our golden chance to eliminate passwords through a desire to capture markets and promote hype.
Corporate interests have overruled good user experience once again. Just like ad-blockers, I predict that Passkeys will only be used by a small subset of the technical population, and consumers will generally reject them.
[…] and I’m starting to agree - a password manager gives a better experience than passkeys.
If you really want passkeys, put them in a password manager you control. But don’t use a platform controlled passkey store, and be very careful with security keys.
Another article by the same author https://fy.blackhats.net.au/blog/2023-02-02-how-hype-will-turn-your-security-key-into-junk/ explains resident keys better, and has more background on the problem. Some quotes:
In CTAP2.0 [the older standard] however, you can not. You can not delete a residentkey without resetting the whole device. Resetting the device also resets your master key, meaning all your non-resident keys will no longer work either. This makes resident keys on a CTAP2.0 device a serious commitment. You really don’t want to accidentally fill up that limited space you have!
This leaves few authenticator types which will work properly in this passkey world. Apples own passkeys, Android passkeys, password managers that support webauthn, Windows with TPM 2.0, and Chromium based browsers on MacOS (because of how they use the touchid as a TPM).