Skip to content
Tech News
← Back to articles

I don't like passkeys

read original get YubiKey 5C NFC Security Key → more articles
Why This Matters

This editorial pushes back on the tech industry's aggressive promotion of passkeys as a login panacea, arguing they trade phishing resistance for higher risks of permanent lockout for everyday users. It matters because companies like Google and Microsoft are nudging or defaulting users into passwordless setups without fully addressing recovery and hardware-key scaling issues.

Key Takeaways
Worth a Look

YubiKey 5C NFC Security Key — If you're wary of relying solely on device-bound passkeys, a hardware security key like the YubiKey gives you a portable, durable backup for your passkeys and two-factor authentication. It works across many services and platforms, so you can keep phishing-resistant login security without worrying about losing access if your phone dies. It's a practical way to hedge against the account lockout risks discussed in the article.

See YubiKey 5C NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

For the past few years, the tech industry has kept pushing passkeys as the ultimate solution to logging in. Many Big Tech companies “helpfully” inform you every time you sign in how much easier and effortless passkeys are. The only way to make them stop is either to concede and set up a passkey or dig into the settings to find the off-switch.

Google goes as far as to name the setting “Skip password when possible” (opens in a new tab) , and Microsoft advertises that you should make your account passwordless (opens in a new tab) .

Passkeys are a fantastic technology. Since they are bound to the site they are created for, they cannot be phished by a hacker’s fake login screen. If a site suffers a data breach, passkeys are asymmetric and cannot be recovered from the server-side details.

This leads to passkeys being the perfect fit for a corporate environment, but a poor fit for personal security. To an individual, the greatest risks are instead permanent account lockout, automated account bans, and device loss. By using passkeys, you gain better security against man-in-the-middle attacks but face the higher probability scenario of losing access to your accounts.

Phishing through the standard login flow is eliminated by passkeys, but it creates a false sense of security. An account’s security is still dictated by the weakest recovery method: SMS, email links, security questions, and so on. If these recovery methods aren’t enabled, then the risk of permanent lockout remains for the user.

Hardware keys

By design, you cannot create a backup of passkeys on a hardware key: passkeys can only be added or deleted but never moved. Instead, you need to purchase 2-3 hardware keys and enroll every key for every site. This can quickly get expensive and doesn’t scale well as the number of accounts starts to grow.

Hardware keys support discoverable credentials, where websites can query for your username instead of you typing it in. These are becoming increasingly popular amongst website developers, yet have limits of 25-100 accounts (opens in a new tab) per hardware key, and top of the line keys can have up to 300. Once you exceed the limit, you must either delete some accounts or you have to buy another set of hardware keys.

Synced passkeys

Both Apple and Google want your identity anchored to their operating systems. The “happy path” on their devices is to use their synced passkey management tied to your Apple or Google account. If their automated systems decide one day to ban your account (opens in a new tab) , you irreversibly lose access to all your passkeys used across all third-party accounts too.

... continue reading