HN
Today

Passkeys were invented by engineers with zero understanding of consumer brain

Nikita Bier's tweet ignited a fiery debate on Hacker News, claiming passkeys were designed by engineers who forgot real users exist, creating an unnecessarily complex login experience. Commenters wholeheartedly agreed, airing grievances about cross-device compatibility, vendor lock-in, and the baffling UX that often makes logging in harder, not easier. The discussion underscores a fundamental tension between robust security architecture and practical, user-friendly implementation in the tech world.

123
Score
151
Comments
#13
Highest Rank
6h
on Front Page
First Seen
Jul 22, 3:00 PM
Last Seen
Jul 22, 8:00 PM
Rank Over Time
151317182222

The Lowdown

The Hacker News story revolves around a provocative tweet by Nikita Bier asserting that passkeys were conceived by security engineers with "zero understanding of the consumer brain," resulting in a confusing and poorly adopted login method. Bier claims the lack of clear communication on passkeys' merits has left users feeling they need "magic fairy dust" to log in, despite the underlying security advancements. It highlights the disconnect between the robust cryptographic principles behind passkeys and their often cumbersome real-world implementation.

  • The tweet, though brief, struck a nerve with the Hacker News community, many of whom are technical professionals.
  • It highlights the disconnect between the robust cryptographic principles behind passkeys and their often cumbersome real-world implementation.
  • The author posits that the difficulty in understanding and using passkeys will hinder their widespread adoption, regardless of their security benefits.
  • The implied critique is that focusing solely on security features without considering user psychology or practical workflows leads to solutions that fail in the wild.

This critique resonated deeply, prompting a cascade of comments detailing personal frustrations and architectural concerns that reflect a broader unease with the current state of digital authentication.

The Gossip

Usability & Portability Puzzles

Many users, including long-time tech veterans, expressed significant confusion regarding passkey usage across multiple devices (phones, laptops), browsers, and operating systems. Key concerns include the inability to easily transfer passkeys, manage them for shared accounts, or understand how to recover access if a primary device is lost or broken. The perceived complexity often drives users back to traditional passwords and managers.

Vendor Lock-in & Control Controversies

A prominent theme is the fear that passkeys, particularly through features like device attestation, are a mechanism for major tech companies (Apple, Google, Microsoft) to exert greater control and enforce vendor lock-in. Critics point to the "naughty client" list, which might block open-source or non-mainstream passkey providers, forcing users into specific ecosystems. This raises questions about user autonomy and the open nature of the web.

Security vs. Simplicity Showdown

While the cryptographic security of passkeys against phishing is generally acknowledged, many commenters argue that this benefit comes at a steep cost in terms of user experience and understanding. The debate often questions whether the security gains are truly significant for users already employing strong password manager hygiene, especially when passwords often remain a necessary fallback. Some see passkeys as "security theater" if they merely shift the attack surface or introduce new complexities without eliminating old vulnerabilities.

The Password Manager Paradox

The role of third-party password managers (like 1Password, Bitwarden) in bridging the usability gap for passkeys is a double-edged sword. While they offer a way to manage and sync passkeys across devices, they also introduce new dependencies and potential points of failure. Concerns include proprietary implementations, the inability to export passkeys from some managers, and the ongoing struggle for cross-platform compatibility without cloud-based synchronization or vendor-specific integrations.