Passkeys Spark Debate: Engineers vs Consumers on Usability and Security

Passkeys Spark Debate: Engineers vs Consumers on Usability and Security

Overview

The conversation began with a tweet claiming that passkeys were invented by security engineers who lack understanding of how consumers think, leaving users to produce "magic fairy dust" to log in to apps. This statement sparked a lengthy comment thread on Hacker News where participants shared personal experiences, confusion, and occasional praise for the technology.

Confusion and Usability Concerns

Many commenters said they do not understand how to use passkeys across their various devices and browsers. One long‑time engineer noted that he accesses sites from an iPad, iPhone, Windows desktop, and MacBook Pro, each with multiple browsers, and worries about whether a passkey created on one device will work elsewhere or how many passkeys can be registered for a single site. Another user described the process as a "nightmare" if a device is lost, questioning whether a unique passkey is needed per device and how to rotate or recover them. A commenter summed up the sentiment by calling passkeys "magic fairy dust" because the underlying mechanism is not explained in a way that feels tangible.

Benefits Reported by Some Users

Despite the confusion, several users reported positive experiences, particularly within a single ecosystem. An Apple‑ecosystem user said that setting up a passkey on Amazon allowed them to sign in on Mac or iPhone with Touch ID or Face ID, describing it as zero friction and life‑enhancing. Another commenter noted that using a password manager such as 1Password or Bitwarden made passkeys feel like a "just works" system, eliminating the need to type or copy‑paste passwords and providing resistance to phishing.

Cross‑Device and Backup Challenges

A recurring theme was the difficulty of moving passkeys between devices. Some users pointed out that early implementations were device‑bound, meaning a passkey created on a Windows PC could not be used on Linux or macOS without additional steps. Others mentioned that relying on a password manager for cross‑device sync introduces a different kind of lock‑in and raises concerns about vault security. A commenter highlighted that if a password manager vault is compromised, the passkey protection offers no added benefit over the existing password‑manager model.

Vendor Lock‑In and Ecosystem Issues

Several participants argued that passkeys favor users who stay within a single vendor’s ecosystem (e.g., Apple or Google) and create friction for those who mix platforms. One user described the experience as being optimized for people who "just press the button that the screen tells them to press" and live inside a closed ecosystem, warning that leaving that ecosystem would break authentication. Another noted that the lack of a clear, standardized way to share passkeys with family members (e.g., for shared Amazon or Pandora accounts) makes the technology impractical for households that share credentials.

Security Perceptions

Opinions on security were mixed. Some commenters welcomed the phishing resistance of passkeys, comparing them to SSH keys and emphasizing that the private key never leaves the authenticator. Others countered that the security gain is minimal when a password manager is already in use, because compromising the vault yields the same result as stealing a password. A few warned that passkeys could be used to enforce vendor lock‑in and facilitate broader digital‑ID initiatives, suggesting that the technology serves corporate interests more than user convenience.

Summary of Sentiment

The thread reveals a split: users who have adopted passkeys within a unified ecosystem and paired them with a password manager tend to find them convenient and secure, while many engineers and multi‑device users express frustration over unclear workflows, backup complexities, and perceived lock‑in. The discussion underscores that the usability of passkeys remains a significant barrier for a broad audience, even as the technology offers certain security advantages.

Sources