I don't like passkeys

Passkeys, the proposed replacement for passwords that ties logins to devices and biometric prompts, are provoking strong reactions as major platforms like Apple, Google, Amazon and PayPal push them more aggressively. Many see clear security gains against phishing and password reuse, especially for less technical users, but worry about account lockout, confusing UX across devices and browsers, opaque storage and backup, and increased dependence on big vendors’ ecosystems and recovery flows. Several commenters argue that for individuals, well-managed passwords plus 2FA or hardware keys remain more understandable, portable and failure-tolerant than today’s fragmented passkey implementations.

Perceived benefits of passkeys

  • Strong protection against phishing and fake sites due to domain‑bound, asymmetric credentials.
  • Prevent password reuse and weak, guessable passwords, especially for “normie” users who don’t use password managers.
  • Good UX when it works: one‑tap/biometric login, no codes to type, no password autofill quirks.
  • Work well for some when stored in modern managers (1Password, Bitwarden, KeePassXC) and synced across devices.
  • Seen as an excellent fit for corporate environments where IT can provision and recover credentials.

Usability & recovery concerns

  • Biggest fear: permanent account lockout after device loss, damage, theft, or account bans on Apple/Google/MS.
  • Many users (especially elderly or non‑technical) don’t understand where passkeys live or how to recover them.
  • Scenarios like travel, robbery, house fire, or using a shared/public computer are frequently cited as problematic.
  • Sync and QR+Bluetooth “hybrid transport” flows are perceived as brittle, inconsistent across OSes/browsers, or unavailable on locked‑down/public machines.
  • People report accidental enrollment via naggy dialogs, then confusion and lockouts later.

Hardware tokens vs synced/software passkeys

  • Some strongly prefer hardware keys (e.g., YubiKey) as independent of big vendors and conceptually simple (“like a physical key”).
  • Major drawback: you can’t easily copy/backup tokens; you must enroll all tokens with every site, which is tedious and unrealistic for most.
  • Limited credential slots on some tokens and no standard backup format are seen as design failures.
  • Others dislike carrying extra hardware or note that tokens don’t work well with containerized/remote environments.

Ecosystem lock‑in, attestation, and freedom

  • Concern that Apple/Google/Microsoft use passkeys to deepen ecosystem lock‑in by tying identity to their cloud accounts and sync.
  • Fear that device attestation will let sites force specific platforms or non‑rooted devices, undermining user choice and open‑source managers.
  • Some explicitly avoid passkeys or plan to “lie” about hardware status if attestation becomes mandatory.

Passwords, 2FA, and alternatives

  • Many argue that unique, manager‑generated passwords + TOTP or hardware 2FA already solve most problems without new risks.
  • Others hate magic‑link email logins and SMS codes more than they dislike passwords or passkeys.
  • Consensus that security is ultimately capped by the weakest recovery path (email/SMS/helpdesk), regardless of passkeys.

Implementation & UX quality

  • Wide frustration with nag screens (Amazon, PayPal, Microsoft, etc.), unclear flows, and inconsistent support for third‑party managers.
  • Some say passkeys “are great in theory, bad in today’s implementations”; others report completely smooth experiences and want broader adoption.