I’m starting to see sites offering passkeys. There’s a good explanation at this link of what passkeys are, how they work, and why they’re even better than passwords with two-factor authentication.
If you’ve begun using passkeys, what has been your experience?
I use passkeys whenever available and so far very few problems. I save them in 1Password which I’ve used for about 2 years. Passkeys are more convenient and safer but they’re most convenient when using the phone rather than web. Still plenty of places use 2-factor and they almost all allow the use of an authenticator app for the 2nd factor rather than email or text. I expect the shift to passkeys will take several years but will continue since passwords alone are so weak and many people can’t handle 2-factor.
I use face id on apple devices as I figure it is at least as secure as a password.
I use 1password for non financial sites. Lastpass got hacked so I switched
I am very worried about. security on financial sites, and I suspect we will not hear if Schwab or Fido gets hacked.
Isn’t it interesting that Schwab seems to have dropped voice ID? maybe too easy for AI to crack?
I’ve used them, so-so, if you stay inside an ecosystem (like FaceID on my iPhone) it’s fine. When Apps start trying to use it, not always success. When I’m on a browser on my laptop, heavy failure rate (it just kicks me back to password).
Isn’t it preferable to have 2FA, as multiple hurdles tend to work better than the all the eggs in one basket approach. (are they really asking us to trade security for convenience)
What happens if you have an accident and your fingerprint changes or your face changes, do you suddenly lose access? Or is it sophisticated enough to work around these challenges.
Last, what’s the compelling interest of the developers? Is this something they’ll give away until it eliminates competition and then charge $11.99/month? If they posted that they were committed to keeping it free in perpetuity I’d be more excited.
Thank you for your comment. That’s a lot for me to explore — which I will.
Could you give one or more examples of an app that kicked you back to your password?
As for two factor authentication, it so often relies on phone call or text that I worry about the phone getting misplaced, stolen, or hacked.
On another note, passkeys are actually meant to be not only more convenient but also more secure than passwords, since even if the site’s portion of the passkey were stolen in a hack, it would be useless without your device’s stored portion of the passkey plus your personal verification (e.g., face ID, touch ID, device startup passcode), and you could then just set up another passkey at the site.
Would you believe them? Remember “do no evil”?
I also fail to see how it would work on my desktop, which is what I use for my finances.