Back
I don't like passkeys: why the ecosystem isn't ready for personal accounts
SiTech AI Team3 წთ. საკითხავი

I don't like passkeys: why the ecosystem isn't ready for personal accounts

The industry presents passkeys as the final answer to logging in, but permanent lockout, automated bans and device loss remain the biggest day-to-day risks for individuals, writes Ethan Hawksley.

For the past few years the tech industry has pushed passkeys as the ultimate solution to logging in. Big Tech companies remind you at every sign-in how much easier they are, and the only way to stop the prompts is to either set up a passkey or dig through settings for the off-switch. Google names its setting "Skip password when possible", while Microsoft advertises passwordless accounts, writes Ethan Hawksley on his blog on 18 September 2026.

The technology itself is strong: passkeys are bound to the site they were created for, so a fake login screen cannot phish them, and because they are asymmetric, a server-side breach does not expose enough to recover them.

Corporate fit, personal mismatch

That makes passkeys a perfect fit for a corporate environment and a poor fit for personal security, the author argues. For an individual, the greatest risks are permanent account lockout, automated account bans and device loss. Passkeys eliminate phishing in the standard login flow, but they create a false sense of security: an account is still only as strong as its weakest recovery method, whether that is SMS, email links or security questions.

The limits of hardware keys

By design, you cannot back up a passkey on a hardware key: keys can only be added or deleted, never moved. In practice that means buying two or three keys and enrolling every one of them on every site. Discoverable credentials are limited to roughly 25–100 accounts per key, and even top-of-the-line keys cap out around 300; once you hit the limit you must delete accounts or buy another set of keys.

Synced passkeys and lock-in

Apple and Google both want your identity anchored to their operating systems. If their automated systems ban your account one day, you irreversibly lose access to every passkey you used across third-party accounts. The FIDO alliance is working on interoperability and easier export, but the experience is still fragmented and inconsistent across providers — too immature to rely on. A password, by contrast, is just a string you can export by hand.

What the author recommends

Signing in on someone else's computer is where passkeys get inconvenient: you may not have access to the ports for a hardware key, and a synced passkey means trusting that machine not to leak your other credentials. Hybrid Transport, which pairs a QR code with a Bluetooth connection, is secure in theory but plagued by edge cases and sometimes unsupported Bluetooth.

Hawksley concludes that enterprise users have good reason to use passkeys, but the ecosystem is not mature enough for individuals. His recommendation is randomly generated passwords kept in a third-party password manager, paired with an independent TOTP app. For people who previously reused passwords everywhere, passkeys are a huge step up; for everybody else, they are currently a step back.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.