I jumped on the bandwagon of passkeys. Since then everything has been a pain in the butt. Passkeys only work with the device they’re created on. Password managers require their app to be the default password manager for your browser for the passkey to work. And even when all that’s set up anything can mess up this functioning.
I’ve had the opposite experience. Whenever I have the opportunity to use passkeys I do. Makes signing in just a quick TouchID and then I’m done. Might be easier for me because I’m fully in the Apple ecosystem, so I’m using Passwords and Safari.
Yes, I am using a KeePass vault and my apps are Strongbox on Mac/iPhone/iOS and KeePassXC on Windows. It works as good (or bad) Passkeys do work/not work.
I got email this morning that Microsoft is making big steps to reduce phishing. The weak spot is SMS and voice authentication. So they will be dropping it completely (in three weeks!) and forcing everyone to move to Passkeys. This is for all Microsoft Entra ID tenants (formerly Azure Active Directory). From what I understand they are also actively phasing out SMS codes for personal accounts as well.
And if MS is doing this, everyone else will be too, soon (and already are).
Resist while ye may, but I think your days are numbered until passkeys envelop you in their cold, sweet and oh-so-secure embrace!
In clamshell mode I have to click or enter my system password to unlock 1Password, but still pretty quick. Same on my Android phone. I really do love Passkeys.
Interesting how password managers will soon be just passkey managers. Still a valuable function, but soon it will be password-free!
Passkeys have not fulfilled their pre-launch promise. I find the use cases to be a bit too variable and slower than a simple password authentication method. I’ve noticed some improvements but it’s still an inferior workflow IMO. So many new technologies sound great but fail to stick the landing.
FWIW, I can create a passkey in 1Password that is useable on all my devices. Including my Mac which doesn’t have any form of 1PW installed.
I know some will not use a server based PW manager, but due to a Windows vulnerability “Server-stored passkeys are now the design used not just by GPM for Windows, but 1Password, Dashlane, and other third-party apps for the Microsoft OS as well.”
I don’t have 1Password installed on my work computer. Typing a (secure, unique, long, random, …) password is a major PITA. Scanning a QR code with my iPhone to log in with a passkey is much easier.
And safer as well! I’m always afraid work computers might capture anything you type (including those passwords), which they can’t with passkeys.
This would still leave the Microsoft Authenticator, so there’s no mandate to use Passkeys yet. But the UK’s NCSC has recently strengthened it’s advice that businesses should use Passkeys where possible, this will inevitably be enforced within government departments.
@svsmailus I still don’t believe that Passkeys are implemented in a universal way, but my understanding is that If you save a Passkey to 1password it can be used on any device that 1Password is sync’d to.
I’ve only started using passkeys in earnest this summer, but it’s been a good experience with 1Password. It does feel weird to use authentication I can’t really copy-paste to use.
When developing support for passkeys in applications, it’s important to try the flow a bunch of times and have good support for managing multiple passkeys and showing enough information about how they were saved and if/when they’re used. Email sign-in code plus passkeys, no other options, is my preferred auth implementation.
I’m sorry using passkeys has been such a difficult experience for you. I can feel the frustration just reading your post. My own experience has been good, and like some others, I’ve been using 1Password. When the passkey system works right, it’s so much better than using an authenticator or SMS code. Now, it’s annoying when someone posts about a terrible experience with something, and so many responses tell you how great their experiences have been. I’m not sure what services you are using (Apple’s, another password manager, etc.), but maybe give it a few months and give passkeys another shot. if not, maybe authenticator apps are a good answer.