Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> No. Don't forget your password. Why would you?

Because passkeys are replacing my password, right? Also, I think if I don't ever have to provide it on a regular basis, I'll eventually forget it.

> Use your password. Or if you can't use it use the "I forgot my password" process.

Why should I use passkeys then if I sometimes need my password anyway?

> They can try if they have this question.

Ok, I tried it and it doesn't work. Is that my fault or the site's? I'm confused – will your support be able to help me out?

> Nor did I think about these questions ever since even once.) So I would suspect worrying about these questions is not the primary reason why people use or don't use passkeys.

These concerns aren't about people not using passkeys, quite the opposite: They're about sharp edges that people usually only hit months or years into using a new authentication method.



> These concerns aren't about people not using passkeys, quite the opposite

The person who I responded to said:

“this stuff is hard to explain to end users. This is the reason it's not widely used yet even on the handful of platforms that provide this option.”

They clearly think “hard to explain” is the reason why they are not more popular. That is what i responded to. You are making an orthogonal point about trickyness of account recovery. (One i largely agree with, but has nothing to do with the ease of explaining passkeys)


I'm not sure "fall back on the existing method" is really an explanation though. It's like saying, "stick shift is easy to explain, whenever you're confused just switch back to standard."

Passkeys are meant to be a password replacement. "Use your password" can't be the answer to "how do I do X with passkeys"? We're talking about onboarding people onto a separate system, they're going to want to know why they're being asked to use two systems simultaneously.


I wouldn't say these are orthogonal.

Platform operators do think about support load and edge cases like the ones I've mentioned, and so to them these are obstacles to deploying passkeys. "How can I explain passkeys to my user?" covers more than just the happy path.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: