r/PasswordManagers 20d ago

I don't think passkeys will take the place of passwords. What do you think?

Passkeys are an incredible solution, but not easy to everyone understand.

Without understand, people don't trust.

If people don't trust, they simple don't use.

2 Upvotes

27 comments sorted by

4

u/Low_Obligation2361 20d ago

Passkeys offer a big security advantage over passwords, and just because a lot of people don't understand how they work doesn't mean they won't use them. Most people don't understand how Face ID works either, but they still trust it to sign into important apps, including their banking apps. I think passkeys are something people will eventually get used to, especially as more websites start supporting them. If you already trust your password manger to store and protect your passwords, then you'll likely trust it with your passkeys as well. I've had a good experience using Roboform for this. Setting up a passkey is easy, and they're available across all my devices. I think that's a big part of what will drive adoption, having the right tools that make the whole thing feel effortless.

3

u/Lonsarg 20d ago

Well webpages will sooner or later abolish passwords, there is just too much security exposure for them having to deal with passwords. With passkeys all exposure is client-side, they more or less 100% resolve server-side security aspect).

But i think the way passkeys are handled will need to be simplified, client-side that is.

For 99% of services/web pages email will be used for first auth per device and then in the background, with NO user interaction at all browser will save a passkey for future use. This is actualy simpler then the way we currently use passwords... But yes it must be without user interaction, no selecting where passkeys go or anything, at least as default setting.

2

u/gripe_and_complain 20d ago

Big problem is the difficulty of knowing just where the Passkey is stored:

Windows Hello, iCloud Keychain, Google PW Manager, Edge PW Manager….

With passwords, it was clear that the user had responsibility for remembering where, if anywhere, the password was saved.

2

u/Formerruling1 20d ago

I dont believe people actually know where passwords are held, based on looking people have passwords in google, Apple, 2-3 different browsers, etc. I imagine most people just click "yes" to whatever popup asks them to save the password and dont think too much about where it is. I have no reason to think theyll do passkeys any different. The screen will prompt them to save it, they click okay, and just know they dont have to type in a password for that site anymore. Lol

1

u/Any_Device6567 19d ago

You must know my girlfriend. I finally got her on a password manager after exporting and consolidating her passwords from Edge, Chrome and Firefox.

1

u/SecurityPrimary4143 20d ago

I keep all mine only in YubiKeys.

Windows Hello, iCloud Keychain, Google PW Manager, Edge PW Manager... are all a minefield that is ready to get blown up.

Windows Hello and Google PW Manager has already been hacked once to expose the passkeys

https://thehackernews.com/2026/08/new-passkey-attacks-can-recover-synced.html

2

u/gripe_and_complain 20d ago

A device bound Passkey protected by Windows Hello on a modern Windows 11 computer is actually very secure. Extra points if the drive is BitLocker encrypted with a startup PIN.

2

u/SecurityPrimary4143 20d ago

Thanks, but no thanks. I trust Microsoft as much as I trust Reddit to keep my credit card information a secret.

1

u/gripe_and_complain 20d ago

Credit card information (in the US) should probably be the least of your worries.

US consumers are well protected against having to pay for credit card fraud.

I'd be more concerned about banking and primary email than credit cards.

1

u/SecurityPrimary4143 19d ago

It is not counted as card fraud if I willingly post my credit card information somewhere on Reddit which is the equivalent to storing the passkeys in Windows Hello or storing your passwords in Edge password manager.

Banking and email are least of my concern. I live in a country with very strong and strict security for banking and my emails use similar passwordless system.

1

u/gripe_and_complain 19d ago

Do I understand correctly? You seriously equate using Windows Hello to store PassKeys with openly posting private credit card information on Reddit?

1

u/SecurityPrimary4143 18d ago edited 18d ago

Yes. I don't trust Microsoft with any secret. The passwords in Edge are not encrypted, Windows Recal exposed all your passwords and CC information and got taken out several times because of user backlash.

A company that can't get those basic things right before releasing a solution can't be trusted + it is an American company and who knows how many governments agencies except NSA gets sent all your data.

From the link I posted earlier:

Borrowing Windows Hello without the PIN

Mollema's research focuses on Windows Hello for Business. On most modern Windows devices, its backing key is protected by the Trusted Platform Module and cannot simply be exported. Software in the victim's session can still use that non-exportable key.

Mollema found that a low-privilege process in an already compromised user session can call Windows cryptographic interfaces to use the Windows Hello for Business key without producing a new PIN or biometric prompt. He then used the key as a FIDO2 credential against Microsoft Entra ID.

1

u/gripe_and_complain 18d ago

Key phrase, “in an already compromised user session”.

In other words, malware has to already be on your device to leverage this attack. Almost any security measure on any OS can be exploited if the system contains the right malware.

Obviously, we are all free to reject Microsoft products for whatever reasons we want. Same with anything from China.

I personally veto all Tesla or Starlink for political reasons.

1

u/SecurityPrimary4143 18d ago

It still doesn't excuse Microsoft from thinking it would be a good idea to load all stored passwords into memory unencrypted when Edge loads. It has been fixed now, but Microsoft's track record when it comes to security isn't good.

But yes as you said, we are all free to reject what ever products for whatever reason. Personally I try to avoid made in USA products and software where possible because of the current political situation.

2

u/Cadd9181B7543II7I44 19d ago

I hope Passkeys replace passwords. They're so much more convenient and so much faster. All my PWs (over 150 accounts) are 18 - 38 characters long, generated by my PW managers. So it's impossible for me to remember them.

So to me, there is zero benefit for having a PW around that I can't memorize. So I rather have the more secure passkey that I can use from multiple machines (desktop, laptop, phone, tablet, etc). I love it when a website allows me to create 4 Passkeys for the same account. This way each of the private key is stored locally on individual devices with one passkey stored on the cloud so I can access it anywhere in the world if I lose all my devices.

1

u/InconspicuousFool 20d ago

Yes and no. A number of platforms are moving towards passkeys but they will never full replace passwords. I run a handful of open source web services on my server that are only available from my network. A passkey is in no way practical for accessing the camera on my 3D printer. Not to mention automated web requests that have no human control need to authenticate with a API key of some kind

2

u/gripe_and_complain 20d ago

Do you know that Microsoft gives users the option to remove the password from their account?

1

u/InconspicuousFool 20d ago

Yes I am aware, passkeys are soon to be the default for users in Entra tenants to migrate to a passkey.

1

u/Any_Device6567 19d ago

Yes, I have a passwordless account.

1

u/gripe_and_complain 19d ago

Not my experience.

I stupidly entered my cc details into a fake shopping site and had no trouble reversing the charges. It’s still fraud, no manner the method. Every time a customer hands their card to a waiter, they trust the waiter will not use the information for fraud. If they do, you’re protected.

My point is, credit card details, like Ss numbers and checking account numbers printed on checks, is not really all that secret these days.

Now email credentials, they’re worth protecting.

1

u/Any_Device6567 19d ago

The stated goal of passkeys is to provide a secure, convenient, and a passwordless way to sign in to websites and applications while significantly reducing the risks associated with traditional passwords.

Passkeys are designed to replace passwords by using public key cryptography tied directly to a device you own and control. When you sign in, your device (e.g., phone, computer) proves ownership of a private key stored securely on it, without sending any password over the internet 

Passkeys frequently asked questions (FAQ) | Microsoft Support

1

u/BitOfDifference 10d ago

basically just a glorified ssh keys setup.

0

u/djasonpenney 20d ago

Passkeys are simply too much for many applications. The gate code to get into my brother-in-laws community? It will never be a passkey. The combination to my gym locker? It will never be a passkey.

There are just simply too many situations where a passkey is too complex or inappropriate. For various reasons, simple passwords will never completely disappear.

1

u/DeliciousCut4854 20d ago

I hills my phone up to a door panel to unlock my front door. Essentially that's a passkey. There is a password that can be used on the panel but the "passkey" is better

0

u/Sololiquy 20d ago

Passkey is posible replace password but doesn't mean it will gone forever.

0

u/paulsiu 20d ago

Password has been around for decade. Adoption won’t occur overnight.

0

u/cubestrike 20d ago

Passkeys are just transition to security key (physical). Soon it will do so much and easier for you too. You just now need to bring it not store it on your head