Hacker Newsnew | past | comments | ask | show | jobs | submit | cfiggers's commentslogin

Imagine a password, but it a) types itself for you and b) detects when it's being sent to an impostor site and blocks them from seeing itself, so it can't be phished.

Tada, passkeys.


Cool, where are they stored? (I know the answer: 'it depends', and that's the big problem with their usability: most users haven't a clue what the answer is and most tech support can't answer that question straightforwardly because it depends on some decisions the user probably didn't even realise they made).

On my keychain in a USB hardware token. With a couple of backup tokens in fire safes.

If you're using a USB hardware token your knowledge of it is at least an order of magnitude better than the median user's. I know where my passkeys are stored, I don't know where my family member's passkeys are stored and neither do they. The same is true for most of my otherwise fairly technical co-workers.

There needs to be industry and government leadership on this to gradually require hardware token usage, for at least critical financial and government applications. Right now everyone is putting their energy behind passkeys, but those are much harder to understand than a physical token. I don’t know any non-technical people who understand how passkeys are normally tied to the device (or the manufacturer-provided cloud account in some cases), how to set them up on a second device, why you might want to do that, etc. And many technical people still don’t get it either!

Absolutely not. If that is required, I will do my damndest to only use implementations that deliberately lie about the hardware status. Your line of reasoning is dangerous.

Then that family member does not worry like you do worry. The main point is assuming one can have a proper security for Google account - everything else becomes easy.

The fearmongering of losing google account should stop. Yes, some people lose it. There are a larger proportion losing/getting pwned by repeat use. For the majority - just pressing the fingerprint to access an account (like amazon/eBay) via passkey is great.

Fairly technical co-workers - I used to suggest them to buy USB security key few years ago. Now that same fairly technical some how has at least 2 devices with them - so they just skipped the USB security key need - and just use Google (in Android) or iPhone in Apple ecosystem. Everything just works.

Yes, there will be a poor soul that may lost everything with only one device.


People keep their entire lives in cloud accounts these days. Their passwords, financial history, copies of important documents, baby photos, etc. Losing access to it is incredibly disruptive and may result in unrecoverable losses.

It shouldn’t be this way, but it is.


At the same time, I know so many people believing DIY raspberrypi based NAS and losing lots of data (thankfully they had cloud backups).

Not everyone has access to server grade hardware.


>Then that family member does not worry like you do worry.

Until they lose access to that account and then it becomes my problem to solve.


This is a different issue. Not everyone has a data engineer - know it all as a family member.

And you need to accept it works for millions.


Working for millions doesn't imply a good hit rate. Google could release a feature that worked 1% of the time and manage that, as well as barely noticing if it wipes out 10% of their users. My actual experience is that almost all the people I know who are using passkeys are using them by mistake and it's only not a big problem because they aren't currently being used up to their promise of preventing the vulnerable authentication methods.

My actual experience is people with passkey are fine. No more account take over. Mote over they like frictionless login.

Yes there are few that used bitwarden and lost everything as their sync using syncthing failed.


The biggest issue with passkeys is that since most USB tokens that support them don't allow syncing the private key to a backup device you have to enroll ALL of them to every site that supports passkeys. This is annoying but it makes storing backups in secure offsite locations impractical.

This is a fair criticism and needs work, I have some short thoughts on it here: https://news.ycombinator.com/item?id=49755217

The entire problem with passkeys is that zero of the issues should have been a surprise, because it should have been part of the design discussion from the start, so the fact that it's not properly implemented before being forced on users says that either it's been done horrifically incompetently and nobody should trust it, or they internally found these concerns and ignored them which means this system is not at all meant to help us, so why is it being forced on us?

It's beyond annoying. It's creating needless toil that no "normies" will ever actually do.

I'd love a hardware sold in multi-packs and "born" at the factory with identical internal device key encryption keys (DKEK). I'd love, even more, if a token just allowed you to "commission" new ones w/ a user-specified DKEK on first use.

I'd use one token as a daily driver and store the other(s) in safe location(s), empty of my personal key material. (Or, if I can just commission a new token w/ my DKEK, store a printed copy of my DKEK in a safe location.)

Give the token a mechanism to "type" a backup of its internal state, encrypted with the DKEK, as a USB HID keyboard. That gives me an easy way to backup the token each time I enroll a new website.

If I lose my daily-driver token I just pull a spare from storage, import my last backup, and I'm up and running.

That would kick ass. No "You just need to buy two tokens and enroll them in every website" bullshit.


Maybe each token also needs a second key, with the DKEK used for authentication and the second used only for revocation. The main reason not to reuse the DKEK is so a lost key can be easily decommissioned.

You would need some out of band way to collect and save your key IDs and publish revocations.

I’m not sure if this would work from a security theoretic perspective, need to think about how the request is signed and transmitted so someone can’t fake a key being “alive” when it’s really “dead”.

I do agree this would be incredibly useful if it can be made to work.


I haven't used a FIDO2 token other than playing around with it on a Yubikey. There, at least, I have to have the PIN to unlock the Yubikey before I can use the FIDO2 credentials (if I'm remembering correctly).

Are there hardware token implementations where mere possession of the token is all that's necessary to use the passkeys stored on it? That's incredibly stupid, and should have been disallowed by the standard, if that's the case.


Yes, the PIN is optional even on Yubikeys, although I think individual providers can require it. Ideally a strong PIN should be used but people may just reuse their ATM PIN, birthday, etc.

I didn't realize PIN was optional.

See my other comment re: the IT industry being fools.


That is how almost all standard FIDO2 tokens work. You just have to press the capacitive sensor when prompted. You can get fancier biometric tokens that require a fingerprint.

That's the stupidest thing ever.

All this hullabaloo taking away user freedom to export keys and backup tokens but physical possession is all that's necessary to use it by default.

We are a ship of fools, the IT industry.


In a secure vault on your phone

How do I use it on my desktop or laptop then? What if I switch browsers on my phone? What if I get a new phone? What if I change from android to iOS or visa versa? What if I need to log into the site on my Wii U's browser?

>How do I use it on my desktop or laptop then

>What if I switch browsers on my phone

>What if I get a new phone

You can let Apple sync your passkeys between devices using iCloud Keychain. Then you can create a passkey on one device and have it available on all of your devices. Google also syncs passkeys to the cloud and lets you use them on Windows (with Chrome)

>What if I change from android to iOS or visa versa

I resolve this by storing most of my passkeys in my password manager. I still store the "important" ones (like online banking) in my phone so a password manager breach doesn't make me lose my money.

>What if I need to log into the site on my Wii U's browser?

Passkeys were designed to let you have more than one, so if you have a device that doesn't let you use your password manager, then just set up another passkey.


Nothing wrong with your answer itself, but having to be Apple or Google is a PITA. These account are ultra critical already and you will want maximum security to access them.

This means if you go on a trip somewhere you absolutely need two devices. If you kill your phone and want to buy another one ASAP, you wont be able to do anything with the new device until you can convince the platform it's you. With passkeys you're just SOL. Imagining if you needed a phone to get back from your trip - e.g. etickets, auth needed etc. - it becomes a nightmare scenario.

A third party manager makes it easier, but it's a lot less usable that the first party ones.

Reasonable people make different life choice, having to constantly think about backup strategies whenever I'm away from home would be so stress inducing to me.


  > With passkeys you're just SOL.
No more so than if you lose access to the device that's required for Google/Apple MFA prompts, neither of which use SMS and depend on a proprietary approval flow.

If you lose your phone in 2026 while on a trip to Italy and try to enter your Gmail user/pass from your wallet, there's about a 100.00% chance you'll hit a "let's verify you're you" gate, that's been the case for 5+ years.

With passkeys I'm not stuck clicking Yes in the Gmail app or typing in the numbers on Apple hardware, I can skip the Apple/Google specific MFA nonsense and keep the passkeys in Bitwarden where they sync seamlessly between devices.

It feels truly liberating being able to skip MFA everywhere and login with 1 click, like a throwback to the golden age of using a password manager in 2010. Before passkeys it started to feel like I was spending 5% of my waking hours every day copying 6 digit codes from phone/email/TOTP after twiddling my thumbs for 15-30 seconds.


>This means if you go on a trip somewhere you absolutely need two devices

If you want multi-device redundancy, you have to carry a second device of some type, it's hard to get around that. I almost always travel with an iPad in addition to my phone, so I have a second device.

In addition, my wife (who travels with me so if my iPhone is stolen, hers might be too) is one of my Apple account recovery contacts, plus I've set my sister as an addtional recovery contact, so even if I'm out of the country and I have to activate a new iPhone, I can call her to help with the recovery. So all I have to do is find an Apple store and buy a new phone.

I also carry a USB key tucked into my luggage with the recovery kit (encrypted) for 1Password so I can activate 1Password on any new device and have access to my passwords and whatever passkeys I don't have in iCloud.


I just don't use Google or Apple accounts for everything. I don't want my whole life in the hands of some big tech deciding how I should prove to them that I'm me.

I did use Microsoft 365 (business version) for my email but they also decided I should use their MFA app so I left. I did have my yubikey as second factor but they keep pushing their stupid authenticator app.


Apple can sync to my wii u?

I updated my reply to be more complete.

as long as you have one working device all will be OK. Either you scan the QR code shown by the website. or if you did login to Chrome with google account then desktop or laptop will just sign you -friction less. Same with iCloud account.

If you browser vendor has implemented passkey then all good.

Most things are built for the majority users. Most don't change. Most don't debate browser wars in hn. Life is like that.

For Wii etc. You just scan the QR code shown in the TV interface. all just works.

Yes, if you want 100% privacy and will do only your own dovecot server then it is not for you.


So if I drop my phone to the toilet, I will forever lose access to everything? Since the vault is on my phone.

A majority have more than one phone. Or at least they can get a new SIM card and sign into the iCloud account. Then all passkeys are synced from cloud.

Yes, if you are edward snowden then not for you. For rest of us - it is useful


This is crazy. I have one phone and zero iCloud. I don't think I'm that unusual.

You are exaggerating. If the loss or lockdown is so bad then many would have stopped using any of icloud or google equivalent. People are able to depend on it. People are able to repair and use phones even when it falls into abyss.

Well, I mean yes. People for whom it works. Others never started.

Idk how much money you must be having, but all of my bubbles only ever go with one device

this is ridiculous. I don't even have a bubble device. Run lineageos in a decent 2020 device moto G32 for €100.

Yes, you can afford to host everything locally. Not everyone can.


A majority have more than one phone?

Or they have a laptop or tablet - even the cheapest one that has logged into Google or Apple. That way they can recover.

Not always. And which vault? There can be multiple on a given device. This isn't some hypothetical 'mollify the user's worries' question, this is an important practical question of what do they need to worry about losing access to. Trust me when I say that most users I have talked to have absolutely no idea about this, and usually only find out when they've already lost them.

Great, what happens if I lose my phone?

in 1password

As others have pointed out, this is a terrible oversimplification which misses all the nuances which cause people headaches when using passkeys.

To your point, I for example would add point c) - Is linked to the device you are using currently. If you want to use another device to log in you are in a world of complexity and pain.


But how do I type it into my new phone?

It depends.

Are you part of the 99.99999% users of one of iOS+Apple or Androidlike+Google/Tencent or HarmonyOS+Huawei? If that's the case, you don't need to as the key is automagically saved by your OS' platform and synced with your new device.

Otherwise, you're such an extreme outlier that you probably either know what you're doing or can find out by yourself, right?


> … users of one of … Google …? If that's the case, you don't need to as the key is automagically saved by your OS' platform and synced with your new device.

This absolutely does not encourage confidence in me. We all know how easy it can be to get locked out of a Google account and have no way of getting back in unless you have enough clout to make a huge noise online so a human there pays attention instead of you being stuck in the 'ol support-bot-run-around loop. It doesn't happen often when you consider how many users there actually are out there, but the potential inconvenience is high enough that “fairly rare in the grand scheme of things” is still enough to be reason enough to be wary.


How can it be saved and synced without credentials? I'm in that overwhelming majority, but I don't grok how I can recover the account when my phone is lost/stolen/damaged. The answer appears to be, use another device that was already logged in?

The point is people like this usually are arguing as they hate adopting new tech. And they hate FAANG. No way to convince them.

That's easy, they'll check whether there's one big fingerprint vs >10^10 little tiny fingerprints and conclude accordingly \j

[flagged]


You sound bitter about this.

I'm sympathetic to the author's core position. I think LLMs as they're currently deployed are doing net societal harm so far. For example, for every React app whistled up in five hours, there's a high schooler or college student out there sleepwalking through their foundational courses and being set up to catastrophically fail upon trying to enter the job market.

But I think it's important for the quality of public discourse that we forward only the best, strongest arguments for any given position (whether I personally agree with that position or not). A weak argument gives unnecessary purchase to unscrupulous haters who might use that weaker argument as a low-grade "straw man" to dismiss the whole position.

So with that preamble, some constructive criticism (very well-intentioned):

> I am not exaggerating: We need to resist “AI” so that thousands, perhaps millions of people do not die.

On this one you are, in fact, exaggerating (certainly with "millions," likely with "thousands" as well).

The overwhelming majority of people who lose their job for whatever reason (and there are many reasons, not just this one issue) fall back on a support network of their family and friends while they "get back on their feet" by pivoting to another job or form of employment (sometimes branching into entrepreneurship, for example).

The alternative to employment at whatever FAANG or FAANG-adjacent company someone was laid off from is not "death." It is typically "some, sometimes quite significant, discomfort." Granted "AI Layoffs" are starting to ripple out beyond FAANG, but the story is similar in other industries.

If "layoffs kill people" is the moral hill we choose to plant our flag on, then mustn't we also campaign with equal vociferousness against all the other causes of layoffs in general? Since to do otherwise is to sit by while those laid off allegedly die in droves of thousands or perhaps millions?

It also occurs to me that this framing ("AI causes layoffs") also gives incompetent and unaccountable executives a pass by pinning the actual harm done by irresponsible layoffs (which to be clear, is not none!) on "the AI" rather than on the leaders who are in the positions to actually decide what happens in their organizations.

I think the argument is much stronger if we talk about the aggregate cost to humanity being paid in terms of displacement, life disruption, and curtailed opportunity (especially for juniors). We should not make the "toxic escalationism" move of equivocating things we don't like with negligent homicide, even if it makes for a punchy one-liner.


> For example, for every React app whistled up in five hours, there's a high schooler or college student out there sleepwalking through their foundational courses and being set up to catastrophically fail upon trying to enter the job market.

Oh man how did we ever survive calculators.


Are you arguing that a TI-84 has materially similar effects on development of critical thinking, writing, and reasoning skills as ChatGPT?

No I'm arguing that many developments that simplify work while not undermining understanding exist, and we have dealt with them. In the narrow scope of understanding engineering, the fact that AI can also engineer does not prevent us from proper education or gaining understanding.

Thanks for clarifying. I think we're talking about different things.

Your response would make sense to me if I was making a case against AI for professional use based on "skill atrophy among professionals who use AI" or something like that (which is a case that I see some people making).

I'm not talking about that, though. This is not me saying, "Slide rule is good, TI-84 is bad; because effortful work has good effects on practitioners and effortless work has negative effects."

I'm talking about youth, adolescents, and young adults who are voluntarily foregoing the effortful mental exercise of reading, understanding, and writing as part of their primary and secondary education—the very effortful mental exercise that our education system exists to "inflict" upon them, for their own long-term good.

I'm talking about people getting into the workforce who don't know how to learn because they've gotten all passing grades while having a chatbot generate the outputs that would previously have indicated that learning was occurring.

Maybe it's the case that AI/LLM usage is the primary skillset needed to thrive in the job market of tomorrow. But I'm not convinced of that, yet.

Just to be clear I don't think there's any way to put the cat back in the bag w/r/t LLMs and education—I think the education system as a whole needs to reinvent itself to account for the existence of LLMs. But in the mean time, until that mammoth societal initiative has time to make progress, I worry that there are many, many kids who are being systematically failed by an education system that was very rapidly outmoded by new technology (not that it was bleeding edge either right before ChatGPT launched, but that's neither here nor there). And that position, which I hold, is one supporting leg of my larger more ambitious position that, "AI is currently, so far, doing net societal harm."


These are the same thing. Youth has been able to effortlessly do math by using calculators in the past decades, yet we expect and succeed in them learning math. The main thing we need to do is ban llm use somehow for education, as we have with calculators. Then, piecemeal, bring it back when it makes sense.

> forward only the best, strongest arguments for any given position... A weak argument gives unnecessary purchase to unscrupulous haters who might use that weaker argument as a low-grade "straw man" to dismiss the whole position.

Excellent point. Thank you for writing such a cogent argument.

It is clear that the rich and powerful are making short-term decisions that are causing widespread and long-term harm. Decisions such as, AI-pilled investors demanding unsustainable productivity from companies, and CEOs in turn forcing employees to use agentic coding and laying the rest off.

Such decision-making is not new, of course, but LLM technology is helping grifters and con artists to turbo-charge it. Founders can raise money using cool demos that achieve the impossible. Investment analysts can back up their AI story with huge paper profits.

The result, as you summarized, is life and career displacement and missed opportunities for young people. It's just too abstract and diffuse of an impact to influence people with, and it also seems to be railing against the holy cow of Capitalism.

"Data centers bad!", or "AI is disrupting humanity and the end is nigh!" are much more punchy slogans.


Programmers pervasively underestimate the sheer amount of manual brunt work that business users routinely do by hand and with their own eyes, mouse, and keyboard to make spreadsheet-based processes "work out."

I work in Finance. It's routine for the folks I work adjacent to to spend literal hours performing a task using a spreadsheet. The same logic could be executed by a query engine or scripting language in seconds. But... I know from trying... it would take months if not years to accurately identify and account for all the weird exceptions and edge cases that the human operator is accounting for intuitively because of their undocumented tacit knowledge of the domain.

So while the spreadsheet itself as an artifact is a mess, and the process as a whole is gallingly inefficient... the outputs they produce are often preternaturally correct.


I mostly agree. There are certain classes of tasks where the spreadsheet is more efficient. It's "more efficient" because it 1) requires less set up time (like you said, translating a computation in a more traditional system could take months), but also because 2) the spreadsheet is a highly interactive and accessible environment.

We have a programmer on our team who keeps trying to convert our excel calculations to more structured systems (database store). The issue is that the spreadsheet-work almost always requires navigating and making decisions based on unstructured data. The format isn't formally specified, so in the end our programmer makes more mistakes because he doesn't engage with the data - the processing gets treated as a routine algorithm, and it's not. The interactivity (and the fact that we're not spending energy on formal specification) is what allows us to more effectively engage with the data.

Another important point is that spreadsheets more easily allows you to consider data points individually without hand cuffing yourself to one kind of processing algorithm or software design. I can easily edit one cell to make a correction in a data set (which is a double-edged sword). The programmer has to create an additional handler to handle the exception. Depending on the design/quality of the code, this could just be adding undesirable complexity in the software. So we can either spend 30 seconds and edit a cell, or spend half an hour adding to code (which by the way may never get used again).


When I and my (still fairly young) family needed to move cross-country, my wife and I accepted a credit card offer with 0% APR for the first year and put all our moving expenses on it. Then once we settled, we paid it down a bit at a time each month, and then right before it would have started charging interest we paid the rest as a lump sum.

Really helped us float the moving company and also some DIY renovations on our house that we didn't have all the cash on hand to pay for outright. And we didn't pay a thin dime for the privilege.


In that podcast DHH was talking about how in Omarchy you can change the system settings, monitor setup, themes, window chrome, installed programs, window manager config, keyboard shortcuts, etc. using agents. This is facilitated by Omarchy because all that stuff is dictated by text files that agents can directly interface with.

Whatever the merits of MacOS, and there are many, it is not the paradigm there that all your system settings and config are stored in text files. That's what he was talking about.


You can use the ‘defaults’ CLI to manage settings files for the OS and applications.

For example: https://macos-defaults.com/


Other than being a proprietary OS that's getting more locked down every year, its disk performance is trash.

https://x.com/theo/status/2090528543746965991


Do you have a non-video, non-X summary of what he’s talking about?

I’m not watching a 31 minute video on X to figure out what this is about. Theo is another influencer who thrives on being contrarian, embellishing negative claims about things he’s not pumping right now, and trying to get everyone to ignore negative things about what he is pumping. I would not trust his judgment on topics like this without some third party benchmarks and deeper claims because the first priority of influencers in this category is to be contrarian and ride divisive topics. Being factually correct is secondary.


Lots of small fs operations on macOS is apparently rough.

I use nix on macOS and any time it's making changes to /nix/store, the Finder and fsevents processes peg cpu.

IIRC his video shows fs-heavy ops like file deltions and pnpm install taking much longer on a macbook despite better specs.

Frankly, things like the lack of a universal cmd-c/v clipboard on linux has been 1000x worse for usability than slower bulk fs.


Ah, the irony of posting "Your Mac is slowing you down" on the bloated JS hellsite that is X. That page took 10s to appear on my machine (before even thinking of rendering the video) whereas the HN front page is <1s.


> Whatever the merits of MacOS, and there are many, it is not the paradigm there that all your system settings and config are stored in text files.

Maybe not, but the agent can call `defaults write` too, no?


"it is not the paradigm there that all your system settings and config are stored in text files."

This is inherently untrue. A .plist in XML is nothing but text. It might be formatted text, but it is still text nonetheless, like almost every other configuration file in existence.


Technically correct but you miss the point. Human readable text (like TOML). Nobody wants to edit XML .plist files to configure their OS and apps.


Surely the LLM doesn't mind.


EMDR is an amazing thing, you might look into it. Be well, friend.


This is a theme in Blindsight by Peter Watts as well.

In that setting, field experts working at the bleeding edge are so advanced that non-experts literally can't understand what they're saying at all. So there's a whole class of specialists, "synthesists", that specialize in gaining approximate understanding of the experts' work for the purpose of communicating it to outsiders—perhaps wrongly, according to the expert at least, but hopefully more productively vs the unmediated version.


What's amusing to me in this context is, summarizing emails and such has for a while been a supposed use case for AI—the LLM serving as the "synthesist" to explain long texts accessibly. But with this math question, a human "synthesist" would be needed to approximately understand the math discovered and programmatically verified by the LLM. So the roles reverse.


If it isn't still common practice 40 years from now (8/18/2066), I'll give the first person to challenge me and cite this comment $1 USD (or equivalent value in the One-World Order-issued omni-currency that we will probably be using by then).


I'll pay 50 eurodollars


I mean I think the only chance you lose this is if curl and bash are obsoleted and replaced by one world order get and execute


This sounds roughly similar to, "If eating steak is nutritious and tastes good, why would you not eat an 8oz sirloin for breakfast, lunch, and dinner for an entire month?"

"Too much of a good thing" does exist. Someone might feel that it takes time for their organization to "metabolize" the rapid additions made by coding agents. That seems quite reasonable to me. Your comment seems to argue a false dichotomy.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: