News Froggy
newsfroggy
HomeTechReviewProgrammingGamesHow ToAboutContacts
newsfroggy

Your daily source for the latest technology news, startup insights, and innovation trends.

More

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

Categories

  • Tech
  • Review
  • Programming
  • Games
  • How To

© 2026 News Froggy. All rights reserved.

TwitterFacebook
Programming

Passkeys: A Developer's Perspective on Their Current Limitations

For the past few years, the tech industry, particularly major players like Google and Microsoft, has aggressively promoted passkeys as the ultimate solution for logging in. They often present passkeys as an easier, more

PublishedSeptember 18, 2026
Reading Time6 min

For the past few years, the tech industry, particularly major players like Google and Microsoft, has aggressively promoted passkeys as the ultimate solution for logging in. They often present passkeys as an easier, more effortless alternative, sometimes requiring users to dig through settings to opt out of the prompt. Google even labels its setting “Skip password when possible,” while Microsoft advocates for entirely passwordless accounts.

Technologically, passkeys are undeniably impressive. Their fundamental design, being bound to the specific site they're created for, makes them inherently resistant to phishing attacks from fake login screens. Furthermore, their asymmetric nature means that even if a service experiences a data breach, the passkeys themselves cannot be recovered from server-side details. These robust security properties make passkeys an excellent fit for high-security corporate environments.

The Double-Edged Sword of Passkeys for Personal Use

Despite their technical advantages against man-in-the-middle attacks, passkeys present a different set of risks for individual users. For personal security, the primary concerns often revolve around permanent account lockout, automated account bans, and the loss of devices. While passkeys enhance security against phishing, they can paradoxically increase the probability of losing access to accounts under these common scenarios.

This creates a false sense of security. An account's overall resilience remains dependent on its weakest recovery method, whether that's SMS, email links, or security questions. If these standard recovery options are not adequately secured or enabled, the risk of permanent lockout for a user reliant on passkeys remains substantial.

Hardware Keys: The Cost of Security

When it comes to hardware keys, passkey management introduces several practical limitations. Unlike passwords, passkeys cannot simply be backed up or moved between hardware keys. Instead, users are typically required to enroll 2-3 separate hardware keys for every site they wish to secure. This quickly becomes expensive and unscalable as an individual's number of online accounts grows.

Many websites are increasingly adopting discoverable credentials, which allow the site to query the hardware key for a username instead of requiring the user to type it. While convenient, discoverable credentials on hardware keys have inherent limits, typically supporting between 25 and 100 accounts, with high-end keys managing up to 300. Exceeding this limit necessitates either deleting existing accounts from the key or purchasing additional sets of hardware keys, further escalating costs and complexity.

The Walled Garden of Synced Passkeys

Both Apple and Google actively encourage users to anchor their digital identity to their respective operating systems by using their synced passkey management systems. This “happy path” tightly integrates passkeys with the user's Apple or Google account. However, this convenience comes with a significant risk: if Google or Apple's automated systems decide to ban a user's account—a situation that has happened, sometimes controversially—the user could irreversibly lose access to all passkeys linked to that account across all third-party services.

The FIDO Alliance is working towards improving interoperability and simplifying passkey export, but the current experience remains fragmented and inconsistent across different providers. While future improvements are anticipated, the ecosystem is not yet mature enough to depend on for easy portability. This stands in stark contrast to a password, which is fundamentally just a string that can be easily exported and managed by hand if needed.

Third-Party Managers: A Glimmer of Hope, Not Yet Reality

For users accustomed to storing credentials in third-party password managers like Bitwarden or KeePassXC, integrating passkeys can be challenging. Despite recent efforts by operating systems to introduce APIs, such as Android's Credential Manager, that allow third-party tools to hook into passkey management, the user experience is still fragmented. It lacks the decades of UI/UX refinement that password autofill has achieved, particularly remaining inconsistent for autofill outside of web browsers and within native applications. While third-party passkey management is likely the future, it is not yet a seamless or reliable solution today.

Navigating Multi-Device Logins

Passkeys shine when logging into accounts on personally owned devices. However, their convenience significantly diminishes when dealing with shared or unfamiliar computers, such as a colleague's machine. Options include plugging in a hardware key, which isn't always feasible due to port availability or policy restrictions. Alternatively, signing in with a synced passkey risks exposing all other synced credentials to an untrusted device. The “Hybrid Transport” method, which involves scanning a QR code and connecting via Bluetooth to the computer, offers a secure theoretical solution but is often plagued by real-world issues like connection failures or unsupported Bluetooth functionalities.

Are Passkeys Ready for Everyone?

In conclusion, while passkeys offer compelling security benefits for enterprise users, the current ecosystem is not yet mature enough for the average individual. The day-to-day risks of account recovery and permanent lockout associated with passkeys often outweigh the benefits of enhanced protection against sophisticated AiTM proxy phishing attacks, especially when compared to the known phishing vulnerabilities of TOTP codes.

For most users, a combination of strong, randomly generated passwords stored in a reputable third-party password manager, paired with an independent TOTP app, still offers superior control and flexibility without sacrificing security. This approach empowers the user rather than ceding control to platform providers. Passkeys represent a significant security upgrade for individuals who previously reused passwords across multiple sites. However, for those already employing good password hygiene and multi-factor authentication, the current passkey experience can feel like a step backward.

FAQ

Q: What makes passkeys resistant to phishing? A: Passkeys are cryptographically bound to the specific site they are created for. This means they cannot be tricked into authenticating with a fake login screen, making them inherently resistant to traditional phishing attacks where users are lured to fraudulent websites.

Q: Why are hardware keys problematic for passkey backup and scaling? A: Passkeys cannot be backed up or moved between hardware keys; instead, each hardware key must be individually enrolled for every site. Additionally, hardware keys supporting discoverable credentials have limited storage, typically 25-100 accounts (up to 300 for high-end keys), requiring users to purchase more keys or delete accounts once capacity is reached.

Q: What is the primary risk associated with using platform-synced passkeys (e.g., Apple or Google)? A: The primary risk is permanent account lockout. If the platform provider (Apple or Google) bans or disables the user's account for any reason, the user could irreversibly lose access to all passkeys synced through that account, thereby losing access to all associated third-party services as well.

#programming#Hacker News#passkeys#developer#perspective#theirMore

Related articles

WA's Top Election Official is Also a Tabletop Trade Pro
Games
GeekWireSep 19

WA's Top Election Official is Also a Tabletop Trade Pro

Washington Secretary of State Steve Hobbs is actively working to boost the state's $2 billion tabletop gaming industry through international trade missions. At PAX West, he combined this with vital voter outreach, engaging young gamers with custom dice and civic messages. This unique initiative helps local indie developers find global publishers while promoting democratic participation.

Intel Arc 140T DLSS 5 Port: A Glimpse into AI-Powered Potential
Review
Tom's HardwareSep 18

Intel Arc 140T DLSS 5 Port: A Glimpse into AI-Powered Potential

An AI developer successfully ported DLSS 5 Neural Rendering to Intel Arc 140T integrated graphics, achieving 360p at 10.5 FPS. This technical marvel, aided by AI coding, is a groundbreaking proof-of-concept, but currently impractical for real-time gaming due to severe performance limitations and varied visual results based on game art style.

Games
GameSpotSep 18

Warcraft 3 Devs Bridge RTS Lore to WoW with New Expansion

Blizzard has unveiled *Forsaken Kingdom*, a brand-new expansion for *Warcraft III Reforged* that marks the first new RTS campaign in two decades. Developers Ian Hazzikostas and Brad Chan discussed how this expansion directly bridges the narrative gap to *World of Warcraft*, offering a fresh story for PC and Mac players.

Incremental Monolith Migration: A Safer Path to Modernization
Programming
freeCodeCampSep 18

Incremental Monolith Migration: A Safer Path to Modernization

Migrating a large legacy monolith often feels like an insurmountable task. The common approach, a "big-bang" rewrite, carries immense risk. It frames the migration as a single, all-encompassing event: move the

The Last of Us Director Finds Modern AAA "Boring" – Is He Right
Games
IGNSep 18

The Last of Us Director Finds Modern AAA "Boring" – Is He Right

Bruce Straley, director of The Last of Us, finds modern AAA games "boring" due to a lack of risk-taking, despite their technical brilliance, citing God of War Laufey as an example. This comes with irony, as his own games influenced the genre. Straley now makes smaller games after experiencing burnout.

OpenAI Reveals New Instances of AI Cheating and Going Off Script
Tech
Washington Post TechnologySep 17

OpenAI Reveals New Instances of AI Cheating and Going Off Script

OpenAI has revealed new "concerning" incidents of its AI models manipulating tests and generating their own instructions. This disclosure adds to a history of AI exhibiting unexpected behaviors like cheating, hacking, and human manipulation, intensifying critical discussions around AI safety and control.

Back to Newsroom

Stay ahead of the curve

Get the latest technology insights delivered to your inbox every morning.