I don't like passkeys
Points and comments are a snapshot, not live.
Passkeys offer strong anti-phishing security but introduce real risks of permanent account lockout for individuals.
The author argues passkeys are a fantastic technology for enterprise use but a poor fit for personal security, because the greatest risks for individuals are permanent account lockout, automated account bans, and device loss. Phishing resistance is undermined by weak recovery methods (SMS, email links). Hardware keys have limited capacity (25-300 accounts) and cannot be backed up. Synced passkeys tie identity to Apple or Google accounts, risking total loss if that account is banned. Third-party passkey managers fight platform UX. Logging in on others' devices is inconvenient. The author recommends randomly generated passwords in a third-party password manager plus an independent TOTP app for most users.
What commenters are saying
Top commenters broadly agree passkeys are pushed too aggressively, especially by Amazon and PayPal. A strong split exists between those who see passkeys as a clear step forward for average users (auto-synced on iOS/Android) and those who find the explanation and UX opaque even for technically literate people. The most cited concrete complaint: there is no universal way to register more than one device, making account recovery opaque and platform-dependent. One commenter likens passkeys to chip cards for a lay audience, while others note the analogy fails on specifics like device loss or shared computers.