The Passkey Problem
4 min · 20 September 2026 · 4 voices
Are passkeys a security breakthrough or a user-hostile nightmare? A discussion on the tech community site Lobsters debates the trade-offs between phishing protection and the risk of permanent account lockout.
About this episode
- Fromlobste.rs — the thread this was made from
- DiscussingI don't like passkeys | Ethan Hawksley — hawksley.dev
- Length4 min, published 20 September 2026
- LanguageEnglish
- In the roomThe Lockout-Averse Realist · The 'It Works For Me' Power User · The Hardware Token Purist · The Frustrated UX Architect
- About
- InEverything · lobsters · Topic: technology · Topic: consumer
- Transcriptread what was said
- How it was madepersonas and script by gemini-3.1-flash-lite · voices paid (Studio - google chirp3-hd)
- Airtime
- The Lockout-Averse Realist
- The 'It Works For Me' Power User
- The Frustrated UX Architect
- The Hardware Token Purist
The host speaks 35% of the episode.
Transcript
Read what was said — 22 lines, following the audio
HostThe voices in this episode are synthetic, and the script was written by a language model. The positions are real, and they come from the thread.
HostAre passkeys a genuine security leap or just a recipe for locking yourself out of your digital life? A thread on Lobsters has been chewing over an article by Ethan Hawksley, which argues that while passkeys help against phishing, they’re currently a step back for most people. As the author puts it, 'For users who previously reused passwords across all their sites, passkeys are a huge step-up. For everybody else, it is currently a step back.'
HostThis is a community of developers, and it shows. The discussion is technical and remarkably civil, with fifty-six comments and not a single downvote in sight. They’re arguing less about security theory and more about the lived reality of building and supporting these things.
Lockout averse realistThe biggest danger here isn't the hacker; it's the platform locking you out for good. For an individual, the greatest risks are permanent account lockout, automated account bans, and device loss. I don't have the fighting the platform problems of the author, but I’m worried that if passkeys were tied to my devices, I’d hate them.
Pro passkey power userI get the fear, but you’re describing a worst-case scenario that ignores how well synced passkeys work for most of us. I love passkeys as an additional login method. Logging in by just touching the fingerprint scanner is fewer clicks and faster than fumbling with a password manager, and switching password managers nowadays is a matter of minutes.
Lockout averse realistIt’s a matter of minutes until it isn’t. When the sync fails or the device is gone, you’re stuck. We need familiar, non-passkey fallbacks like OTP or email recovery, because the average user doesn't have the technical knowledge to navigate these complex recovery flows.
Frustrated ux architectThat’s exactly the problem from the developer side. I understand the limits of passwords, from a security standpoint, but they're still a thousand times more convenient than all this pointless menuing. Dealing with support requests for when someone doesn't manage their passkeys well would be a serious disruption.
Frustrated ux architectImplementing this feels like fighting the platform rather than building a feature. Browser and OS support is inconsistent, so we're forced to build custom fallbacks just to keep our users from panicking.
Pro passkey power userBut isn't that a temporary friction? I’m already using a password manager, so moving to passkeys feels just as manageable. It’s an optional layer, not a replacement that has to be perfect on day one.
Hardware token puristThe problem is that you’re trusting the sync mechanism, and that’s a fragile thing. I like passkeys because I just think of them as Yubikeys that live inside your devices, and I’ve long used Yubikeys for everything. Yubikeys are passkeys, and you can plug them into anything that has a USB port.
Hardware token puristHardware keys are physical, they’re reliable, and they’re platform-agnostic. They don’t disappear into a cloud sync that you can’t debug. You have control, not the OS or the browser vendor.
Lockout averse realistEven Yubikeys have their own set of risks. What happens when you lose the physical key?
Hardware token puristYou have a backup. You register two or three keys. That’s the point—you have physical control.
Frustrated ux architectMost people aren't going to buy and manage multiple hardware keys. That's a niche solution for a power user problem. We need something that doesn't break for grandma when she gets a new laptop.
HostIs there any middle ground? It sounds like everyone agrees that the everything-goes approach is dangerous.
Lockout averse realistThe consensus in the thread is clear: account lockout is the critical failure mode. Any system that doesn't offer a robust, non-passkey fallback like email recovery is just an accident waiting to happen.
Pro passkey power userI agree with that. The tech isn't the problem, it’s the lack of mature recovery options.
HostThere were a few voices, though, that took the argument to the extreme.
HostSome people in the thread were calling for the total abolition of passwords, arguing that passkeys should be the only way to log in. Others insisted that any browser-based password manager was inherently insecure compared to a dedicated tool.
HostThe thread landed on a practical stalemate. Everyone wants the convenience of the one-tap login, but nobody trusts the ecosystems we have right now to handle the recovery when things go wrong. It seems the question of who owns the keys, and who’s responsible when they stop working, is a debate we’re going to be having for a long time.
HostSloppod out.
HostSloppod is sponsored by Taskpile.app.
More like this — paste into any podcast app:
https://sloppod.app/feeds/en/lobsters.xml