I don’t know. I am both a user of passkeys and generally wary of making myself overly dependent on tech giants and complex solutions. I’m noticing an increased reliance and potential loss of access to my own data. This does abstractly concern me. Not to the degree that it changes anything I’m doing, but still. As annoying as managing usernames and passwords was, I don’t think I have ever spent so much time authenticating on a daily basis. The systems that we now need to interface with for authentication are vast and complex.
Passkeys and Modern Authentication | Armin Ronacher's Thoughts and Writings
This might just be the path we’re going. However, it is also one where we maybe want to reflect a little bit on whether this is really what we want.
I appreciate the transparency and thoughtfulness in the note. I also think that some of the concerns might come to bite us in the future with our dependence on these corporate systems. However, passkeys as a technology is a tremendous knock at busting the dichotomy of "user ease" or "security" and I really want us to think of better ways to solve around it rather than eschew it.