Engineers designing passkeys overlooked critical usability issues that confuse average users, according to criticism gaining traction in tech communities. The passwordless authentication standard is struggling with consumer adoption due to poor design decisions.
Passkeys, promoted as a replacement for traditional passwords, were built without sufficient consideration for how everyday users actually think and behave, critics argue. The technology requires users to understand concepts like device syncing, backup codes, and biometric authentication—complexity that undermines the goal of simplification.
Key friction points include unclear recovery processes when users lose access to devices, confusion about where passkeys are stored, and difficulty explaining the system to non-technical users.
The criticism reflects a broader pattern in tech development: solutions optimized for engineering elegance can fail in real-world deployment. Companies like Apple, Google, and Microsoft backing passkeys have implemented various approaches, but adoption remains slow among mainstream users who prefer familiar password managers.
The debate highlights the gap between technical specifications and consumer experience, with 254 comments on the discussion thread indicating widespread concern about passkey viability as a mass-market authentication standard.
Cybercriminals are exploiting thousands of compromised small-business websites to distribute ClickFix malware payloads stored in smart contracts on the BNB Smart Chain, amplifying the reach of a known threat.
Quad9 provides an open DNS recursive service that prioritizes user privacy and security at no cost. The service blocks malware and phishing domains while maintaining minimal data collection.
A government website running Ruby on Rails was exploited within hours of a critical vulnerability patch becoming public. The rapid attack demonstrates how quickly threat actors weaponize disclosed security flaws.