Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What's their end game here?

What is Microsoft gaining from their push to passkeys? They knew this was going to piss off a lot of people, but they went ahead with it anyway. That makes me believe there's something else at play.

My experience with passkeys has been worse that my Bitwarden password auto complete, so needless to stay I'm sticking with my regular passwords on my Bitwarden (I know Bitwarden has Passkeys support. I don't want to use it)



I suspect it's another step in the push to make the mobile device the centre of digital identity. (Yeah, it might support some standalone key devices, but nobody's giving Joe Sixpack a Yubikey)

The one with far more data gathering capability and generally less robust ability for the end user to assert control over it, and which is generally tied to a service contract that in many countries requires identity verification.


That would require all the microsoft auth platforms to allow you to use yubikeys or similar instead of default forcing you in to ms authenticator only


Microsoft authenticator supports YubiKeys


So in business Microsoft cloud land, not using Microsoft Authenticator specifically is basically impossible. You have to shut it off four different ways even if you have an alternative solution already configured.

I think centralizing control is absolutely the core play for them.


Feels like they're betting big on being seen as a leader in "passwordless" security




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: