一位技术评论作者在Hacker News上发表文章,对业界广泛推广的密钥认证(passkeys)技术提出了批评1。该作者承认密钥认证在防止钓鱼攻击和防护数据泄露方面优于传统密码1,但认为这项技术对个人用户面临的实际风险——如账户锁定、设备丢失和跨设备登录困难——帮助有限1。
评论指出,密钥认证的生态系统尚不成熟,存在多项实际障碍1。具体而言,硬件密钥无法备份密钥数据,用户需要购买2至3个硬件密钥,并为每个网站单独完成注册1。即使是支持可发现凭证的高端硬件密钥,每个密钥也仅支持25至100个账户,顶级型号最多可存300个账户1。此外,苹果和谷歌推出的同步密钥依赖于各自的操作系统账户,一旦该账户被禁用,用户将无法恢复所有第三方账户的密钥1。在他人设备上登录时,混合传输方式(二维码加蓝牙)在理论上安全,但在实践中存在连接失败等边界情况1。
虽然FIDO联盟正在改进互操作性,但目前跨供应商体验仍不成熟1。在此背景下,作者建议个人用户继续采用密码管理器配合基于时间的一次性密码(TOTP)的组合方案,而密钥认证技术目前更适合企业用户1。
A technology commentator has raised concerns about the industry's promotion of passkeys as a password replacement, arguing that while the authentication method offers advantages over passwords in preventing phishing and data breaches, it falls short in addressing real-world risks faced by personal users 1. The critic points out that passkeys struggle with account lockout scenarios, device loss, and cross-device login difficulties that consumers commonly encounter 1.
The author notes that major technology companies have begun steering users toward passkey adoption, with Google labeling the feature "Skip password when possible" and Microsoft promoting passwordless accounts 1. However, the current passkey ecosystem remains immature for individual use cases. Hardware keys supporting passkeys cannot be backed up and require users to purchase multiple devices—typically two to three keys—with separate registration for each website 1. Additionally, hardware key storage capacity is limited, with most keys supporting between 25 and 100 accounts per device, though premium options may reach up to 300 accounts 1.
A critical vulnerability exists in synchronized passkeys from Apple and Google, which depend on users' operating system accounts; if such an account becomes disabled, users lose access to all third-party account credentials stored on that platform 1. While the FIDO Alliance is working to improve interoperability across vendors, cross-platform experiences remain underdeveloped 1. Logging into passkey-protected accounts on another person's device involves hybrid transmission methods combining QR codes and Bluetooth, which are theoretically secure but prone to practical failures such as connection issues 1.
The critic suggests that passkeys are better suited for enterprise environments and recommends that individual users continue using password managers paired with time-based one-time passwords (TOTP) until the passkey infrastructure matures 1.
评论
还没有评论,欢迎留下第一条。