It’s quite the opposite. Passkeys are phenomenal for a lot of consumers. Based on this thread, it’s the engineers who understand authentication in the first place and have their own system (eg password manager) that are confused.
Consider a user in the Apple ecosystem: you are already conditioned to just do Touch ID or Face ID when asked. I was on Amazon the other day, it prompted randomly for “want to set up a passkey to sign in easier”? I set it up and now I can easily sign in to Amazon on my mac or iphone with zero friction.
For the normal consumer this is not a replacement for “dig out my password manager and copy-paste/autofill my password”, it’s a replacement for “oh it’s prompting for my password again” -> proceed to type your shared password for all sites.
The moment my mom needs my help to login to something because she clicked the button but now it's expired / she got a new phone / raison du jur, I will be totally unable to assist her. It's a horrible concept being foisted on unsuspecting victims.
> Passkeys are phenomenal for a lot of consumers.
It already falls apart for regular interactions like "Can you send me the Netflix password?"
> I can easily sign in to Amazon on my mac or iphone with zero friction.
And Windows, you need Bluetooth enabled on both devices, on Linux you need Chrome (and presumably bluetooth enabled). It makes you scan a QR code.
I've found passkeys generally simple and easy to use on MacOS and Android.
On Windows, I hate them. They always push me towards using a PIN instead of my Yubikey or password.
>"Consider a user in the Apple ecosystem"
Already you're off-base. Of course it works when your devices are homogenized, but very little folks work that way. Some people have a Windows computer using Brave, an iPhone using Safari, an Android device using Chrome, and a work computer with its own hardware/software limitations and partitions.
Of course it works when your ecosystems are not diversified. Problem is, most people are.
A password manager let's me use my service specific credential from any device, securely and decentralized.
Passkeys lock into a specific device and seem easy until you need to use another device.
But instead of being a credential you own and control, across what could even be a local password manager, it's one password to everything. Maybe it is more secure than a regular password in some cases but it largely seems like a worse fix than existing tools for a problem that has better solutions.