I like it because I can use discord on even a pretty untrusted computer without providing it any credentials or access to my passkey, and then later when I'm done I can revoke the session.
You scan the QR code, click the confirmation button, and you're signed in. It's part of the standard UI of normal operating systems.
Might not work (well) if you're on an old computer without decent Bluetooth but everything has Bluetooth these days.
now multiply it with every web site you want to access.
But don’t log in to important accounts on a public computer, like ever, unless it’s a dire emergency.
(...and I’m pretty sure plugging my yubikey into a locked down public terminal is not going to solve this, either.)
If my phone's camera is broken but both devices have bluetooth, it can do the handshake over bluetooth.
If I'm on someone else's computer and I want to use a passkey on my authenticator on my keychain, I'll just plug it in and then tap the button on the authenticator.
Meanwhile, if I logged in with the password and the account only has a password then they have a full copy of my entire authenticator to the account. With the passkey, once the session is invalidated the access is gone.
I would love for this feature to actually work but every time I've needed it to it hasn't. Literally this week I only had a passkey on my phone, but at the time I was in Linux with Firefox, and afaict the qr code workflow basically requires either chrome or windows 10.
in poland we have similar to passkey implementation for government profile, that is then used to login to most/all government websites or to sign government documents. you point the camera on the qrcode, confirm it on the phone and you are done. this same app has your ID, which can be used in most places (shops, banks, police etc).
and btw im using linux (main box), macos, android and ios - no issues so far with really cross device usage
Now, if only Windows, macOS, and Linux can get together and fix whatever needs fixing to get headsets to connect properly automatically, that'd be grand.
But I'm also a person who generally never experiences the issues some people have with Bluetooth in general. If I ever have an issue with Bluetooth on a computer, I swap out the wireless chipset with an actually good one. Its almost always just bad hardware. I've only had to do that a few times in the last decade though, more modern WiFi/BT chipsets are generally pretty OK. Its the old ones that are near worthless.
Although I will say most of the time I just plug in my USB authenticator. I normally only fall back to the QR code if I don't have my keys on me.
And as an edit, I wasn't aware fully that the QR code is to help assist the BT handshake, I had assumed it was posting a signed request back to the service. My bad, my above comment isn't completely correct. Thanks for cluing me in to the BT requirement for the QR code path.
Which I’m sure is great in theory. But IMO just adds even more complexity to a system that already has several moving parts and is more fragile than it should be.
In fact, if you have your Apple Passwords app set to sync through iCloud, you can:
- Make a passkey on your Mac for a site in the Passwords app
- Go to a different computer (a friend's or whatever)
- Attempt to log in, choose use another device, it'll show the QR code
- Use your iPhone to scan that QR code and sign in, as the iPhone has the passkey synced through iCloud
Note, the same kind of thing is also possible with other password managers as well.
I've seen the same on Android too, and I think there's a difference in how Chrome and Firefox are handling the requests.
Then you get in to cases like a Microsoft Account. You need to use your account to log in to the device that has the passkeys, so the workflow never works properly and you have to fall back to another method.
Amazon is another one. If an app like Libby redirects to Amazon, I get a different, passkey-less password prompt, so I need to have a password readily available.
It's great when it works, but honestly 1password with straight up username/passwords is probably just a better UX in the end.
Plus, that doesn't have the negatives/limitations of passkeys.
It’s not that difficult. Spend 10 minutes researching the topic and you’re fine. Passkeys are so much more convenient than having to use passwords. When implemented right, it’s literally one click from opening the login page to being signed in. On all of my devices.