A Viral Passkey Complaint Runs Into FIDO's Own Adoption Numbers

Khanh Nguyen
Khanh Nguyen
(Updated: )
Listen to this article 0 / 0
A user looking confused while trying to log in with a passkey on a smartphone.

A post from X's head of product argued passkeys were built by engineers who never understood how ordinary users think, and it struck a nerve on Hacker News. FIDO Alliance's own 2026 survey shows why: awareness has hit 90%, but only about half of users actually rely on passkeys day to day.

A Product Chief's Complaint Lands Where FIDO's Own Numbers Show a Gap

Nikita Bier, Head of Product at X, argued that passkeys were designed by security engineers with little regard for how consumers actually think, leaving people unable to evaluate the technology on its merits. He described the resulting experience as needing to produce unspecified "magic fairy dust" to log in, since the credential might live on a phone, in a browser, in an operating system, or tied to a person's body. The post was submitted to Hacker News, where it drew over 100 points and more than 150 comments within hours.

That reaction lines up with a real, measurable pattern rather than just online noise. FIDO Alliance's 2026 global survey of 11,000 consumers found awareness has climbed to 90%, up from 75% a year earlier, and that 75% of people have now enabled a passkey on at least one account, up from 69% in 2025. But the share of people using passkeys across most of their apps barely moved, from roughly 38% to 40%. Awareness and one-time setup have grown quickly. Broad, comfortable daily use has not kept pace.

Passkey adoption grew, but broad daily use barely shifted, 2025 to 2026Grouped horizontal bar chart comparing 2025 and 2026 FIDO Alliance survey figures for two metrics: consumers who enabled a passkey on at least one account, and consumers using passkeys across most of their apps.69%75%38%40%Enabled on ≥1 accountUsing across most apps0%25%50%75%100%Setup Rose Fast. Broad Use Barely Moved.FIDO Alliance consumer survey, 2025 vs. 202620252026Source: FIDO Alliance, State of Passkeys 2026 / 2025 year-over-year comparison

Hacker News Turns the Tweet Into a Fragmentation Case Study

The most-upvoted reply on Hacker News came from a commenter with 26 years in tech who laid out a concrete scenario: a passkey created accidentally in the "wrong" browser or password manager may not be usable on a person's other devices, and there is no consistent, site-by-site answer for how many backup passkeys are allowed or how shared household logins are supposed to work. That specific, first-person confusion — not abstract skepticism about cryptography — is what drove much of the thread's engagement.

FIDO's own funnel data shows where that confusion likely bites hardest. Awareness of passkeys is now nearly universal, and most people who try passkeys do get one set up somewhere. But the share who say they use passkeys "whenever possible" or "most of the time" is meaningfully smaller than the share who have merely turned one on.

From awareness to habit: where passkey adoption narrowsFunnel chart showing 90% of consumers are aware of passkeys, 75% have enabled one on at least one account, and 49% use passkeys regularly, per FIDO Alliance's 2026 survey.Awareness Is Nearly Universal. Habit Isn't.FIDO Alliance, State of Passkeys 2026 consumer surveyAware of passkeys90%Enabled on ≥1 account75%Use regularly49%Source: FIDO Alliance, State of Passkeys 2026 global consumer survey (n=11,000)

Why the Same Passkey Doesn't Follow You Across Devices

The mechanism behind the confusion is documented, not speculative. Several Hacker News commenters, including one describing direct involvement in the standard, explained that the original WebAuthn specification assumed a hardware-bound key created separately on each device. Apple and Google later pushed for passkeys that sync through a cloud-based credential manager, which reduced friction for people who stay inside one ecosystem but fragmented the experience for anyone who moves between an OS keychain, a browser's built-in manager, and a third-party password manager. Ars Technica's review of passkey usability reached a similar conclusion: the cryptography works as intended, but the consumer-facing prompts asking a person to choose where a credential should live are frequently unclear.

That fragmentation has a compliance layer, too. The passkey specification's public list of known client issues documents password managers that don't fully match expected verification behavior, and several commenters noted that services can use this list to block certain credential managers — meaning a passkey stored in a smaller or open-source manager may simply stop working on some sites, with little explanation to the user.

Why a passkey set up on one device may not appear on anotherFlow diagram illustrating that a passkey is saved to a single credential provider, and only appears automatically on another device if that device uses the same provider.One Passkey, One Provider, Two OutcomesBased on WebAuthn implementation reporting, not measured dataUser creates a passkey on Device ASaved to one credential provider onlyDevice B uses the same providerPasskey appears automaticallyDevice B uses a different providerPasskey is not foundFalls back to password,backup code, or QR/Bluetooth relayBased on Hacker News technical commentary, Ars Technica reporting, and passkeys.dev documentation

What the Complaint Gets Right, and What It Leaves Out

Bier's underlying point — that most consumers can't fully explain where their passkey lives or how it moves between devices — matches both the Hacker News thread and the mechanism FIDO's and Ars Technica's material describe. The fallback paths do generally work: nearly every implementation discussed in the thread still allows a password or backup code when a passkey isn't available, so the failure mode is confusion and abandoned setup rather than permanent lockout in most cases.

What the criticism doesn't address is the underlying security case for passkeys, which the sourced material doesn't dispute: credentials that can't be typed into a phishing page, and can't be reused across a breached site, close off two of the most common attack paths against passwords. The open question, based on what FIDO's own numbers show, is not whether passkeys work, but whether the industry has explained the workflow — multiple providers, inconsistent export rules, and a compatibility list that can get a manager blocked — clearly enough for the 75% who've enabled one to actually rely on it.

Comments (0)

Sort by:

No comments yet.

Be the first to share your perspective on this topic.