A post from X's head of product argued passkeys were built by engineers who never understood how ordinary users think, and it struck a nerve on Hacker News. FIDO Alliance's own 2026 survey shows why: awareness has hit 90%, but only about half of users actually rely on passkeys day to day.
A Product Chief's Complaint Lands Where FIDO's Own Numbers Show a Gap
Nikita Bier, Head of Product at X, argued that passkeys were designed by security engineers with little regard for how consumers actually think, leaving people unable to evaluate the technology on its merits. He described the resulting experience as needing to produce unspecified "magic fairy dust" to log in, since the credential might live on a phone, in a browser, in an operating system, or tied to a person's body. The post was submitted to Hacker News, where it drew over 100 points and more than 150 comments within hours.
That reaction lines up with a real, measurable pattern rather than just online noise. FIDO Alliance's 2026 global survey of 11,000 consumers found awareness has climbed to 90%, up from 75% a year earlier, and that 75% of people have now enabled a passkey on at least one account, up from 69% in 2025. But the share of people using passkeys across most of their apps barely moved, from roughly 38% to 40%. Awareness and one-time setup have grown quickly. Broad, comfortable daily use has not kept pace.
Hacker News Turns the Tweet Into a Fragmentation Case Study
The most-upvoted reply on Hacker News came from a commenter with 26 years in tech who laid out a concrete scenario: a passkey created accidentally in the "wrong" browser or password manager may not be usable on a person's other devices, and there is no consistent, site-by-site answer for how many backup passkeys are allowed or how shared household logins are supposed to work. That specific, first-person confusion — not abstract skepticism about cryptography — is what drove much of the thread's engagement.
FIDO's own funnel data shows where that confusion likely bites hardest. Awareness of passkeys is now nearly universal, and most people who try passkeys do get one set up somewhere. But the share who say they use passkeys "whenever possible" or "most of the time" is meaningfully smaller than the share who have merely turned one on.
Why the Same Passkey Doesn't Follow You Across Devices
The mechanism behind the confusion is documented, not speculative. Several Hacker News commenters, including one describing direct involvement in the standard, explained that the original WebAuthn specification assumed a hardware-bound key created separately on each device. Apple and Google later pushed for passkeys that sync through a cloud-based credential manager, which reduced friction for people who stay inside one ecosystem but fragmented the experience for anyone who moves between an OS keychain, a browser's built-in manager, and a third-party password manager. Ars Technica's review of passkey usability reached a similar conclusion: the cryptography works as intended, but the consumer-facing prompts asking a person to choose where a credential should live are frequently unclear.
That fragmentation has a compliance layer, too. The passkey specification's public list of known client issues documents password managers that don't fully match expected verification behavior, and several commenters noted that services can use this list to block certain credential managers — meaning a passkey stored in a smaller or open-source manager may simply stop working on some sites, with little explanation to the user.
What the Complaint Gets Right, and What It Leaves Out
Bier's underlying point — that most consumers can't fully explain where their passkey lives or how it moves between devices — matches both the Hacker News thread and the mechanism FIDO's and Ars Technica's material describe. The fallback paths do generally work: nearly every implementation discussed in the thread still allows a password or backup code when a passkey isn't available, so the failure mode is confusion and abandoned setup rather than permanent lockout in most cases.
What the criticism doesn't address is the underlying security case for passkeys, which the sourced material doesn't dispute: credentials that can't be typed into a phishing page, and can't be reused across a breached site, close off two of the most common attack paths against passwords. The open question, based on what FIDO's own numbers show, is not whether passkeys work, but whether the industry has explained the workflow — multiple providers, inconsistent export rules, and a compatibility list that can get a manager blocked — clearly enough for the 75% who've enabled one to actually rely on it.
Comments (0)
Please sign in to join the discussion.
No comments yet.
Be the first to share your perspective on this topic.