Search Results for 'feed'

Switching Password Managers in 2026

Important Note: Although I work at Apple in the password management and app/website authentication spaces, in this post I am speaking only for myself, personally. There is no “news” in this post or any kind of “inside scoop”. Please do share this post, but if I see “Apple’s Ricky Mondello” anywhere, I’ll be sad. My intention is to help people benefit from data portability and interoperability work I’ve personally participated in. Nobody should feel locked into their password manager. :)

Would you believe me if I told you that the best device to switch password managers on might be your iPhone or iPad? For many pairs (exporter and importer) of apps, it’s true! Here’s a simultaneously boring and exciting video of me exporting 100 items from 1Password and into Apple Passwords.

To export from 1Password’s iOS app, navigate to Items › Settings › Advanced › Start Export. After approving the export, an iOS system interface confirms the data transfer request with Face ID and has me select the destination app. I pick “Passwords” (Apple Passwords), confirm my selection, and then Passwords opens to import the data. The data that’s exported from 1Password and imported to Apple Passwords includes passwords, passkeys, verification codes, notes, and more. No data is deleted from 1Password as part of the export.

Apps that support this mechanism include Apple Passwords, 1Password, Bitwarden, Dashlane, DuckDuckGo, Devolutions, and more.

You might be wondering how a mobile operating system (of all places!) got data interoperability for password managers that’s easier, more secure, and more comprehensive than on desktop.[1] You can thank passkeys and the passkey community for this. (But wait — didn’t you read on X or Hacker News that passkeys are just a trojan horse for platform and password manager vendor lock-in? Weird!)

I gave a keynote at the Identiverse conference this last June that, in part, tells the story of how delivering data interoperability for passkeys necessitated a bunch of standardization and innovation that’s made the password manager interoperability story better for everyone. (Here’s a timestamped YouTube link to the relevant portion, starting at 24:48.)

Transcribed, the story:

Back in 2022, when passkeys were first made available on iPhone, one of the most important bits of feedback that the community gave Apple was: “Are these my credentials? My credentials that I can move between apps like passwords and a password manager? Or are they locked to wherever I initially saved them?” The answer to this was easy. Your credentials are yours to take and manage in whatever software you want, on whatever platform you want, whenever you want.

We just needed to figure out how to enable that in a phishing-resistant way. At the time, the state of the art for transferring credential data wasn’t great. I’m talking about manually exporting an unencrypted file and then importing it into another app. And I think you all know that was going to be a non-starter for passkeys because a threat actor could trick someone into exporting their data and then uploading it to them. That’s called phishing.

For data interoperability for passkeys to maintain their phishing-resistant promise and their ease of use, we were gonna need to work together and innovate as an entire community. And so, some folks within the FIDO Alliance started working on a concrete data format and requirements around transfer. In May of 2024, the first draft of the Credential Exchange format was published.

That format, which is now published as an open spec that anyone can read, covers not just passkeys, but all of the rich data that you’ll find in a modern credential management app. At Apple, we started building on top of that work. And as of iOS 26 and macOS 26 released last fall, passkeys are now securely transferable between credential manager apps on Apple’s platforms. And that’s through a first-class mechanism that was built specifically for those apps.

Here’s how it works. In the first app, you select the data that you want to export, and then you initiate a system export. In a secure, isolated, and out-of-process picker, you choose which of the registered other apps you want to transfer that data to. Then you Face ID, and you’re done. The data is transferred directly between the two apps that you have trust of, without any intermediate files being created.

Then What?

A data transfer starting on an iPhone or iPad is genuinely a fantastic start, but I recommend thinking about switching password managers as a process. You can use the relatively rare and potentially disruptive event of switching password managers as a reason to clean house a bit. Back in September of 2024, I wrote a piece titled “Consider Slowing Down When Switching Password Managers” about this, but I’m going to summarize and update my advice in this post so you don’t have to go back and read that one.

My tips:

  1. If you’re fortunate enough to be able to, upgrading your phone is a great time to switch password managers! Many apps will, annoyingly, make you re-sign in. You can use that as an opportunity to stress test your new setup. You might also be in a mood to rearrange your apps, refresh your settings, and generally tidy up. I recommend you:
    1. Do your bulk transfer from your old app to your new app on your existing device, as described above, before you get your new device.
    2. Going forward, treat your new app as the source of truth for your information, and only consult the old app if something goes wrong. Do not spend time updating or deleting information from the old app; it’s only there as a safety net. Don’t try to keep multiple password managers in sync; with today’s technology, that’s folly.
    3. On your existing device, turn on AutoFill for your new app and turn off AutoFill for your old app. You’ll have a much better experience if you’re not having nearly identical suggestions duplicated from two apps.
    4. When you get your new device, let iOS copy your content and settings from your existing phone to your new one. Whether you do that or not, check to ensure that your data transferred in both your new and old apps, and then ensure AutoFill is only enabled for your new app.
  2. Wait as long as you can[2] to delete the exporting app and its contained data, which now serves as a backup. Although the data interoperability standard smooths over incompatibilities, software is still software. Deleting your old app could feel good, but you’re throwing away an important backup. Do stop paying for your old app whenever you’re able to, but don’t delete your account. Again, safety net.
  3. If you have time, visit the apps and websites that you have credentials saved for and log in to check if your account is still in good standing. If your password has any security issues, generate and save a new strong password, and then see if you can enable a passkey, or failing that, a verification code generator. You’ll sometimes learn that a website doesn’t exist anymore!

If You’re Switching to Apple Passwords

Here are a few things you might want to know:

  1. The Passwords app gets bug fixes, enhancements, and new features with Apple OS releases, so try to run the latest versions of those operating systems to make sure you’re not missing out. If you haven’t updated to macOS Tahoe yet, macOS Golden Gate’s Passwords app is a pretty big leap forward from version 1.x on macOS Sequoia!
  2. The app supports shared groups (like, a shared folder) and has password histories. The app does not support custom fields, although there is a single notes field on every item.
  3. When adding something new to Passwords, both a user name and password are optional. You can have an item that’s just a title and a note! For richer secure notes, Apple’s Notes app is great.
  4. The Mac app has a menu extra that can be enabled in the app’s settings. It’s handy!
  5. The Mac app supports AutoFill in non-Safari browsers with the iCloud Passwords browser extension. In the app’s “Passwords” menu, select “Get Browser Extension…” to see a list of your installed browsers with links to install the extension in that browser. (Fun fact: the data that powers this view is an open source JSON file.)
  6. The app has a Security tab that tells you about passwords that are weak, reused, or have appeared in a data leak. It’s similar to 1Password’s Watchtower feature, but is powered by an Apple service.
  7. Apple Passwords is available on Windows by installing iCloud for Windows. This link is also in the Help menu of the Mac and iPad apps.
  8. The Passwords app unlocks using Face ID, Touch ID, or your device passcode or Mac login password. You cannot set a different “master” password.
  9. Exporting your data from Apple Passwords works completely offline using the data present on your device. You don’t have to be signed in to an Apple Account.

About Values

I genuinely don’t care a lot about what password manager people use[3], but it’s important to me personally that people have ownership of their data and never feel locked into software. The now-legacy password manager data portability experience served as a user experience moat around software and was a non-starter for both passkeys and everyday computer users.

At a FIDO Alliance meeting in May of 2023, when folks from 1Password and Dashlane were demonstrating a proof of concept for transferring credential data from one app to another, I recommended breaking the data format and transport layers into two different work items, and my recommendation was adopted. The data format became the Credential Exchange Format, which is transformed into Swift structs for strongly-typed and versioned data interoperability on iOS, iPadOS, and macOS. I’m happy with how a collaboration on a data portability standard married nicely with an operating system capability, and it makes me happy to be able to directly contribute to work that aligns with my values.

1Password’s recent investment in the Omarchy Linux distribution, created by the outspoken and dangerous David Heinemeier Hansson, and the subsequent industry conversation, inspired me to “fast”-track publishing updated advice on switching password managers. This investment was justifiably criticized by many, including employees of 1Password. I feel for those employees because it’s a terrible feeling when the impact of your work is diminished by actions you had no say in and can’t control.

In this moment, where we’re globally reckoning with the influence of regressive ideas, organized far-right extremists, and the bottomless pockets of the ultra-wealthy, many people appreciated the ability to express their disappointment and freely move their data between password manager apps. Technology is not and has never been morally neutral or exempt from moral consideration.


  1. This OS-facilitated secure data transfer capability exists on macOS, and Apple Passwords supports it. 1Password and some other apps haven’t adopted it there yet.  ↩

  2. I personally switched away from 1Password and to Apple Passwords about ten years ago, but I still have an old copy of 1Password running on one of my Macs. I admit that this may have been easier to do before the advent of subscription software!  ↩

  3. You know, as long as it has a good track-record of responding to security issues.  ↩

How I’m Doing at the End of 2025

I am in the process of updating my résumé. Not because I’m looking for a job[1], but because I like to feature my résumé on my website and the current published copy doesn’t reflect my pivot from engineering management to an individual contributor role two years ago. I feel a little bit weird about the misrepresentation, and would rather update the document than take it down. While working on some edits, I was reflecting on how things have been going, and decided to write this “what’s been happening” post as my productive procrastination.

Caretaking

Two years ago, I wrote:

I’m living with my mom in upstate New York, somewhere between Poughkeepsie, NY and Danbury, CT. My mom has several health conditions, including chronic pain and memory impairment, that my sister and I have been helping her manage.

All of this is still the case, but it’s gotten progressively more difficult. Summoning the patience and grace, every day, to show up for someone else who is almost always in pain and is regularly in need of help navigating tasks involving any kind of bureaucracy — it’s hard. To tell you the truth, it’s been really hard. And before you ask, in my experience, it’s harder to find in-home help that actually helps than to shoulder this myself, if that makes sense. Especially in a rural area.

I don’t have much of a community or much in terms of friends where I live. In-person dating also isn’t viable here. I haven’t moved me and my mom closer to friends I have down in the city because her home is familiar to her and she says she’s comfortable here and doesn’t want to move. This is negotiable, but the thought of project managing a move is just too much for me to handle given my regular responsibilities. There’s also no other family besides me and my sister.

The way that I relieve the stress from my caretaking role is to travel to see friends domestically and visit new places internationally as often as I reasonably can. When I travel, my sister, who lives about a half hour away, steps in to take care of things with my mom. That’s hard on her, because as I know full well from doing it for a decade, caretaking is harder without having passive eyes and ears on the person being helped; phone calls and visits reveal less of the ground truth.

But my travels are fun! And travel is especially nice because I no longer use nearly all of my vacation time visiting home, and because I’m lucky enough to travel for work sometimes. This last year I was able to visit Australia, New Zealand, Türkiye, Japan, the SF Bay Area, Seattle, Denver, and Boston.

Putting this together, it feels like I’m living my life in a cycle. I spend a few weeks or months in upstate New York keeping everything on the rails at home while working my sometimes also stressful full-time software engineering job; and then I go somewhere else and feel like a young, vibrant person at the top of my game — funnier, hotter, and smarter than I’ve ever been at any other point in my life; until the point where isolating upstate for a couple of weeks sounds kind of nice.

The balance is very far from perfect, and I know I’ve made it sound difficult in this post, but I am profoundly grateful and happy that I’m able to be here for my mom. She doesn’t deserve her chronic illness. (In fact, nobody deserves chronic illness, and seeing the way that society treats the chronically ill first-hand has been one of the most impactful experiences in my life). She’s a sweetheart, I love her dearly, and being able to be here is meaningful to me. It’s just hard.

Oh, and don’t worry — I have a therapist, and they’re great. :)

Zepbound

I started taking Zepbound earlier this year, and it’s been one of the best things to happen to me in my entire life. With the help of this medication, the constant preoccupation with food I’ve felt my entire life is under control. If you’ve known me for a while, you’ve seen my body change in shape over time as I’ve oscillated between my “regular” state and a way of living where I was managing the stress-eating that I’m prone to at the cost of a wild amount of willpower — almost a singular focus of my being alive. This medication is helping me with my relationship with food more than anything else I’ve tried and I tolerate it extremely well.

Despite all of the bullshit shame that society wants us to feel around needing help with food, I am so happy to talk about this. My primary reason for starting the medication was to address some early signs of potential health issues my doctor and I could see on the horizon. My goal wasn’t and isn’t a target weight or appearance. Instead, it’s to consistently measure some better health markers. I’m happy to say that I’ve started hitting some of those goals!

My employer is paying for most of this very expensive medication, and I’m really happy about that. Early this year I was ready to start paying for it out of pocket ($1000+ a month, ~$500 with coupons), but I figured I’d check with my insurance one last time before ponying up, and it turns out, in 2025, my employer started offering a relevant benefit to employees. After going through a 90 day online course that coaches you through healthy eating, sustainable exercise, and habit building, you’re a candidate for medication like Zepbound.

I was legitimately devastated to have to wait another 90 days to try out this new-to-me form of help after a lifetime of being coached on healthy eating, sustainable exercise, and habit building. And the gatekeeping of it all is legitimately offensive to me. But no matter how devastated or offended I felt, I figured it’d be worth going through the program if I could potentially save hundreds of dollars a month on a medication that, other than the cost, I have no reservations about being on for the rest of my life. With my insurance, I pay roughly $25 a month.

(An aside: If you would benefit from getting help in this area of life, and your health insurance is provided by your employer, and you aren’t your own employer, and your insurance doesn’t cover it, keep checking to see if coverage has changed. I also recommend sending a quarterly letter to your employer’s benefits department making a case for coverage. I also wouldn’t blame anyone for leaving a job ever, but especially for leaving to get coverage on a life-changing medication. And if you work where I work, hit me up if you have questions or want details about the program.)

Career

The last two years have been good for correcting something important: making the work I do in the tech industry matter less to me, compared to other aspects of my life, than it used to. Living with and helping to take care of my mom has helped foster a sense of perspective I was struggling to grow by myself in California[2].

And yet, and I think this is a good thing overall, my work in tech still matters to me and motivates me. I surprised myself earlier this year when I finally accepted a standing invitation to speak at the FIDO Alliance’s “Authenticate” conference and started the difficult work of putting together a story, finding my emotional center around that story, and iterating on how I told that story with the help of my colleagues until it was a story I was excited to tell.

Said more directly, putting a good conference talk together is a shit-ton of work. I was asking myself, “Who is this Ricky? Am I happy that they’re back?” And during the more busy moments with the rest of my day job and the tougher moments of taking care of my mom, I was very seriously cursing myself. A feeling I find to be unpleasant, but also useful and validating, is when I have enough presence of mind to recognize that I’ve stretched myself too thin, and that some part of my life is merely getting the best I can give it right now and not what I wish I could give it right now. (What’s much worse than this feeling is to lose myself enough that I don’t even realize I’m letting people down!)

Fortunately, even I have convinced myself that the talk was good and worth doing. An ongoing project for me right now is iterating on the value proposition of passkeys by collecting and distilling feedback, advocating for changes internally where I work, and talking to my industry colleagues inside and outside of standards to address problems. This is challenging because although I deeply believe in passkeys, I cannot immediately effect change on the many websites, apps, and other passkey managers that make up the overall global experience of and sentiment around them. Despite any and all criticisms people have about passkeys, I am stunned by how well the industry transition away from passwords and to passkeys is going. The momentum is wildly outpacing my expectations.

Outside of passkeys, in 2025, I was really proud of the work my team did to polish the Passwords app after its 1.0, and I figured out how to bring two features to the world that I love because they’ll save people time and maybe make them smile. The first was to offer AutoFill of security codes contained in the contents of app push notifications, including apps like Gmail and WhatsApp, in iOS 26. The second was to offer AutoFill of security codes in all apps on macOS 26, including web browsers. The engineering on this last one was wild, and it wasn’t without complications at launch, but we got ‘em cleaned up, and now more people than ever can use their brains to do things other than manually type six digit codes.

:)

If you read this far, it probably means that you have supported or are supporting me in some way in my life, and I appreciate that! If we’re friend friends and we haven’t chatted in a while, reach out! And if we’re not, please do take me up on meeting up when I toot or skeet that I’m visiting near where you live. Please be kind to yourself, happy holidays, and happy new year!


  1. I’m not looking for a job! I’m happy with my role where I work right now. That said, everyone has a specific combination of both a price and a conscience. My hands aren’t perfectly clean, but I can live with a software job that resolves around saving people time, frustration, and some of the pain of having their online accounts compromised.  ↩

  2. This had a lot to do with the fact that the sole reason I was living in the bay area was for my career.  ↩

Magic Links Have Rough Edges, but Passkeys Can Smooth Them Over

Important Note: On this blog I speak only for myself as someone experienced in usable security and website authentication. I am not speaking for the company I work for. I encourage linking to and talking about this post, but if you can, please identify me without affiliation.[1]

Independent media venture 404 Media recently published a post titled, “We Don’t Want Your Password”. The piece is a cogent explanation of the problems with password-based accounts online followed by a defense of the website’s login strategy, magic links, in the face of feedback about them being inconvenient and difficult to use.

I applaud 404 Media for having the courage to do what they feel is best for them and their customers, even if their customers may not expect it, and I give them a standing ovation for remaining resolute, but thoughtful, in the face of complaints. Passwords are deeply entrenched, and straying from the expected or default path for any kind of service, much less a media venture, is taking a risk. I’ve been meaning to write about my frustrations with and appreciation for magic links for some time now, and the steadfastness and clarity of this post pushed me over the edge to do it.

Obviously, authenticating to websites isn’t an either-or binary between passwords and magic links. Passkeys — the next-generation authentication standard defined by the FIDO Alliance and W3C, with backing from all of the major platforms, browsers, and credential managers — can be layered nicely into a magic link-based system to give users a secure and fast sign-in experience without the frustrations that come with switching apps to refresh one’s email. They’re complementary technologies, because passkeys can do this in a way that seamlessly coexists with, and is in fact supported by, email magic links for people who don’t yet have a passkey, don’t want a passkey, don’t have the device stability to use passkeys, or would prefer to sign in with a magic link this one time.

You’ve almost certainly encountered magic links in your time online. A “magic link” is just the special, one-time link you get emailed to you that will sign you into a website after giving it your email address. And if you’re reading this post, there’s a good chance that you use a password manager and that you find magic links to be far slower than using your password manager to sign into a website.


They frustrate me, too. My local grocery store, one of the many Albertsons companies, has taken to preferring an email magic link over my easily-AutoFilled password, and it frustrates me every single time I try to sign in. Once you’ve experienced a world where signing in to websites and apps is so seamless it requires next to no thought, while still being secure, you never want to go back.

But I also kind of love magic links, because they acknowledge — no, radically accept — some fundamental truths. Namely, that…

  1. almost all online accounts can eventually be signed into by proving possession of an email address; this is usually phrased as “forgot password?”
  2. many of the people who don’t use password managers use that “forgot password?” flow every time they sign in because people cannot use passwords effectively; why shouldn’t they just make that the user experience for everyone, or at least, the default flow?
  3. merely having a password for a service opens a user to attacks like credential stuffing, which is when stolen account credentials are used to gain access to accounts on other systems; credential stuffing is particularly effective because people reuse passwords

The title of 404 Media’s piece very powerfully acknowledges point 3 by saying, “We Don’t Want Your Password”, singular, acknowledging that most people have on average approximately 0.8 correct passwords in their memory at a time. And they’re willing to cop to the negative feedback they’ve gotten, writing:

Probably the most common problem people run into with magic links is they think they have logged into the site on their normal browser, but they’re actually logged in through an in-app browser. For example, someone might receive the login link to their email. They open up the Gmail app, click the “Sign in to 404 Media” button, and their phone loads the webpage. But this is loading the website in Gmail’s web browser, not your native Safari one.

In-app web browsers are unlikely to go anywhere any time soon[2], so the post describes how to work around the problem:

A solution on iPhone is when receiving the login link, click and hold the “Sign in to 404 Media” button to bring up the contextual venue, and hit “Open Link.” This will open the link, and sign you in, on your native browser. Or, copy and paste the sign in link which is also in the email.

Them calling this out is a tell; we can infer that these complaints are a real problem for 404 Media because they saw value in addressing a very specific user experience complaint. The way that their business works is that people directly pay to read their journalism; anything that stands in the way of people getting their money’s worth can impact their bottom line. I can’t say that my local grocery store’s strong preference for magic links has stopped me from being a customer, but that’s likely because I live in an area where they have an effective monopoly.

Something that I’ve learned by working on the user experience around website and app authentication is that, if you need to educate a person to go against what the inline flow naturally leads them to do, that cognitive friction will frustrate or stymie a significant number of people.[3]

Despite these drawbacks, I think that proving possession of an email address as a mechanism for signing into an online account is valuable and has its place for many, but not all, websites and apps, because email is decentralized and universal, email account providers are very highly incentivized entities to protect user accounts (e.g. Apple, Google, or Microsoft aggressively drive email account security forward), and ultimately, most people can follow instructions to check their email. This is of a kind with my belief that although it is far from ideal, SMS 2FA has its place, because authentication technology is all about threat modeling and what actually works in practice.

Passkeys

I’m going to assume that you know what passkeys are and that you’ve used them with your Google, PayPal, or TikTok account, or some other online account. If you need a refresher, I’ll plug my four minute video explanation of passkeys from a few years back that holds up pretty well today.

For the purpose of improving a passwordless authentication strategy using magic links, what’s important to remember is that passkeys suffer from none of the security problems that passwords have, and that signing in with passkeys is super fast, keeps users in their context, and never requires switching over to another app.

When it comes to speed and ease of use, in an April 2024 update on their passkey rollout, Google claimed that passkeys are 50% faster than passwords. And in my personal experience, signing in with passkey can sometimes be an order of magnitude faster than signing in with a magic link.

On iOS and Android, in notable contrast to magic links, passkeys are directly usable across web browser apps and system web view experiences. (Really. Any passkey saved and usable in Safari, whether in Apple Passwords or an app like 1Password, is usable in Chrome for iOS, Firefox for iOS, Gmail for iOS, and more.) So if a user follows a link to 404 Media in any web browser or in any email or social media app that makes use of the system web view, they can use their passkey to sign in within seconds. This is even true in web browsers like Chrome and Firefox on macOS!

For a user to sign in with a magic link, they first need to type or AutoFill their email address into a text field on a website.

Here’s the magic: Passkeys can seamlessly integrate into AutoFill.[4] Instead of filling the literal email address, AutoFill can sign the user in with one tap and a Face ID, while behind the scenes performing the strong authentication that powers passkeys. Here’s a six-second video showing me using AutoFill and a passkey to sign into my Google account in Safari on my iPhone:

Video showing opening the Google sign-in page loading in Safari. The page has a single “Email or phone” field. Near-instantly after the page loads, an AutoFill affordance appears, saying, “Sign in to google.com with your passkey for “email@example.com”?”. It features a big blue button that reads, “Use Passkey”, and tapping it performs a Face ID that signs me in.

The most important part of this experience is that it causes zero disruptions for people who don’t already have a passkey. Here’s what’s visible in Safari on my iPhone when I don’t have a saved passkey:

Screenshot of the Google sign-in page in Safari. The page has a single “Email or phone” field. The standard text insertion keyboard is present.

You’ll notice that this looks like a totally pedestrian web form asking the user to enter their email address. The Google website has still asked the browser to help it sign in using a passkey, but since I don’t have one, I’m left to type my email address.

The website of my grocery store, as well as 404 Media’s website, could work exactly the same way, with a field for the user’s email address that is progressively enhanced to have passkey sign-in when it’s available. And all of this works without a password. (For a resource on how to implement something like this, see the footnote attached to this sentence.[5])

To start, websites using magic links can make passkeys an optional, opt-in feature for the customers who have complained about how their magic links work today. To ensure it doesn’t cause any problems, as a sort of soft launch, they could make the feature 100% opt-in.

Slightly later on, once the people running the website are convinced that passkeys really help with the user experience issues around magic links, they can prompt users to add passkeys after signing in, once every 90 days or so, or whenever they sign-in using the cross-device sign-in feature of passkeys[6]. The framing of such a prompt can be something like this for users on Apple devices: Want to avoid having to check your email next time? Set up a passkey to use Face ID or Touch ID to sign in quickly and securely.

The Role of Software Platforms

The user experience and security of what I’ve demonstrated are a clear improvement over either password-based sign-in or a magic links-only experience, but in the world of running a business, nothing is free. In fact, doing literally anything at any kind of scale takes a lot more work than any of us like to think, especially for folks who have gone independent. A corporation like Albertsons may be able to afford to build and deploy passkey support, but developing and deploying a one-off feature like passkey support in 404 Media’s content management system almost certainly will not be worth the cost to them as a small business in the struggling field of online journalism.

And yet, I still wrote this post! Why is that? :)

Like a large portion of the web, 404 Media is using an open software platform (in this case, Ghost) to power their venture. If the world can convince Ghost and other platforms like WordPress and Mastodon to support passkeys, and maybe even contribute time, money, or expertise to make it happen, a huge number of people stand to benefit.

Resources

If you’re in a position to implement passkeys or influence an organization to implement them, I think it’s time to evaluate, engage with, and implement passkeys. Here are some resources I recommend you check out:

I’m also personally happy to answer questions and talk with folks considering adopting passkeys. I’m serious — hit me up.

Takeaways

I want to see my friends, family, and people who I will never meet no longer harmed by passwords, and I have dedicated the last five years of my career to dethroning them as the default credential for websites and apps. Passkeys aren’t perfect, because nothing is, but myself and other members of the FIDO Alliance are always listening to feedback and working to improve them. And as they exist today, they can clearly make the experience of signing into websites faster and easier than before.

Again, if you have questions about passkeys or authentication technologies in general, feel free to hit me up on Mastodon or Bluesky. I hope you learned something, and thanks for reading!


  1. As you can tell, I am taking great pains to not have my blog meaningfully affiliated with my employer. I am doing this to respect my employer’s desire to not have employees interpreted as speaking for the company when they are speaking only for themselves. As a proud member of technology standards organizations with noble goals, and as an independent person, I hope I can help the industry by contributing my perspective from time to time. If being pressured to not emphasize my employer in a link post dissuades you from linking to it, then I didn’t deserve your link in the first place. :)  ↩

  2. The incentives, economics, and privacy considerations around in-app web browsers is a fascinating and important story, but one I am not able to tell.  ↩

  3. If you’ll give me some leeway, I think it’s analogous to password management software in that password management software has a ceiling to the number of people it can help, because fundamentally, it is laying instructions and a process on top of websites and apps that expect people to create and type passwords by hand. The dissonance that I’m describing here is similar to the difficult to remember to do advice to copy and paste a sign-in link that is screaming to be tapped. This advice is almost begging you to inhabit the mental model of how browser cookies work, which is something that normal people shouldn’t have to do.

    This ceiling for the number of people password management software can help is part of why I believe so strongly in passkeys. A single, attractive affordance for signing in can confuse fewer people than whatever a password manager lays on top of a web page.  ↩

  4. In WebAuthn parlance, the use of passkeys with the AutoFill user experience is called “conditional mediation”. It’s not just a powerful tool for integrating with magic links, but also with existing password-based sign-in experiences.  ↩

  5. WebAuthn Conditional UI (Passkeys Autofill) Technical Explanation, a post from the Cordabo blog, goes into detail on how to implement conditional mediation for passkeys.  ↩

  6. As demonstrated in the four minute video I linked to, passkeys can be used to sign in across devices. So I can use a passkey on my iPhone to sign into a website on a Windows PC. Websites can detect when this happens, and should turn around and ask the user to register another passkey on the “new” device.  ↩