A new developer essay challenging the consumer push toward passkeys argues that stronger resistance to phishing can come with practical costs in account recovery, portability and user control. The post does not dispute the cryptographic advantages of passkeys; it questions whether today’s ecosystem handles everyday failures well enough for individuals.
Passkeys replace a reusable password with a cryptographic credential tied to a website or service. That construction prevents a credential from being entered into a convincing lookalike domain, addressing a major weakness of passwords and time-based one-time codes. Ethan Hawksley, the essay’s author, calls the underlying technology strong and says it is a major improvement for people who otherwise reuse passwords.
His concern is that a login credential can become entangled with the account and device ecosystem that stores or synchronises it. Losing access to that environment can turn authentication into a recovery problem. The post also argues that service-specific implementations differ enough to make transitions between platforms confusing, while some sites continue to offer fallback mechanisms that dilute the security benefit.
Hardware security keys provide another way to hold passkey credentials, but Hawksley says their limits and the need to maintain backups can complicate use for an individual. Cross-device authentication is designed to bridge devices, often using a nearby-device flow, yet the essay describes real-world connection and Bluetooth failures as sources of friction. Those observations are the author’s experience and assessment, not measurements from a controlled study.
The essay’s preferred alternative is a randomly generated password held in an independent password manager, paired with a separate app for time-based one-time codes. Hawksley acknowledges that this combination remains exposed to sophisticated adversary-in-the-middle phishing, which can relay both a password and a temporary code. He nevertheless argues that recovery and lockout failures present a more common day-to-day risk for many consumers than that attack.
That conclusion depends heavily on a person’s threat model. An employee targeted for access to valuable systems may reasonably prioritise phishing resistance, and centrally managed organisations can provision credentials and recovery procedures. A consumer who frequently changes devices or deliberately avoids a dominant cloud account may assign greater weight to portability and independent backups.
The post therefore adds a useful distinction to a debate often framed as a simple contest between old and new authentication. Passkeys can provide a meaningful security improvement without every current implementation being equally mature. For users, the relevant questions include where the credential is stored, whether it can be moved, what backup authenticators exist and how recovery works before the primary device or platform account is lost.



