Passkeys still failing on UX and trust
The 'I don't like passkeys' thread drew significant engagement, with commenters landing on two distinct complaints. First, the marketing problem: nobody can explain what a passkey actually is without reaching for jargon, and different OS vendors (Apple, Google) are actively competing to own the user experience in ways that create lock-in and confusion. Second, the trust problem: passkeys solve for company liability, not user security. The 'we got hacked but your passwords weren't leaked' email is the actual use case they were designed for.
The frustration is particularly sharp around aggressive adoption pushes from Amazon and PayPal, which are treating passkey enrollment as a dark pattern rather than a genuine user benefit. Several commenters noted that the per-device nature of passkeys, combined with OS-level wallet capture, makes them feel like the company extracting something from the user rather than giving something to them.
This is a recurring HN theme, but the intensity has picked up as passkeys go from experimental to default at major consumer platforms.
So what?
If you are building authentication for a consumer product right now, passkeys are the direction the industry is going, but the UX is still broken enough that aggressive rollout will cost you users. The better play is opt-in with clear language about what the user gets, not mandatory migration that feels coercive.