Windows Passkey ?
Author
Discussion

Andeh1

Original Poster:

7,598 posts

236 months

Sunday 20th September
quotequote all
I would normally class myself as pretty tech savvy, but for the life of me Windows Passkey is really pissing me off.

It's annoying enough to have to use a pin to log into windows (I miss the days of it just booting straight to desktop...) but to now have Windows clearly trying to force me down the route of using it, when my uber-complex password has been sufficient for the last 20 years, to get into my emails.

I have to click around it, to find the link to let me use another sign in...to finally get me back to my password.

is it just me? Is there a way to disable it entirely?

p4cks

7,502 posts

229 months

Sunday 20th September
quotequote all
Invasive isn’t it?! Even eBay try it and you have to search for the option to log in the old school way

arandomstranger

81 posts

115 months

Sunday 20th September
quotequote all
Windows Passkeys seem to be the Windows ME of 2026. A rubbish new thing where you can't quite pin down a common issue...everyone seems to have a unique problem.

xeny

5,482 posts

108 months

Monday 21st September
quotequote all
Andeh1 said:
It's annoying enough to have to use a pin to log into windows (I miss the days of it just booting straight to desktop...) but to now have Windows clearly trying to force me down the route of using it, when my uber-complex password has been sufficient for the last 20 years, to get into my emails.
Windows, or the service providing your email?

i don't particularly like passkeys, but people are so good at being phished that I can understand why online services are promoting them so vigorously.

The Mad Monk

11,497 posts

147 months

Monday 21st September
quotequote all
I am not very tech savvy, so please bare (bear?) with me.

1. If the PC has been turned off, press the little button under the screen (Dell AIO).
2. It goes through its start up routine and then a pretty picture come on the screen.
3. After a few secs, I click somewhere on the screen, a little box comes up, I type in my PIN and we are away.

I can go straight into mail, or Google, or umpteen other things.

Is this what we are talking about? Because it isn't difficult - even for me.

Griffith4ever

6,946 posts

65 months

Monday 21st September
quotequote all
The Mad Monk said:
I am not very tech savvy, so please bare (bear?) with me.

1. If the PC has been turned off, press the little button under the screen (Dell AIO).
2. It goes through its start up routine and then a pretty picture come on the screen.
3. After a few secs, I click somewhere on the screen, a little box comes up, I type in my PIN and we are away.

I can go straight into mail, or Google, or umpteen other things.

Is this what we are talking about? Because it isn't difficult - even for me.
The issue is that other services now demand it.

I'm on holiday so every site I use is suspicious.

Log into ebay with passoword? not good enough, must use passkey too. I guess its a form of 2FA.

The problem is when it insists on using anotehr device - i.e. my phone. Often that means I have to go get my phone - which isn't always easy - currently my phone is at the other end of our villa garden being a wifi repeater.

Paypal? same.
Amazon, same.

I'm not too annoyed as its another layer of security, but it is a touch annoying when we use complex passowrds and thats not enough any more.

xeny

5,482 posts

108 months

Monday 21st September
quotequote all
Griffith4ever said:
we use complex passowrds and thats not enough any more.
Problem is that people are too trivially phishable. Internal IT security team was recently conducting a phishing "training" campaign.

They stopped after nearly 1/3 of the organisation fell for one of their emails, making it hard for them to claim people were getting better at spotting phishing emails - it's a case of how well the phish subject matches email the person typically receives.

MFA makes phished credentials far less useful, but I haven't the heart to tell the security team that it does very little against MITM attacks, so presumably that will be the next line of attack.

Mr Pointy

13,384 posts

189 months

Monday 21st September
quotequote all
Griffith4ever said:
The issue is that other services now demand it.

I'm on holiday so every site I use is suspicious.

Log into ebay with password? not good enough, must use passkey too. I guess its a form of 2FA.

The problem is when it insists on using another device - i.e. my phone. Often that means I have to go get my phone - which isn't always easy - currently my phone is at the other end of our villa garden being a wi-fi repeater.

Paypal? same.
Amazon, same.

I'm not too annoyed as its another layer of security, but it is a touch annoying when we use complex passwords and that's not enough any more.
Why don't you use a cross-platform password manager then the passkeys are shared:
https://bitwarden.com/en-gb/resources/are-passkeys...

Mr Pointy

13,384 posts

189 months

Monday 21st September
quotequote all
Andeh1 said:
I would normally class myself as pretty tech savvy, but for the life of me Windows Passkey is really pissing me off.

It's annoying enough to have to use a pin to log into windows (I miss the days of it just booting straight to desktop...) but to now have Windows clearly trying to force me down the route of using it, when my uber-complex password has been sufficient for the last 20 years, to get into my emails.

I have to click around it, to find the link to let me use another sign in...to finally get me back to my password.

is it just me? Is there a way to disable it entirely?
Just set Windows up so it boots without a password then. That's what mine does.

arandomstranger

81 posts

115 months

Monday 21st September
quotequote all
Mr Pointy said:
Just set Windows up so it boots without a password then. That's what mine does.
I presume you're joking? It's difficult to tell on forum posts.

Mr Pointy

13,384 posts

189 months

Monday 21st September
quotequote all
arandomstranger said:
Mr Pointy said:
Just set Windows up so it boots without a password then. That's what mine does.
I presume you're joking? It's difficult to tell on forum posts.
No, why would it be a joke? I turn my desktop on, it boots to the desktop. Windows 11, fully up to date.

My laptop, on the other hand, is set up to require a password on boot up because it's used outside of the house.

butchstewie

67,732 posts

240 months

Monday 21st September
quotequote all
Hope people have their passkeys backed up.

ARH

2,081 posts

269 months

Monday 21st September
quotequote all
Mr Pointy said:
arandomstranger said:
Mr Pointy said:
Just set Windows up so it boots without a password then. That's what mine does.
I presume you're joking? It's difficult to tell on forum posts.
No, why would it be a joke? I turn my desktop on, it boots to the desktop. Windows 11, fully up to date.

My laptop, on the other hand, is set up to require a password on boot up because it's used outside of the house.
My windows install does this, I set auto login years ago. My Linux daily driver does as well.

phil4

1,649 posts

268 months

Monday 21st September
quotequote all
Passkeys have some great upsides, and if we stopped there they'd be the solution to almost all hacking, phishing, MITM and similar attacks.

However it seems someone forgot about the users. So while in isolation one of them is easy to deal with, having multiple, and using more than just a phone or a PC starts making it much harder (see the previous comment about needing a cross platform password manager), and backing up nigh on impossible.

I think they're going to struggle to gain traction until cross platform storage is ubiquitous. At the moment, chrome, windows, apple and the password managers all compete, and with no backup, you can't move one that chrome just created to your password manager.

carl_w

10,757 posts

288 months

Monday 21st September
quotequote all
phil4 said:
However it seems someone forgot about the users. So while in isolation one of them is easy to deal with, having multiple, and using more than just a phone or a PC starts making it much harder (see the previous comment about needing a cross platform password manager), and backing up nigh on impossible.
If you go all-in on the Apple ecosystem the passkeys are shared between iPhone and Mac.

Griffith4ever

6,946 posts

65 months

Monday 21st September
quotequote all
Mr Pointy said:
Why don't you use a cross-platform password manager then the passkeys are shared:
https://bitwarden.com/en-gb/resources/are-passkeys...
At a glance, I didn't understand any of whats on that link

jimmyjimjim

8,290 posts

268 months

Tuesday 22nd September
quotequote all
xeny said:
Griffith4ever said:
we use complex passowrds and thats not enough any more.
Problem is that people are too trivially phishable. Internal IT security team was recently conducting a phishing "training" campaign.

They stopped after nearly 1/3 of the organisation fell for one of their emails, making it hard for them to claim people were getting better at spotting phishing emails - it's a case of how well the phish subject matches email the person typically receives.

MFA makes phished credentials far less useful, but I haven't the heart to tell the security team that it does very little against MITM attacks, so presumably that will be the next line of attack.
Our IT team conduct regular phishing tests. I like to think we do well in spotting them, but I think we've all failed one.

In return, one of the IT team said something on the group chat that sparked an amusing exchange
IT bod posted a link
Someone replied that it looked suspicious and that we should ask IT about it.
"I am IT security!"
"Are you really?"
"I'm not sure he is"
"Let's ask someone else".
"I know him, he's making it up"
Oh, god but he got pissed. It was hilarious.

xeny

5,482 posts

108 months

Tuesday 22nd September
quotequote all
jimmyjimjim said:
Our IT team conduct regular phishing tests. I like to think we do well in spotting them, but I think we've all failed one.
.
MS offer a list of domains to use for phishing tests. email rules to auto delete anything associated with them is an easy way to improve the stats......

mmm-five

12,379 posts

314 months

Tuesday 22nd September
quotequote all
jimmyjimjim said:
Our IT team conduct regular phishing tests. I like to think we do well in spotting them, but I think we've all failed one.

In return, one of the IT team said something on the group chat that sparked an amusing exchange
IT bod posted a link
Someone replied that it looked suspicious and that we should ask IT about it.
"I am IT security!"
"Are you really?"
"I'm not sure he is"
"Let's ask someone else".
"I know him, he's making it up"
Oh, god but he got pissed. It was hilarious.
Similar happened at my last job, and whilst I never failed one I might have been over-zealous in reporting an email from the Head of Procurement when they used a personal email address to try to get an invoice paid urgently for a supplier who was threatening to cut off our supply of raw materials (about £350k was supposedly 3 months overdue).

I had a look in our systems and saw the outstanding invoice as described, but 1) I didn't know if it was genuinely overdue or held for a specific reason (usually wrong PO number, quality issues or missing items); 2) it wasn't my PO/invoice; and 3) I couldn't authorise invoices over £1k anyway (as I was an agency worker).

It had all the hallmarks of a scam...it was from an external email, it was asking for something to be rushed, the language used was poor, and I'd never before received even an internal email from this person in my life.

Seems she'd been trying to get someone else in Procurement to chase/rush it, but as it was a public holiday(s) in that country she decided to mass-email everyone in the Procurement email list instead...and for some unknown reason didn't have access to her company accounts.

butchstewie

67,732 posts

240 months

Tuesday 22nd September
quotequote all
Griffith4ever said:
Mr Pointy said:
Why don't you use a cross-platform password manager then the passkeys are shared:
https://bitwarden.com/en-gb/resources/are-passkeys...
At a glance, I didn't understand any of whats on that link
This is the point.

Passkeys are good but like voodoo to normal people - hell even to a lot of IT people.