Windows Passkey ?
Author
Discussion

Andeh1

Original Poster:

7,596 posts

235 months

I would normally class myself as pretty tech savvy, but for the life of me Windows Passkey is really pissing me off.

It's annoying enough to have to use a pin to log into windows (I miss the days of it just booting straight to desktop...) but to now have Windows clearly trying to force me down the route of using it, when my uber-complex password has been sufficient for the last 20 years, to get into my emails.

I have to click around it, to find the link to let me use another sign in...to finally get me back to my password.

is it just me? Is there a way to disable it entirely?

p4cks

7,492 posts

228 months

Invasive isn’t it?! Even eBay try it and you have to search for the option to log in the old school way

arandomstranger

73 posts

114 months

Windows Passkeys seem to be the Windows ME of 2026. A rubbish new thing where you can't quite pin down a common issue...everyone seems to have a unique problem.

xeny

5,469 posts

107 months

Yesterday (07:37)
quotequote all
Andeh1 said:
It's annoying enough to have to use a pin to log into windows (I miss the days of it just booting straight to desktop...) but to now have Windows clearly trying to force me down the route of using it, when my uber-complex password has been sufficient for the last 20 years, to get into my emails.
Windows, or the service providing your email?

i don't particularly like passkeys, but people are so good at being phished that I can understand why online services are promoting them so vigorously.

The Mad Monk

11,460 posts

146 months

Yesterday (07:50)
quotequote all
I am not very tech savvy, so please bare (bear?) with me.

1. If the PC has been turned off, press the little button under the screen (Dell AIO).
2. It goes through its start up routine and then a pretty picture come on the screen.
3. After a few secs, I click somewhere on the screen, a little box comes up, I type in my PIN and we are away.

I can go straight into mail, or Google, or umpteen other things.

Is this what we are talking about? Because it isn't difficult - even for me.

Griffith4ever

6,894 posts

64 months

Yesterday (08:20)
quotequote all
The Mad Monk said:
I am not very tech savvy, so please bare (bear?) with me.

1. If the PC has been turned off, press the little button under the screen (Dell AIO).
2. It goes through its start up routine and then a pretty picture come on the screen.
3. After a few secs, I click somewhere on the screen, a little box comes up, I type in my PIN and we are away.

I can go straight into mail, or Google, or umpteen other things.

Is this what we are talking about? Because it isn't difficult - even for me.
The issue is that other services now demand it.

I'm on holiday so every site I use is suspicious.

Log into ebay with passoword? not good enough, must use passkey too. I guess its a form of 2FA.

The problem is when it insists on using anotehr device - i.e. my phone. Often that means I have to go get my phone - which isn't always easy - currently my phone is at the other end of our villa garden being a wifi repeater.

Paypal? same.
Amazon, same.

I'm not too annoyed as its another layer of security, but it is a touch annoying when we use complex passowrds and thats not enough any more.

xeny

5,469 posts

107 months

Yesterday (08:49)
quotequote all
Griffith4ever said:
we use complex passowrds and thats not enough any more.
Problem is that people are too trivially phishable. Internal IT security team was recently conducting a phishing "training" campaign.

They stopped after nearly 1/3 of the organisation fell for one of their emails, making it hard for them to claim people were getting better at spotting phishing emails - it's a case of how well the phish subject matches email the person typically receives.

MFA makes phished credentials far less useful, but I haven't the heart to tell the security team that it does very little against MITM attacks, so presumably that will be the next line of attack.

Mr Pointy

13,354 posts

188 months

Yesterday (09:04)
quotequote all
Griffith4ever said:
The issue is that other services now demand it.

I'm on holiday so every site I use is suspicious.

Log into ebay with password? not good enough, must use passkey too. I guess its a form of 2FA.

The problem is when it insists on using another device - i.e. my phone. Often that means I have to go get my phone - which isn't always easy - currently my phone is at the other end of our villa garden being a wi-fi repeater.

Paypal? same.
Amazon, same.

I'm not too annoyed as its another layer of security, but it is a touch annoying when we use complex passwords and that's not enough any more.
Why don't you use a cross-platform password manager then the passkeys are shared:
https://bitwarden.com/en-gb/resources/are-passkeys...

Mr Pointy

13,354 posts

188 months

Yesterday (09:05)
quotequote all
Andeh1 said:
I would normally class myself as pretty tech savvy, but for the life of me Windows Passkey is really pissing me off.

It's annoying enough to have to use a pin to log into windows (I miss the days of it just booting straight to desktop...) but to now have Windows clearly trying to force me down the route of using it, when my uber-complex password has been sufficient for the last 20 years, to get into my emails.

I have to click around it, to find the link to let me use another sign in...to finally get me back to my password.

is it just me? Is there a way to disable it entirely?
Just set Windows up so it boots without a password then. That's what mine does.

arandomstranger

73 posts

114 months

Yesterday (15:28)
quotequote all
Mr Pointy said:
Just set Windows up so it boots without a password then. That's what mine does.
I presume you're joking? It's difficult to tell on forum posts.

Mr Pointy

13,354 posts

188 months

Yesterday (16:49)
quotequote all
arandomstranger said:
Mr Pointy said:
Just set Windows up so it boots without a password then. That's what mine does.
I presume you're joking? It's difficult to tell on forum posts.
No, why would it be a joke? I turn my desktop on, it boots to the desktop. Windows 11, fully up to date.

My laptop, on the other hand, is set up to require a password on boot up because it's used outside of the house.

butchstewie

67,455 posts

239 months

Yesterday (16:55)
quotequote all
Hope people have their passkeys backed up.

ARH

2,050 posts

268 months

Yesterday (17:15)
quotequote all
Mr Pointy said:
arandomstranger said:
Mr Pointy said:
Just set Windows up so it boots without a password then. That's what mine does.
I presume you're joking? It's difficult to tell on forum posts.
No, why would it be a joke? I turn my desktop on, it boots to the desktop. Windows 11, fully up to date.

My laptop, on the other hand, is set up to require a password on boot up because it's used outside of the house.
My windows install does this, I set auto login years ago. My Linux daily driver does as well.

phil4

1,646 posts

267 months

Yesterday (17:15)
quotequote all
Passkeys have some great upsides, and if we stopped there they'd be the solution to almost all hacking, phishing, MITM and similar attacks.

However it seems someone forgot about the users. So while in isolation one of them is easy to deal with, having multiple, and using more than just a phone or a PC starts making it much harder (see the previous comment about needing a cross platform password manager), and backing up nigh on impossible.

I think they're going to struggle to gain traction until cross platform storage is ubiquitous. At the moment, chrome, windows, apple and the password managers all compete, and with no backup, you can't move one that chrome just created to your password manager.

carl_w

10,740 posts

287 months

Yesterday (17:44)
quotequote all
phil4 said:
However it seems someone forgot about the users. So while in isolation one of them is easy to deal with, having multiple, and using more than just a phone or a PC starts making it much harder (see the previous comment about needing a cross platform password manager), and backing up nigh on impossible.
If you go all-in on the Apple ecosystem the passkeys are shared between iPhone and Mac.

Griffith4ever

6,894 posts

64 months

Yesterday (19:18)
quotequote all
Mr Pointy said:
Why don't you use a cross-platform password manager then the passkeys are shared:
https://bitwarden.com/en-gb/resources/are-passkeys...
At a glance, I didn't understand any of whats on that link

jimmyjimjim

8,281 posts

267 months

xeny said:
Griffith4ever said:
we use complex passowrds and thats not enough any more.
Problem is that people are too trivially phishable. Internal IT security team was recently conducting a phishing "training" campaign.

They stopped after nearly 1/3 of the organisation fell for one of their emails, making it hard for them to claim people were getting better at spotting phishing emails - it's a case of how well the phish subject matches email the person typically receives.

MFA makes phished credentials far less useful, but I haven't the heart to tell the security team that it does very little against MITM attacks, so presumably that will be the next line of attack.
Our IT team conduct regular phishing tests. I like to think we do well in spotting them, but I think we've all failed one.

In return, one of the IT team said something on the group chat that sparked an amusing exchange
IT bod posted a link
Someone replied that it looked suspicious and that we should ask IT about it.
"I am IT security!"
"Are you really?"
"I'm not sure he is"
"Let's ask someone else".
"I know him, he's making it up"
Oh, god but he got pissed. It was hilarious.

xeny

5,469 posts

107 months

jimmyjimjim said:
Our IT team conduct regular phishing tests. I like to think we do well in spotting them, but I think we've all failed one.
.
MS offer a list of domains to use for phishing tests. email rules to auto delete anything associated with them is an easy way to improve the stats......