Why passkeys are a step back for personal security: examining account lockout risks, platform lock-in, hardware key limits, and fragile recovery flows.
You world be very surprised. It’s not what I directly work on, but there are entire programs dedicated to tracking and lowering the cost of password and account resets (and doing it securely). That last part is the hard thing. Large organizations can save millions of dollars if they can get people to not lose/forget their credentials -or- self service those resets (but even then, having that person do it is now losing their time and energy).
It’s not just indirect opportunity costs either, it’s direct costs to the IT organization. Smaller teams can absorb this stuff as a rounding error on their time, but the second you’re counting in the thousands, you need to deal with this type of thing. (And I’ll repeat: securely)
Now imagine doing it as a B2C+B2B organization like Google or Microsoft. The costs are staggering.
Fair, but costs of resets overall. This is not a factor in tech giant costs.
You world be very surprised. It’s not what I directly work on, but there are entire programs dedicated to tracking and lowering the cost of password and account resets (and doing it securely). That last part is the hard thing. Large organizations can save millions of dollars if they can get people to not lose/forget their credentials -or- self service those resets (but even then, having that person do it is now losing their time and energy).
It’s not just indirect opportunity costs either, it’s direct costs to the IT organization. Smaller teams can absorb this stuff as a rounding error on their time, but the second you’re counting in the thousands, you need to deal with this type of thing. (And I’ll repeat: securely)
Now imagine doing it as a B2C+B2B organization like Google or Microsoft. The costs are staggering.