<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/what-is-wrong-with-apple-passkeys--1zqglza1l" -->

---
title: What is wrong with Apple Passkeys? | daily.dev
description: Apple introduced a controversial ‘improvement’ to webauthn called Passkeys, which could impair the security of your most valuable online resources. With...
canonical: https://daily.dev/posts/what-is-wrong-with-apple-passkeys--1zqglza1l
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: What is wrong with Apple Passkeys? | daily.dev
og:description: Apple introduced a controversial ‘improvement’ to webauthn called Passkeys, which could impair the security of your most valuable online resources. With...
og:url: https://daily.dev/posts/what-is-wrong-with-apple-passkeys--1zqglza1l
og:image: https://api.daily.dev/og/posts/1ZqGlZA1l.png
og:image:alt: What is wrong with Apple Passkeys?
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# What is wrong with Apple Passkeys?

**[Community Picks](https://daily.dev/sources/community)** · 7 min read · 17 upvotes · 2 comments

## Summary

Apple introduced a controversial ‘improvement’ to webauthn called Passkeys, which could impair the security of your most valuable online resources. With ‘pre-Passkeys passwordless’, you could secure the trust relationship between your computer and a service, say, a crypto exchange. When Passkeys proponents say it is a huge step forward.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://medium.com/@arkenoi/what-is-wrong-with-apple-passkeys-1d044072c5a3>

## Community discussion

Top comments from developers on daily.dev.

**@appforce1** · 1 upvotes

> Well, that article is overbearing in a way.
>
> WebauthN does allow for what is called roaming authenticators. Roaming meaning that the key material is not stored in a non-exportable fashion. Nothing wrong with a roaming token, provided the implications and indeed the reduction in security is understood.
>
> The author of this article is right in the case that roaming authenticators are not suitable for certain usecases. Is Passkeys a bad idea? Well, I think it is a whole lot better than what loads of people do nowadays... using the same credentials over and over and over...
>
> I don't think Passkeys...

**@gabrielkoo** · 0 upvotes

> Well said, it's essential like the role of password managers for passwords. Somehow the extra convenience is actually taking the overall security to lower levels.

## Similar posts on daily.dev

- [Don’t just attend KubeCon \+ CloudNativeCon, Merge Forward your experience\!](https://daily.dev/posts/don-t-just-attend-kubecon-cloudnativecon-merge-forward-your-experience--l0rpp73x8) · CNCF · 1 upvotes · 0 comments
- [Announcing H2 2026 KCDs](https://daily.dev/posts/announcing-h2-2026-kcds-m96goajm1) · CNCF · 1 upvotes · 0 comments
- [Two months of Open Community Groups](https://daily.dev/posts/two-months-of-open-community-groups-asf52zhbs) · CNCF · 0 upvotes · 0 comments
- [CNCF Unveils Schedule for KubeCon \+ CloudNativeCon Europe 2026](https://daily.dev/posts/cncf-unveils-schedule-for-kubecon-cloudnativecon-europe-2026-ikhcoa5cb) · CNCF · 2 upvotes · 0 comments
- [CNCF Debuts KubeCon \+ CloudNativeCon Japan 2026 Schedule](https://daily.dev/posts/cncf-debuts-kubecon-cloudnativecon-japan-2026-schedule-xp5pyudub) · CNCF · 1 upvotes · 0 comments

---

Tags: [#apple](https://daily.dev/tags/apple), [#authentication](https://daily.dev/tags/authentication), [#ios](https://daily.dev/tags/ios), [#passkeys](https://daily.dev/tags/passkeys), [#security](https://daily.dev/tags/security)

[View this post on daily.dev](https://daily.dev/posts/what-is-wrong-with-apple-passkeys--1zqglza1l)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"What is wrong with Apple Passkeys?","url":"https://daily.dev/posts/what-is-wrong-with-apple-passkeys--1zqglza1l","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/what-is-wrong-with-apple-passkeys--1zqglza1l"},"datePublished":"2022-10-10T12:44:29.430Z","dateModified":"2023-11-11T02:13:18.532Z","description":"Apple introduced a controversial ‘improvement’ to webauthn called Passkeys, which could impair the security of your most valuable online resources. With...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/47dc4445f433fc7a1875fe8dac030411","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/47dc4445f433fc7a1875fe8dac030411","isAccessibleForFree":true,"articleSection":"Community Picks","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Community Picks","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1655817725/logos/community","url":"https://daily.dev/sources/community"},"commentCount":2,"discussionUrl":"https://daily.dev/posts/what-is-wrong-with-apple-passkeys--1zqglza1l","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":17},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":2}],"keywords":"apple,authentication,ios,passkeys,security","timeRequired":"PT7M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Community Picks","item":"https://daily.dev/sources/community"},{"@type":"ListItem","position":3,"name":"What is wrong with Apple Passkeys?"}]}
{"@context":"https://schema.org","@type":"WebPage","@id":"https://daily.dev/posts/what-is-wrong-with-apple-passkeys--1zqglza1l","comment":[{"@type":"Comment","text":"Well, that article is overbearing in a way.\nWebauthN does allow for what is called roaming authenticators. Roaming meaning that the key material is not stored in a non-exportable fashion. Nothing wrong with a roaming token, provided the implications and indeed the reduction in security is understood.\nThe author of this article is right in the case that roaming authenticators are not suitable for certain usecases. Is Passkeys a bad idea? Well, I think it is a whole lot better than what loads of people do nowadays… using the same credentials over and over and over…\nI don’t think Passkeys is aimed at corporate or high security usecases. And with that, the choice for a roaming authenticator protected by a biometric credential is a strong usecase.","datePublished":"2022-10-19T14:33:36.217Z","url":"https://daily.dev/posts/1ZqGlZA1l#c-729Wz-Q1G","author":{"@type":"Person","name":"Jeroen Leenarts","url":"https://daily.dev/appforce1","image":"https://lh3.googleusercontent.com/a-/AFdZucq7HI31SUzhxAs-0FIlXnYzaEoJgFSfARIPNnqgFA=s100"},"interactionStatistic":{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1}},{"@type":"Comment","text":"Well said, it’s essential like the role of password managers for passwords. Somehow the extra convenience is actually taking the overall security to lower levels.","datePublished":"2022-10-17T03:05:48.419Z","url":"https://daily.dev/posts/1ZqGlZA1l#c-3HZryCBPD","author":{"@type":"Person","name":"Gabriel Koo","url":"https://daily.dev/gabrielkoo","image":"https://avatars.githubusercontent.com/u/16297877?v=4"}}]}
```

