Opinionpasskeysauthenticationencryptionidentity
Industry Urged To Stop Using Passkeys
5.9
Relevance ScoreTim Cappalli posted on Link Blog on Feb. 27, 2026, urging the identity industry to stop using passkeys to encrypt user data. He argues that passkeys, while excellent for phishing-resistant authentication, are frequently lost by users, making encrypted data irrecoverable without robust recovery mechanisms. The post recommends keeping passkeys for authentication only and adopting separate key-recovery or custodial solutions.
Scoring Rationale
Actionable industry guidance with firsthand observations, limited by single-author opinion and lack of empirical data.
Sources
- Read OriginalPlease, please, please stop using passkeys for encrypting user datasimonwillison.net


