Back in Nov 2024, @balloob rejected github pull request 122725, which would have added passkey support, stating that “most users don’t know what passkeys are.”
Even back then, passkeys were already widely used, not just by technical users, but regular users. In May 2024, Google revealed 400 million users had passkeys enabled in their Google accounts. And in Oct 2024, Amazon revealed they had 175 million users logging in with passkeys.
But over the last year, many more companies that serve the general public have enabled passkeys. The growing list including Walmart, Costco, TikTok, Snapchat, Playstation, Nintendo, the UK National Health Service, Albert Heijn, and SNCF (the french national railway).
In rejecting the pull request @balloob also said some of the “users that do (know what passkeys are), might not know the implications. If you store your passkey in Chrome password manager, you can now not login if you’re on another browser. I feel like it would lead to more, not less, people getting locked out.”
I recognize that one of the differences between the many big companies listed above and a local Home Assistant installation is that if you lose access to your Amazon or TikTok passkey, the companies can always email you a magic link and restore your access to your account. A Home Assistant server can’t do that. So perhaps that’s a reason to not make it too easy for users to enable passkeys for admin accounts. But given how many other features are available for power users in Home Assistant, this seems like a strange place to draw a line, particularly when the overlap between users of Home Assistant and users of multi-device password managers is probably extremely high.
In short, it would be really great if the developers could reevaluate the decision from 2024 to reject this pull request. Passkeys are so much better than passwords, from both a security and usability standpoint.