Greetings Rob: We seem to be talking past each other. You've missed my main point again. By "absurd", I clearly do not mean that there is no rationale for the passkeys and the other items you've explained. I'm simply saying that in practical terms, it's a waste of time to try to understand. I have ZERO intention of (as you say) "simply start[ing] to use passkeys locally on at least their Windows 11 system..." I'm a Windows 11 user and I do not use passkeys and I will not start to do so. The way this is presented to the user (in Microsoft Windows) is simply not advantageous for the way I use my system. I seriously doubt it's efficacy.
I'm doing fine without passkeys and I will resist any attempt by Microsoft (or FIDO2, whoever that is) to force me to use them. I bypass the "passkey" reminder routinely, with Amazon and other sites, and have no hindrance doing what is important to me online and locally.
I do indeed recognize you are knowledgeable about all this and that's great for you. I have found this whole topic (off and on over about six months in this "community" thread) to be confusing and worse, a colossal waste of time. Certainly, their reason for passkeys is not "absurd" but the way it's been rolled out, including the way you've explained it is, in my world "absurd". No offense intended to you. I'm simply expressing what I imagine MANY users must feel about "passkeys" at this point.
But, hey, I'm a "boomer" (age 67) so maybe it's a generational thing.
Hi, a very frustrated Microsoft customer, I'll respond generally to both you and the others who followed up with their own replies, since the theme is relatively consistent.
It's not generational, since I'm the same age as you, but it is clearly related to technical background, since my career in computers and security makes understanding passkeys relatively easy, though the interfaces clearly need work.
I do wonder if those having the most trouble with their use on Windows 11 have both biometric capabilities on those devices, as well as whether the smartphone issue is adding to the problems as someone else mentioned, since that's where I had the biggest issues with Windows 10 and Android.
Though my own larger issue was with my initial test with Amazon, which absolutely everyone complains about, so it's clearly something in their implementation that's the problem there and I wonder if that's a result of the cross-platform authentication issues I saw with that website, meaning it's a deeper problem with that portion of the FIDO2 WebAuthn specification, upon which passkeys operate.
My earlier explanation of the problem with passwords and why a PIN is better wasn't intended for easy reading, since I was pointing out the various technical reasons behind why passwords are really already dead and dangerous, regardless of how easy and functional various password managers may make them to use, since it's the core problem that they're a shared secret and too easily breached by any number of methods that make them unsafe and really useless in terms of security.
The unfortunate truth though is that the current state of the passkey system requires too much of the user in terms of knowledge, since without it their operation is still relatively confusing as you've indicated.
I guess what I should say is that if you already have an effective authentication system that at least includes 2-Factor Authentication, preferably that doesn't require a password if possible, then you're probably okay until Microsoft and others have time to polish their passkey operation.
If not though, I personally wouldn't bother dedicating myself to useless efforts like password managers or even the still relatively difficult to use and more so maintain Microsoft or Google authenticators, because from everything I've seen here, those are at least as troublesome for most consumers as passkeys with Windows 11 will ever be.
Since my use is Microsoft centric, the Android issues won't really be a problem unless I try to use both sets of devices and apps fully across both platforms, since the Microsoft implementation with syncing across their Edge and Outlook for Android apps will make everything I truly need to authenticate to 3rd-party websites functional without a need for cross-platform operation.
So, it's not just Windows 11, but really all Microsoft apps which I require, while on Android the only apps I really use are phone, camera, Gmail for Google communications only and a few others all of which require only a single Gmail account that I've separately defined 2-Factor authentication and backup for on the Google platform. Only contacts have ever been synced between the platforms, primarily to display incoming callers on the phone app, with everything else kept completely separate for many reasons.
Anyone trying to cross-authenticate, sync or manage their Microsoft, Google, or Apple accounts in tandem across multiple physical planforms is simply asking for trouble, especially in terms of security, while I've personally always kept the platforms and security separate, with only the ability for one platform's email to be used as a second verification factor for the other.
Rob