Letter XXII: Provider, Provide — Do Not Prescribe

By Martyn Walker
Published in Letters from a Nation in Decline

This morning, I attempted to log in to a different company account on QuickBooks.

It should have taken perhaps ten seconds. Instead, passkeys turned it into an intense five-to-ten-minute project involving repeated attempts, rejected routes and the usual digital guessing game in which the customer must discover what the software has decided to do on his behalf.

Eventually I checked the settings which I had previously disabled. They had somehow been re-enabled. I had not changed them. Perhaps an update had restored the provider’s preferred defaults; perhaps some other piece of helpful automation had intervened. Either way, my expressed choice had not survived.

A setting which silently reverses itself is not a setting. It is a temporary stay of execution.

Passkeys are presented as the civilised successor to passwords: simpler, safer and resistant to phishing. The cryptography is undoubtedly clever. A passkey is tied to the genuine website and cannot be handed innocently to a convincing imitation. This tackles a real problem, particularly among people who reuse memorable passwords or type credentials into whatever page appears before them.

But the sales pitch quietly substitutes one security problem for another. It concentrates identity, authentication and often account recovery in the same small object carried everywhere in a pocket.

Put down an unlocked telephone and someone else can pick it up. Phones are snatched from people’s hands by thieves on bicycles. Criminals observe PINs before stealing devices. Ministers, officials and businesspeople have all demonstrated that possession of an important telephone is not a theoretical risk confined to careless teenagers. Yet the technology industry increasingly treats possession of the device, assisted by a face, fingerprint or short PIN, as proof of possession of the identity.

The answer from security specialists is that a properly locked telephone still requires biometric or PIN verification. This is true in the same way that a properly locked front door keeps out a burglar who has neither the key nor a window. It describes the security model while avoiding the circumstances in which the security actually fails.

Once a thief gains access to a phone, he may acquire the passkey, email account, text messages, authenticator, password-reset route and banking applications together. We are told this is multifactor authentication. Physically, it is often several differently named functions living inside one stolen box.

I have used Bitwarden since its early days. I do not know any of my account passwords. Each is unique and generated by the password manager; I know only my personal master password. I have never been hacked. My family know that master password, so when I die they will be able to gain access to the accounts and information they will need.

That is not an accidental arrangement devised for my convenience. It is a considered security and succession policy. It has one deliberate trust anchor, controlled by me, with a comprehensible route for inheritance.

Passkeys intrude upon that arrangement by creating a parallel collection of credentials distributed among Apple, Google, individual devices, browser profiles, password managers and service providers. Some synchronise; some do not. Some can be deleted; some appear again. Some sites remember the right account; others offer a passkey for the wrong one. Death, incapacity, loss of a device or a disputed cloud account can turn the promised simplicity into an archaeological expedition through systems nobody consciously chose.

This is not merely an objection to passkeys. Those who want them should be free to use them. The objection is to prescription disguised as provision: automatic creation, persistent prompting, passkey-first login screens and updates which restore settings the customer has already rejected.

The provider benefits handsomely. Fewer forgotten-password calls reduce support costs. Phishing losses decline. Authentication is outsourced to devices and platform companies. The customer supposedly receives convenience, but when the machinery fails, the provider’s saving becomes the customer’s unpaid labour.

Multiply my lost five or ten minutes by millions of users, then add every compulsory application, broken identity portal, circular chatbot, unexplained verification request and setting restored after an update. None appears in the national accounts as waste. It is simply removed from the productive day in fragments too small to invoice and too dispersed to attract ministerial attention.

Britain can no longer indulge this casually. As Ross Clark puts it with admirable economy in the title of his forthcoming book, Britain Is Bust. His subject is the approaching sovereign debt crisis and the unavoidable rationalisation of public spending. Passkeys will neither cause nor cure that crisis. They are, however, a neat specimen of the culture accompanying it: institutions lower their own visible costs by exporting effort, delay and frustration to citizens and businesses, then call the result innovation.

A country does not become unproductive only through grand strategic errors. It also does so ten minutes at a time.

The proper policy is neither difficult nor technologically reactionary. Providers should offer passwords, independent authenticator applications, physical security keys and passkeys. They should explain the differences. They should allow the customer to choose. A rejected method should remain rejected, and an update should not constitute fresh consent. No credential should be created silently. No customer should be repeatedly funnelled towards the provider’s cheapest option.

Security should also permit genuine separation. The credential, the device approving its use and the route for recovery need not all occupy the same phone. People handling valuable businesses or sensitive information should be able to keep authentication on a separate device or physical key. Those planning sensibly for death or incapacity should not have their arrangements defeated by credentials imprisoned inside a dead person’s biometric ecosystem.

The password was not perfect. Neither is the passkey. The difference is that I was permitted to manage the former intelligently, whereas the latter is increasingly imposed upon me by organisations convinced that their preferred system must also be mine.

Let providers provide. Let customers decide. And when we have decided, leave the bloody setting alone.


Discover more from Verbal Alchemy

Subscribe to get the latest posts sent to your email.

One Reply to “”

Leave a comment