Passkeys, Inception, and the Object Permanence Asymptote
Consumers reject passkeys because their frictionless security forces them to trade the sovereign ownership of passwords for a rented digital identity.
By Jonah Reyes
Sparked by Passkeys were invented by engineers with zero understanding of consumer brain · discussion

Over on the timeline, consumer app veteran Nikita Bier recently pointed out that the aggressive rollout of passkeys feels entirely driven by engineers who fundamentally misunderstand how the consumer brain processes trust, a critique you can find in his viral tweet. Predictably, the subsequent discussion thread on Hacker News immediately devolved into the classic Silicon Valley defense mechanism. The engineering class framed everyday users as irrational DAUs, technically illiterate laggards stubbornly resisting the frictionless utopia of WebAuthn. It is a highly intoxicating narrative for anyone who spends their days staring at telemetry dashboards.
But whenever a theoretically flawless technological upgrade encounters widespread, localized consumer friction, the most productive analytical move is to assume the users are acting rationally. To understand the visceral rejection of passkeys, we have to look past the cryptography and interrogate the affordance. We have to reverse-engineer the underlying sociology of why a clumsy, phishable string of text feels safer to a human being than a biometric hardware enclave. We have to stop treating human vanity and control as bugs in the system, and start treating them as the baseline physics of the digital arena.
In Christopher Nolan's film Inception, extractors navigating multiple layers of shared dreamscapes rely on a highly specific physical tool known as a totem. As explained in the movie's lore, a totem—like Arthur's loaded die or Cobb's spinning top—must possess an exact weight and tactile balance known exclusively to its owner. The totem grounds the dreamer. It proves they are in base reality because only they possess the physical, sensory memory of the object's true nature. If the top falls, the world is real; if it spins forever, you are trapped in a simulated reality built by someone else.
For all of its objective flaws as an authentication mechanism, the traditional password operates as our primary digital totem. You know your password. You hold it in your biological memory, or you scribbled it into a physical notebook tucked inside a desk drawer, or you meticulously curated it inside a local vault. Even when saved in a rudimentary password manager, you can click a button to unmask the text, revealing the raw string of characters to your own eyes. It is deeply inefficient, but it is undeniably yours. It possesses a tangible, verifiable weight in your digital pocket. You can whisper it, you can forget it, you can text it to a spouse. The agency is completely sovereign.
When an industry tries to replace a visible, user-held asset with an invisible, platform-held process, they inevitably crash into what I call the Object Permanence Asymptote.
This is the structural ceiling a product hits when its operational mechanics aggressively strip away the user's tangible sense of ownership, trading psychological sovereignty for frictionless convenience. Passkeys are mathematically elegant, leveraging robust public-key cryptography to generate localized credentials that can never be intercepted in transit by a malicious phishing site, completely eliminating the primary attack vector of the modern web. The engineering architecture is undeniably S-Tier.
But you can't hold it.
[Let me be clear that my own thumb gets remarkably tired of pecking out 16-character alphanumeric strings containing at least one special symbol on a glass touchscreen while trying to order takeout, and I deeply respect the cryptographic superiority of the WebAuthn standard. I want phishing to die as much as any security researcher on Twitter. Yet the math is sociologically irrelevant to the human ego.]
To map why this loss of digital object permanence triggers such intense consumer anxiety, we have to borrow a framework from financial history. A password operates exactly like a bearer bond. Bearer instruments are notoriously dangerous because they are entirely unregistered; whoever holds the physical piece of paper owns the asset, making them an absolute magnet for theft and loss. If you lose the paper, the value is permanently gone. But they also offer unparalleled sovereignty. If you hold the paper, no central banking authority can freeze your account, deny your transaction, or arbitrarily lock you out of the vault. The risk is entirely yours, but so is the power.
A passkey, by contrast, operates like a derivative.
When you create a passkey, you do not possess the underlying asset. As the mechanics of cloud syncing clearly demonstrate, the credential is fundamentally tethered to a broader ecosystem—usually your Apple ID, your Google account, or your Windows Hello profile. You are trading the sovereign bearer bond for a derivative contract managed by a tech oligopoly. The underlying cryptographic key pair is generated and stored in a secure enclave that you are barred from accessing directly. You are holding a receipt for a secret stored inside a black box, entirely reliant on the continued benevolence of the platform hosting the box. If Apple decides your device violates a terms of service update, or if Google's automated moderation algorithm incorrectly flags your account for spam, your derivative contract is unilaterally voided.
The consumer is highly attuned to recognizing this trade. They correctly perceive that the friction of a password was actually a form of leverage, and the frictionless nature of the passkey is merely a mask for ecosystem capture.
Consider a two-by-two matrix mapping our authentication options. If you plot "Security against bad actors" along the horizontal x-axis and "User Agency" along the vertical y-axis, the traditional password sits perilously low on security but incredibly high on agency. Passkeys shoot all the way to the right on security, establishing an unbreachable defensive perimeter. Yet they simultaneously plummet into the basement on user agency. The engineering class looked at the matrix, saw the exponential leap in security, and declared the problem mathematically solved. The users looked at the exact same matrix, felt the sudden, terrifying drop in agency, and instinctively rebelled against the UI.
And the users were entirely justified to worry.
The industry is quietly realizing the magnitude of this behavioral error. Just recently, the FIDO Alliance had to scramble to publish drafts of the Credential Exchange Protocol, a late-stage attempt to standardize a secure way to move passkeys between different password managers and operating systems. This frantic structural backpedaling perfectly validates the initial consumer anxiety. The FIDO architects realized that their elegant mathematical solution was generating massive narrative debt. The everyday user, perhaps without knowing the term "vendor lock-in," intuitively sniffed out what the highly-paid security experts missed: without guaranteed portability, a passkey is just a pair of golden handcuffs.
We have spent the last decade passively accepting that we merely rent our movies, stream our music, and license our software through an endless procession of monthly SaaS subscriptions. Every physical artifact of our cultural and professional lives has slowly evaporated into the cloud, replaced by the ephemeral vibes of access. Passkeys represent the final, invisible threshold of this subscription economy. They ask us to quietly resign ourselves to renting the keys to our own identities, trusting that the digital landlord will never change the locks.