4 ms·
That's the whole point of this exercise. If export is possible it's not secure against local compromise in the way that's needed.
by wbl 1y ago
That's the whole point of this exercise. If export is possible it's not secure against local compromise in the way that's needed.
- tzs 1y agoThat's not quite correct. This can easily be seen by simply considering that the people who developed the passkey standard are also developing a passkey import/export standard which is nearly done and implementations are appearing in the field already. For example Apple's Passwords app on MacOS/iOS/iPadOS 26 now supports export and import of passkeys to/from other apps that support that standard. I don't know if any other apps have yet actually released such support.
- josephcsible 1y agoThe point of passkeys is to protect against phishing and password reuse. You can't protect against local compromise, even if your passkeys are stored in something like a YubiKey, because once you log in to your bank with your hardware-backed passkey, the malware on your computer could use the session you started to transfer all of your money out of your account.
- ngrilly 1y agoThat’s why most banks ask you to approve transactions with an explicit reauthentication.
- josephcsible 1y agoThen the malware will just wait until you want to do something legitimate that needs that, and then swap it out for its own thing.
- wbl 1y agoBut it can't maintain that compromise. That's important.
- AlexandrB 1y agoNeeded for whom? As others have said, without export it's a recipe for vendor lock-in.
- gowld 1y agolock-in to which vendor? Passkeys support transfer to any vendor you want.
- amenhotep 1y agoI want to transfer them to a vendor that will let me export them in plain text.
- josephcsible 1y agoIs it really "any" vendor, or is it just the big ones? Can you transfer your Apple passkeys to KeePassXC?
- AlexandrB 1y agoCan you send some documentation on how? For example, I tried googling for transferring a passkey out of popular systems and it doesn't seem possible[1][2] other than through JSON export[3] which is what some sites want to block as I understand. [1] https://old.reddit.com/r/Bitwarden/comments/1efs5d2/how_can_i_transfer_passkeys_from_icloud_keychain/ https://old.reddit.com/r/Bitwarden/comments/1efs5d2/how_can_... [2] https://old.reddit.com/r/Bitwarden/comments/1di8nbz/import_passkey_from_1password/ https://old.reddit.com/r/Bitwarden/comments/1di8nbz/import_p... [3] https://news.ycombinator.com/item?id=44454106 https://news.ycombinator.com/item?id=44454106