4 ms·
I store my passkeys in KeePassXC and I have absolutely no feeling of being walled into any garden, personally.
by Shank 10d ago
I store my passkeys in KeePassXC and I have absolutely no feeling of being walled into any garden, personally.
- EvanAnderson 10d agoWait until websites start demanding device-bound/attested passkeys. Big tech just needs to get enough adoption to make this change.
- nbobko 10d agoAs much as I hate to admit it (because I love passkeys UX), but I do think that device-bound/attested passkeys are going to happen in the future :( UPD: oh, heck, attested passkeys are actually already in the protocol. Why can't we just have nice things?
- Shank 9d agoNobody is going to do this because Apple’s devices don’t support this for the Passwords app out of the box, by design.
- tonoto 10d agobut what do passkeys offer in terms of security, when stored in password managers, compared to having a (password manager) generated password and a totp? I believe that by allowing password managers to store passkeys, the whole purpose of "device based security" got lost..
- flumpcakes 10d agoYes. I use hardware based passkeys and absolutely love them. I think it was a giant mistake having them 'software' based. It some ways it kind of defeats the entire purpose...
- qlte 9d agoThey are 100% immune to credentials phishing. You literally cannot authenticate to an impersonator site based on cryptographic guarantees. And yes, I know the happy path of password managers uses host-based autofill which does add some friction to phishing attempts, but given the prevalence of unexpected but legitimate urls with weird alternate subdomains/SSO/redirects in modern login flows, you have to manually autofill/add an exception often enough that it's possible to let your guard down once at the wrong time.