Comment by pabs3

1 day ago

KeepassXC has exportable passkeys, so you can avoid the stolen case at least.

Too bad the spec is stupid and requires password managers to be identifiable so servers can deny the "insecure ones". It's already a pain to use Keepassxc for otp since they all want you to use their apps but it's still doable (the worst offender being steam where you have to hack your own app to extract the otp secret). With passkeys you won't have a choice to use The Google AuthenticatorTM etc because eventually some exec will find they can block every provider except their own to boost app download KPI. I really like concept of passkeys, the simple fact of using asymmetric keys is so much better than giving the secret to prove you have it, but the spec is hostile and thought for vendor closing.

  • No, the spec is for companies that need to enforce higher levels of security so that you can e.g. only enable Yubikeys in your env. I hate big tech just like anybody else but this is just spreading FUD right now.

    Also execs can already enforce their apps only - banking apps for approving transactions are already a thing at least in europe, no fido passkey needed.