← Back to context

Comment by duskdozer

5 hours ago

Funny enough, that's what the big passkey folks want: https://github.com/keepassxreboot/keepassxc/issues/10407

Really glad open-source password managers are resisting the bullying and not implementing DRM.

  • For now: https://github.com/keepassxreboot/keepassxc/issues/10406

    Or not: https://github.com/Kunzisoft/KeePassDX/issues/2321

    They are imo clearly gearing up to lock down passkeys in practice one day so that you will only be able to use those tied to a Google or Apple account (or some new player). They're already threatening in these issues to blacklist open implementations that don't submit to their requirements, and then requiring an attested client would then become the "best practice" adopted blindly and widely. I think the only hope is for the open clients to fully submit, hoping to avoid full attestation, while not making it too hard to patch out the anti-features. Of course, anyone who can't compile is screwed though.