Post #2733404
2025-10-20 17:17 UTC
Replies (3)
-
@cryptgoat@fedifreu.de 2025-10-20 17:51
@chpietsch@fedifreu.de The entire system around #Passkeys is fundamentally flawed, at least to some degree. Not a fan myself at this point.
-
@schlackenfuchs@social.tchncs.de 2025-10-20 18:47
@chpietsch@fedifreu.de @cryptgoat@fedifreu.de Das Zögern fällt mir bisher nicht schwer: Zwar werden lt. https://passkeys.directory/ inzwischen ~230 Seiten unterstützt, für mich sind jedoch keine wirklich relevanten darunter. Das entwickelt sich nicht wirklich rasant...
-
@mvgorcum@chaos.social 2025-10-21 06:34
@chpietsch@fedifreu.de @cryptgoat@fedifreu.de while thats technically true, if you look at what part keepassxc is "non-compliant" in, it's in not re-asking the user for a password when their database is unlocked. I agree with keepassxc that this is proper behaviour for a password manager. The second is that keepassxc allows to export passkeys in plain text. That's probably a little debatable, but it's not like we can fully prevent extracting passkeys in plain text at all, since the user obviously has the keys required.