Elektrine lite

← Feed

@chpietsch@fedifreu.de

Post #2733404

2025-10-20 17:17 UTC

@cryptgoat@fedifreu.de According to this writeup, #KeePassXC supports #passkeys in a non-compliant way: https://me.micahrl.com/blog/concerns-about-passkeys/ I am still hesitant about passkeys.

Replies (3)

  • @cryptgoat@fedifreu.de 2025-10-20 17:51

    @chpietsch@fedifreu.de The entire system around #Passkeys is fundamentally flawed, at least to some degree. Not a fan myself at this point.

    Open ##2733405

  • @chpietsch@fedifreu.de @cryptgoat@fedifreu.de Das Zögern fällt mir bisher nicht schwer: Zwar werden lt. https://passkeys.directory/ inzwischen ~230 Seiten unterstützt, für mich sind jedoch keine wirklich relevanten darunter. Das entwickelt sich nicht wirklich rasant...

    Open ##2733406

  • @mvgorcum@chaos.social 2025-10-21 06:34

    @chpietsch@fedifreu.de @cryptgoat@fedifreu.de while thats technically true, if you look at what part keepassxc is "non-compliant" in, it's in not re-asking the user for a password when their database is unlocked. I agree with keepassxc that this is proper behaviour for a password manager. The second is that keepassxc allows to export passkeys in plain text. That's probably a little debatable, but it's not like we can fully prevent extracting passkeys in plain text at all, since the user obviously has the keys required.

    Open ##2733407