6 ms·
Exactly, I always refuse to add a passkey because I'm afraid I won't be able to easily login again. Also, I don't want to be locked in to a vendor.
by reddalo 2mo ago
Exactly, I always refuse to add a passkey because I'm afraid I won't be able to easily login again. Also, I don't want to be locked in to a vendor.
- rib3ye 2mo agoYou can use a passkey that's tied to a Yubikey.
- avh02 2mo agoThe problem here is i want to have more than 1 yubikey, so if i lose it, all is not lost... I can't do that with the current implementations unless i present N yubikeys to every new account i make. Which makes an off-site backup yubikey impossible. With my current yubikey usage with password store, my "offline" yubikey can be brought in whenever i want to decrypt the passwords, including ones inserted while the key was in storage. Also yubikeys have limited passkey slots (100, 25 with old firmware)
- pllbnk 2mo agoAlso, where do I store the backup Yubikey, or any other pass key owning device for that matter? It has to be easily accessible to set up the pass keys, but also safe from accidents like house fire. There's a strange tension where I want to use pass keys because they are easy to use but also they are easy to lose, so I choose a KeePass synced over cloud and deal with a bit of a hassle by having to copy/paste my passwords.
- preisschild 2mo agoI think technically you can just register the public key of the passkey and only need it on-hand for login
- avh02 2mo agoTechnically i would think so too, but is that how it's implemented? (I legit don't know, but my feeling was always that you had to add them while they're present, especially as there's different passkeys for different sites, to do it offline do you pregenerate 100 keys for each device to assign later?)
- pas 2mo agouse an open source password manager that supports them. as others mentioned, there's BitWarden (cross-platform, self-hostable), but if you want something simple there's KeePassXC (and you can put the store file on a dropbox shared folder)
- OkayPhysicist 2mo agoThe cabal of evil behind the passkey project actively have KeePassXC on their naughty list fore deigning to allow users to access their keys, and specifically included in the standard the means to discriminate between different passkey vault providers. It is the opposite of an open system, and cannot, under any circumstances, be trusted. Do not use passkeys, tell other people not to use passkeys, and make sure to not let shills astroturf conversations about passkeys unopposed.
- SrslyJosh 2mo agoThis is hard to understand without any references. Can you please share a relevant link or two?
- OkayPhysicist 2mo agoHere's KeePassXC being threatened with blacklisting over granting users control over their own data: https://github.com/keepassxreboot/keepassxc/issues/10407#issuecomment-1994182200 https://github.com/keepassxreboot/keepassxc/issues/10407#iss... Here's the most readable reference to playing favorites on passkey vaults I could find from the FIDO Alliance (the previously mentioned 'cabal of evil'). See Section 2.2: "Validating FIDO UAF authenticator attestations against the configured authenticator metadata to ensure only trusted authenticators are registered for use. " And Section 2.3: "Verify attestation assertions made by the FIDO UAF Authenticators to ensure the authenticator is authentic and trusted. Verification occurs using the attestation public key certificates distributed via authenticator metadata. " https://fidoalliance.org/specs/fido-uaf-v1.2-ps-20201020/fido-uaf-overview-v1.2-ps-20201020.html https://fidoalliance.org/specs/fido-uaf-v1.2-ps-20201020/fid... Basically, Relying Parties (the sites you are logging in to) are expected to allow/disallow certain passkey authenticators (the devices or software that hold your passkeys), based on registration and trusted lists. The FIDO Alliance can use entry into those trusted lists as a cudgel to force compliance with the standard. Effectively, the standard is that users must be locked into to proprietary ecosystems, unable to escape.
- preisschild 2mo agoYou can register multiple passkeys for a single user, there is no lock in
- spaqin 2mo agoEven if I have my Yubikey passkey that's with my house keys, it's annoying to go grab it and connect every time I need to access something. Enabling it on GitHub was a mistake...