▲ | jorams 9 days ago | ||||||||||||||||
They paraphrased what you said in the thread, but I don't think it's much of a misrepresentation. You may have "been one of the most vocal proponents of synced passkeys never being attested to ensure users can use the credential manager of their choice", but as soon as one such credential manager allows export that becomes "something that I have previously rallied against but rethinking as of late because of these situations". There may not currently be attestation in the consumer synced passkey ecosystem, but in the issue thread you say "you risk having KeePassXC blocked by relying parties". The fact that that possibility exists, and that the feature of allowing passkeys to be exported is enough to bring it up, is a huge problem. Especially if it's coming from "one of the most vocal proponents of synced passkeys never being attested", because that says a lot about whoever else is involved in protocol development. | |||||||||||||||||
▲ | timmyc123 9 days ago | parent [-] | ||||||||||||||||
You should really re-read the entire discussion. It wasn't about passkeys being able to be exported. It was specifically about clear text export. > The fact that that possibility exists, The possibility does not exist in the consumer synced passkey ecosystem. The post is from a year and a half ago. | |||||||||||||||||
|