Remix.run Logo
ryandrake 2 days ago

I resent that I need a special app to "manage" them. I want to know where this key is on my filesystem so I can back it up and edit it myself, not have to use some app to access it. My ssh authorized_keys is just a text file. I can "manage" it with something as simple as vim. Maybe KeePassXC and BitWarden give you that simplicity, if so great!

VCFundedGenYer 2 days ago | parent | next [-]

KeePassXC "supports passkeys" but the website/app that offers the passkey needs to offer it in the correct way for KeePassXC to ingest it. I've found a fair amount of scenarios where they don't correctly let you drop it into them.

reddalo 2 days ago | parent [-]

Until I can have all my keys as cleartext in a text file, I won't use passkeys.

pseudalopex 2 days ago | parent | prev [-]

KeepassXC gave users this choice. And was threatened to be blocked for it.[1]

[1] https://github.com/keepassxreboot/keepassxc/issues/10407#iss...

ryandrake 2 days ago | parent [-]

Yuck. Look closely at the wording: He is trying to counter a "user choice" feature by saying it doesn't have "protection". "File protection." "Protection of the key." Protection from who? From the user, that's who!

This mentality that the user is an attacker, and the software must protect its data from the user. Isn't a passkey ultimately supposed to be my data?

inigyou 2 days ago | parent [-]

This is simply the mentality. Everyone who's worth anything (as in money) has it. Everyone who makes anything you own has it. They do everything based on this mentality and will not give it up. Every new specification or policy has provisions to ensure the device is protected from its user. Whether it's age verification (non-California-style), passkeys, or CSAM scanning.