| This hasn't actually been released yet, it's just in the release branch. It was merged down less than 4 days ago. It comes with the following caveats: > What is not working / is missing / won't be implemented: > Some extensions are still missing (authentication doesn't support them at all, yet). > Support for Resident Key. > Support for triggering unlock from extension. > Support for root certificates. > Support for PIN/TouchID when authenticating. > What is not tested: > Support for Passkeys with Google/Apple and other common sites So... can anyone confirm to me whether the passkey implementation in KeePassXC actually works with any of the sites implementing passkeys? I'll be happy if it ends being great and works everywhere. But what should I take away about the spec that the developers who have implemented the spec in KeePassXC aren't certain whether it will work with every site that claims to support passkeys? I know it won't work with any site requesting hardware-bound keys: https://fosstodon.org/@keepassxc/111301312353785552 I'm happy for KeePassXC to add support, it's a big deal, but it seems pretty early to say, "see the Linux situation is solved now." I go back to the complaint about passkeys being recommended for people to use today, even though they're still kind-of half finished. This is on a release candidate branch, and we're already acting like Linux is just supported now. Never mind the fact that it's a partial implementation, never mind the fact that we have no idea if browsers like Chrome will allow KeePassXC to be treated as a platform provider without installing an additional extension to bypass the browser's built-in behavior. Never mind the fact that its import/export format only works with itself. Linux is supported now and you can export your keys, what's the problem? /s ---- And ignoring all of that, if Linux has support now, I would repeat: why do I need to find out about this on Mastodon? Seriously, the FIDO Alliance is made of the richest tech companies on the planet. Why is the official user-facing dev site -- a site maintained by W3C members and organizations -- giving incorrect information? Why are supported features, goals, and timelines being communicated entirely via social media? |
Linux situation is definitely not solved yet, and some sites still ignore Firefox because of missing support. The only reason I mentioned KeePassXC because it's the first free and open source solution that actually supports importing and exporting Passkeys. Even if it's still beta/rc phase.
Every other password manager browser extension injects same kind of scripts to every page (1Password included), because browsers lack an open API for WebAuthn.