Hacker News new | ask | show | jobs
by ryandrake 6 days ago
I resent that I need a special app to "manage" them. I want to know where this key is on my filesystem so I can back it up and edit it myself, not have to use some app to access it. My ssh authorized_keys is just a text file. I can "manage" it with something as simple as vim. Maybe KeePassXC and BitWarden give you that simplicity, if so great!
2 comments

KeePassXC "supports passkeys" but the website/app that offers the passkey needs to offer it in the correct way for KeePassXC to ingest it. I've found a fair amount of scenarios where they don't correctly let you drop it into them.
Until I can have all my keys as cleartext in a text file, I won't use passkeys.
KeepassXC gave users this choice. And was threatened to be blocked for it.[1]

[1] https://github.com/keepassxreboot/keepassxc/issues/10407#iss...

Yuck. Look closely at the wording: He is trying to counter a "user choice" feature by saying it doesn't have "protection". "File protection." "Protection of the key." Protection from who? From the user, that's who!

This mentality that the user is an attacker, and the software must protect its data from the user. Isn't a passkey ultimately supposed to be my data?

This is simply the mentality. Everyone who's worth anything (as in money) has it. Everyone who makes anything you own has it. They do everything based on this mentality and will not give it up. Every new specification or policy has provisions to ensure the device is protected from its user. Whether it's age verification (non-California-style), passkeys, or CSAM scanning.