Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Can they be synced to my paper notebook in my desk drawer?


Technically you can, but most software will make it impossible or hard. It is not supposed to leave the secure storage.


> It is not supposed to leave the secure storage.

"Secure storage" defined as the vendor's cloud services but not the user's eyeballs.


> It is not supposed to leave the secure storage.

How do they authenticate if they are not leaving the secure storage ? Through telepatic transmission ?


By using the built in device attestation feature to blackball any passkey providers that allow that, apparently:

https://github.com/keepassxreboot/keepassxc/issues/10407#iss...

Now imagine a whitelist of acceptable providers. Suddenly, you don't even own your credentials anymore.


Obviously via public key cryptography. It seems that you lack a sufficient understanding on this subject to back up the repeated snarky comments.


Then how are untrained users supposed to trust passkeys if they can't understand how they're secured when a third party is holding them?


How are untrained users supposed to trust passwords if they don't understand the differences between unsalted SHA1 versus PBKDF2 versus bcrypt and probably don't know what practices their third party is doing to properly hash the password?


Explaining password managers like the browsers' or 1password is easier than explaining passkeys. At least with password managers, you can export the whole database when switching platforms.


This thread is crazy, it reads like 2 people arguing but there are actually zero repeat commenters, like some sort of debate conga line


I agree. People ask the same questions about password managers just storing passwords.

One of major failures of the passkey marketing is that the FIDO Alliance left it at:

1) Vendors marketing passkeys as this brand new thing for their customers;

2) Anyone technical needing to already know that passkeys weren’t this brand new vendor specific thing, and reading the standards documents.

Passkeys are essentially just a marketing name for FIDO2 credentials with a focus on particular kinds of implementation. But FIDO didn’t bother to handle communications to technical folks outside the authentication space, and they’ve failed to do so effectively beyond that area.


Can they be synced to my own server, or my local machine like laptop or PC?


You can self host bitwarden.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: