I'm not convinced this person knows what they're talking about.
KeepassXC implements passkey support, but they do not implement these anti-user features. As a result, they are being threatened with being banned via attestation:
https://github.com/keepassxreboot/keepassxc/issues/10406
https://github.com/keepassxreboot/keepassxc/issues/10407
Screw these "You'll own nothing and be happy" people. I'll own all my keys no matter what. The software I run on my device should never betray me to signal things like "this passkey is allowed to be backed up!".
This was my impression, and it explains why the original announcement involved companies that would benefit the most from keeping their users on a leash.
Edit: Reading one of those issues it sounds like they want the keys stored in an encrypted way, is that too much to ask for? I dont care about viewing it but it shouldnt be stored in a plain easy to open JSON.
That's the key difference. If it mattered, they would make it part of the spec, not threaten a ban. That's even more concerning, there is a central group of people who get to decide who can and cannot use Passkeys.
Poe's law strikes... I can't tell if this is satire.
Oh, to have the luxury of redefining success and handwaving away hard learned lessons in the software industry.
> You still have to have a human who knows the system to validate that the thing that was built matches the intent of the spec.
You don't need a human who knows the system to validate it if you trust the LLM to do the scenario testing correctly. And from my experience, it is very trustable in these aspects.
Can you detail a scenario by which an LLM can get the scenario wrong?
To me, this article with this title is as much of a low effort spam as the PRs it is critiquing.
So this post got the the front page of HN with no comments, with a title "Reputation Scores for GitHub Accounts." The article does not show reputation scores, it barely even sketches out ideas for a reputation score.
It should be titled "We Need Reputation Scores for GitHub Accounts" to let people know that this is just a low effort feature request.
I didn't see the GitHub domain so I assumed it's going to be some blogger sharing their thoughts on a situation.
Not every title will be able to cater to everyone's ability to understand or misunderstand the intention, so it's worth taking the time to read it. I found it to be short and well written fwiw.