Readit News logoReadit News
varjolintu commented on Don't use passkeys for encrypting user data   blog.timcappalli.me/p/pas... · Posted by u/zdw
tredre3 · 13 days ago
Is this really how password managers extensions work? They inject arbitrary javascript in every page you visit?

I would have naively thought that there'd be a better and safer API for it, considering that all browsers already have the infrastructure in place to handle login autocomplete.

varjolintu · 12 days ago
Yes. This is mandatory for all browser extensions. There's no API behind a separate permission, even if would be the best way to handle this.
varjolintu commented on Don't use passkeys for encrypting user data   blog.timcappalli.me/p/pas... · Posted by u/zdw
Cyph0n · 13 days ago
The problem with passkeys is that they aren’t exportable (at least from Bitwarden).
varjolintu · 12 days ago
Actually, if you export your vault as JSON, the passkeys are there in plain-text.
varjolintu commented on Discord will require a face scan or ID for full access next month   theverge.com/tech/875309/... · Posted by u/x01
mmlkrx · a month ago
They are planning on doing something similar:

Discord is also rolling out an age inference model that analyzes metadata like the types of games a user plays, their activity on Discord, and behavioral signals like signs of working hours or the amount of time they spend on Discord.

“If we have a high confidence that they are an adult, they will not have to go through the other age verification flows,”

varjolintu · a month ago
I'm curious to know what this "model" actually means. A real-time AI monitoring for conversations?
varjolintu commented on Passkeys: They're not perfect but they're getting better   ncsc.gov.uk/blog-post/pas... · Posted by u/ashergill
josephcsible · 4 months ago
> I read about Passkey comittee being against open source passkey managers during start of this year (can't reference it, sorry) but with open source password/key managers already supporting passkeys, i don't think it turned out to be true.

Here's an Okta employee threatening to use the attestation (anti)feature of passkeys to block open-source implementations, because they allow you to export your passkeys: https://github.com/keepassxreboot/keepassxc/issues/10407#iss...

varjolintu · 4 months ago
FYI: If you export your Bitwarden vault as plain JSON, passkeys are included in plain-text too. So, it works similar to KeePassXC.
varjolintu commented on Passkeys and Modern Authentication   lucumr.pocoo.org/2025/9/2... · Posted by u/Bogdanp
unsnap_biceps · 6 months ago
The walls are going to come down. KeyPassX supports passkeys and allows you to export them as you wish. 1Password and Apple Passwords have both said they're going to support exporting and importing of passkeys.

Yes, it's awful during the transition period while the tech matures, but there is a path towards a great future.

varjolintu · 6 months ago
KeePassX is long dead, and it's not with "key" but with "kee" -> KeePassXC. Thank you :)
varjolintu commented on Japan's Creepiest Station   tokyocowboy.co/articles/d... · Posted by u/ewf
ape4 · 7 months ago
Can anyone translate the sign?
varjolintu · 7 months ago
ようこそ 日本一のモグラえき 土合へ Translates to something like: "Welcome to Doai, Japan's number one mole station (mogura-eki)".
varjolintu commented on FIDO Alliance publishes new spec to let users move passkeys across providers   fidoalliance.org/fido-all... · Posted by u/Terretta
varjolintu · a year ago
The worst thing about passkeys is how browser extensions must handle them: using JavaScript injections to the web page. Of course this means _any_ browser extension could do the same and be the man-in-the-middle inspecting the passkey creation and authentication. I'd be glad to have some kind of standard API behind a proper permission for handling passkeys.
varjolintu commented on Concerns about Passkeys   me.micahrl.com/blog/conce... · Posted by u/mrled
halJordan · 2 years ago
In general any one can make a passkey app. Keepass chooses to be out of spec. No one is gatekeeping them. If an nginx server receives bad data it spits out a 400 error instead of processing the request. One of the reasons browsers are still effed up is because they refused to be standards compliant and were still paying for quirks mode. I would like to see this article complain about an http server handling a bad actor.

Otherwise, create multiple passkeys. Create a passkey in your ios keychain and in your Keepass app. This walled garden has a gate, walk through it.

varjolintu · 2 years ago
According to this list majority of the clients are out of spec: https://passkeys.dev/docs/reference/known-issues/

u/varjolintu

KarmaCake day295June 26, 2017View Original