logoalt Hacker News

cpburns2009today at 3:08 PM3 repliesview on HN

I can find my ssh keys in `~/.ssh`. No such place exists for passkeys.


Replies

kingstnaptoday at 4:19 PM

Thats because the people behind passkeys are paternalistic and don't trust users. I had an argument with one of them a few months ago.

https://github.com/keepassxreboot/keepassxc/issues/10407

https://news.ycombinator.com/item?id=47189749#47193048

My read on it all is that FIDO is stuck in some sort of groupthink. They don't feel the boots on the ground confusion around passkeys being opaque. They only care about phishing and being called "insecure" and don't care about anything else. Hence why WebAuthn has additional weird anti features like AAGUID for provider authentication.

Another one of those ridiculous threads is saying you gotta have support for nonsense like user presence verification.

https://github.com/keepassxreboot/keepassxc/issues/10406

show 1 reply
microflashtoday at 3:19 PM

It depends on the app you’re using to save passkeys. Use Keepass and it saves the passkeys into kdbx file (similar to SSH keys).

show 1 reply
datakantoday at 3:36 PM

I can pull up all my passkeys in 1Password or Bitwarden without issue.

show 1 reply