Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm sure you mean KeePassXC? KeePassX has been dead for years.


KeePassXC added support for passkeys in 2.7.7, released a week ago:

https://keepassxc.org/blog/2024-03-10-2.7.7-released/

This post prompted me to give it a try at webauthn.io.

Passkey support is disabled by default, so you have to enable it in the settings for the browser extension. After that, the UI seems reasonable enough. It creates an entry with a "Passkey" tag, where the Password field is empty, and the credentials are stored as additional attributes on the Advanced tab.

One thing I'm not sure about: although the extension has a setting to fall back to the browser's own passkey support, when I dismissed the KeePassXC prompt, I did not get a prompt from Firefox.


> Passkey support is disabled by default

Thank, I hadn't noticed that, I thought I had to wait for the extension to be updated after the announcement from KeepassXC.

> After that, the UI seems reasonable enough.

I tried it on webauthn.io and I'm wondering if there's a point in showing a prompt on every login attempt, if passkeys are phishing proof. Why not just allow the login right away? Maybe show a notification that it happened, but why wait for user confirmation?


The fallback should be fixed in extension version 1.9.0.2.


Yes, my bad.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: