Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Unless the service you are trying to log in to requires you to only use an approved authenticator, as is explicitly supported by the spec[1].

[1] "To be very honest here, you risk having KeePassXC blocked by relying parties." https://github.com/keepassxreboot/keepassxc/issues/10407#iss...

More examples here https://fy.blackhats.net.au/blog/2025-12-17-yep-passkeys-sti...



Right, that sucks. But the service could also only allow you to use the Google SSO, it's not really a problem coming from the passkeys...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: