Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> see a compelling argument for passkeys

It's tied to vendor lock in. Which increases the ability of companies who develop certain technologies for the masses to increase the friction of interacting with things outside of the ecosystem. The argument is that if a user is unable to use an alternative, by hook or crook they will pay increasingly high subscriptions to access the services provided by that ecosystem. This increases a number on a spreadsheet, the only true compelling argument one could say



> It's tied to vendor lock in

If you're referring to the inability to transfer passkeys across systems, that should be improving soon.

https://blog.1password.com/fido-alliance-import-export-passk...

https://arstechnica.com/security/2025/06/apple-previews-new-...


As long as the passkey spec includes remote snitching (attestation) your keepass open source alternative will exist only because big tech allows it, and it will end when big tech demands it. The entire import/export standard is a red herring.


It's sort of happening already. Members of FIDO threatening to block KeepassXC users [0] from logging in, unless KeepassXC complies with FIDO demands regarding specific implementation

[0] https://github.com/keepassxreboot/keepassxc/issues/10407#iss...


On one side of the pond, we have the EU's Digital Markets Act to protect consumers. It has teeth and it's already being used to ensure consumers have choice.


But only in the EU. You can already see iOS behave differently depending on which side of the pond you're from.


Not so sure that EU bureaucrats will understand and fix that problem. With NIS2, they let the IT-security-crapware lobby dictate draconian and mostly stupid security laws. Could be that the security-paranoid part of the bureaucracy overrides the consumer protection part in that case.


> that should be improving soon

Then _soon_ I might reconsider using passkeys.

I'm not making changes to my security workflows now based on promises that the lock-in potential will be reduced as some unspecific point in the future.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: