That means that they're literally impossible to back up. If 1Password goes down, or the company stops operating, or anything else like that, your Passkeys are just... gone. Absolutely no way to recover them.
That means that they're literally impossible to back up. If 1Password goes down, or the company stops operating, or anything else like that, your Passkeys are just... gone. Absolutely no way to recover them.
See a recent post in the 1Password passkey AMA about this subject: https://old.reddit.com/r/1Password/comments/16to6x7/hey_redd...
Re. your point about 1Password going down: Your passwords and passkeys are all stored locally when they sync to your devices. If 1Password becomes unreachable for any reason, you still have access to everything in your vaults, you just can't sync between devices any more.
Edit: I took the last sentence out, it was childish on my part.
Also (i think) none of them are open source?
Yes, some individual implementers recognize the issue and have "log in with another device" (which is the best option you can have, although still quite clunky), so you can solve the chicken-and-egg problem of logging in on another platform's device to add your another platform's passkeys. But to best of my awareness, this is not a part of any standard or recommendation (it should've been).
And other implementers do the contrary and artificially limit your options so you can't add a portable authenticator with them without some hacking around.
While noble, why? 1Password exports a plaintext file that has all of the credentials in plaintext already.
Not “or”. Passcodes don’t provide availability, so they are not providing security.
This is undergrad-level stuff.
I still think the real reason is lock-in, but I could imagine this is their official justification.
Because you can export plain-text passwords just fine, and they give you exactly the same access as a PassKey does.
In other words, if a website doesn't like that their passkeys can be exported, they can block KeePassXC.
Temporarily, i guess? Since it's not stored in an open format?
Is this not bound to some sort of "Secure Enclave" or whatever, and won't survive a reinstall / restore / etc. ?
1: of course, a user could still be tricked into adding an attacker's passkey to their account or something
It was obvious from day 0 (to anyone except for Apple and Microsoft) that people do have multiple devices and not all of them are from a single vendor. My only explanation is that they deliberately decided to ignore this aspect, because it wasn't in corporate interests.
They made it significantly easier to lose all the passkeys, because they made it very hard to add multiple passkeys (you literally have to walk/run/drive/fly and grab every different device you have, get it online and register - or get properly locked in with a single vendor and pray they work for you, forever).
Carrying a Yubikey does not work (you can lose it). iCloud/Windows Hello does not work (you can be on a non-Apple/Microsoft device). 1Password is better but still does not really work (you can lose access to your account). They're all SPOFs, and avoiding SPOF was deliberately made hard (you can't easily enroll a "backup" Yubikey that you don't have at hand, and if you have it at hand it's not a backup anymore).
Heck, "official" demo at passkeys.io doesn't even bother to showcase how multiple passkeys are going to be a thing at all, which is an obvious red flag.
That is, not to mention that a growing number of vendors contributed to the crappiness by limiting what kind of authenticators and which platforms one can use (BestBuy, PayPal and so on), contributing to decreased security and increased headaches.
We fixed this on mobile years ago but email is still a goddamn mess. Moral of the story: never get locked in.
And sure, you and I have multiple devices. We're in the minority. Most people just have the one. Without another way in, they're irrevocably fucked.
Agile Bits support kept insisting it was the same as the old native app and people kept complaining about bugs until I stopped following it.
Do you have a different workflow where you use the main app a lot?
With 1password 7 whe safari plug in is more conveniently integrated than the chrome one which is pretty clunkly by comparison, though this is true of other chrome plug ins too. But that's not a big deal as I rarely use chrome anyway, just for google docs which don't need 1password.