well, people are talking about it but it's not making a difference https://lucumr.pocoo.org/2025/9/2/passkeys/
The document there is laughable too, because KeepassXC is listed as "not performing User Verification" when it demands manual authorization per request. But this isn't good enough for the passkey people. Ultimately, I see any FOSS option being effectively banned from most services and all important ones. It's a parallel to how you must now be on Cloudflare's nice list or be banned from the majority of the internet.
I proudly print my entire KDBX file including passkey private keys and I encourage my elderly parents to do so too.
Lightning strikes (and assisting people with cleanup and repair from them) have taught me that there are definitely a class of threats that will leave me with paper but possibly no technology until I can go buy a cheap laptop to restart my digital life, SO BEING ABLE TO BACK EVERYTHING UP IS ABSOLUTELY ESSENTIAL.
His website says he's in Boston, so I seriously doubt he's ever seen what lightning can do or dealt with a hurricane or tornado.
In general, if you're in the FIDO Alliance and had anything to do with the kind of micromanagement that passkeys can allow, FUCK YOU. Go get a job at Walmart as a greeter. We'll all be better off.
Do you mean you print the raw values to paper or some encoding that would let you reconstitute the file (some giant QR code or something?)?
On macOS I use Strongbox's Print Database capability. On Windows, I'm testing a KeePass plugin I created that does the same thing and more (not quite ready for public release).
If I'm still around and coherent, I can re-type it into a KDBX-supporting app by hand (or maybe if I'm lucky only enough entries to get to a backup in cloud storage).
If the worst happens and I'm no longer capable of using a computer, it's an obviously-important document for whoever is cleaning up after me (I bet most people would understand the importance of a document with a bunch of usernames and passwords). They won't have to somehow break into my computer first to be able to figure out what online/digital matters of mine need to be dealt with.
EDIT: My current printout is 46 pages long.
Wow. Roughly how many entries do you have and how do you handle updates? I'm often being asked to change passwords and of course create new login entries.
I don't reprint for every password change. I will for major accounts. I will also immediately print for certain new accounts but not all (e.g. I didn't reprint for my HN account).
The Strongbox printout has the last printed date on it and my KeePass plugin even includes the SHA256 of the KDBX file just to be sure.
>I've already heard rumblings that KeepassXC is likely to be featured in a few industry presentations that highlight security challenges with passkey providers, the need for functional and security certification, and the lack of identifying passkey provider attestation (which would allow RPs to block you, and something that I have previously rallied against but rethinking as of late because of these situations).
https://github.com/keepassxreboot/keepassxc/issues/10407#iss...
They 100% will lock it down to "secure" options you cannot control. I suppose if there's any hope, it would maybe be the official keepass submitting to their demands, while keeping them easy to bypass with a recompile.
> [When UV is required, KeePassXC must request user verification or not handle the request]
> This implementation is not spec compliant and has the potential to be blocked by relying parties.
The only conclusion I can come to when it comes to this and the earlier kerfuffle regarding being able to export the plain text of passkeys is 'the spec is bad and you should feel bad'.
Passkeys are a convenience and as I stated above I always have a password as a fallback