Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Pretty sure 1password can store and use passkeys.


It does, but 1password forces you to use the browser extension in order to manage passkeys.

I still don't trust browser extensions. I'm probably being irrational, but it is hard to find good sec info on how "safe" extensions really are.


If you're copy-pasting passwords from 1password into your browser you're making yourself vulnerable to phishing. The browser extension's autofill will at least check the domain name and prevent that.


Somewhat. Lots of sites log you in via a different domain.


That’s the domain you’d have saved, then. You can also save multiple domains on a credential.


I know about the issue and still experience it. Sometimes these things also change over time. Of course, it still helps to use the browser extension!


That does get me every now and then. “Why has this stopped autofilling…”


It certainly can.


until the time comes that it's used for spammers and everyone requires providers from a list that only included apple and Google.

y'all trying very hard to not see where this will go.


This would be possible via attestation, but both Apple and Google removed that feature when they replaced their respective device-bound authenticator implementations with cloud-synchronizing ones. (Google technically still allows creating device-bound ones and supports attestation in that case, but that's arguably a niche use case and not what people are talking about when they say "passkeys".)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: