> trying to pressure KeepassXC to remove exporting passkeys in an open format
I'm not sure that's an entirely accurate representation of the request? At least from a quick skim the claimed issue is being able to export keys in plaintext. For example, from the issue author:
> I strongly recommend you temporarily disable this feature or at a minimum require file protection/encryption.
And later:
> > Besides, determined advanced users could just write code to decrypt the kdbx file and extract the passkeys anyway.
> That's fine. Let determined people do that, but don't make it easy for a user to be tricked into handing over all of their credentials in clear text.
> I don't quite understand why requiring file protection/encryption can't be a temporary minimum bar here.
To me that doesn't sound like they're requiring a proprietary format. Something like AES encrypted JSON sounds like it'd work as well, and that sounds pretty "open" to me?
> > That's fine. Let determined people do that, but don't make it easy for a user to be tricked into handing over all of their credentials in clear text.
Has there even, ever, been an instance of that happening?