logoalt Hacker News

coldpietoday at 3:32 PM1 replyview on HN

Unless the service you are trying to log in to requires you to only use an approved authenticator, as is explicitly supported by the spec[1].

[1] "To be very honest here, you risk having KeePassXC blocked by relying parties." https://github.com/keepassxreboot/keepassxc/issues/10407#iss...

More examples here https://fy.blackhats.net.au/blog/2025-12-17-yep-passkeys-sti...


Replies

palatatoday at 4:46 PM

Right, that sucks. But the service could also only allow you to use the Google SSO, it's not really a problem coming from the passkeys...