Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Bitwarden works just as well on Android. In fact, it's even easier when it comes to managing multiple passkeys per domain. And yes, that includes CTAP2 logins ("scan a QR code with your phone to log in").





From what I saw, 1Password was fighting tooth and nail to get into the FIDO Alliance, as the big corps were trying to leave 3rd party password managers behind. I assume without fights like this, all 3rd party password managers would have been left behind. I think that was the plan, thankfully it didn’t work.

Keepass was straight up threatened with blackballing using the attestation feature an enforcement mechanism. This thing was barely out of the gate before the mask slipped.

For now. But will that always be the case? And what if sites use attestation to reject passkeys from providers loke bitwarden or keepass(xc)?



Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: