My read sees pi as a starter kit. It's job is to build personal workflows and not to dictate a workflow. Copy on the site calls it minimal and tells us to 'adapt pi to your workflow, not the other way around.' In other words a fleshed out pi is unique to you.
I have to think people aren't doing any research. Both Android and Apple sync your passkeys to your account. You can toss all your devices in a wood chipper, buy a replacement and still have access to all your passkeys.
Yeah, they do. But what if you want to move from Android to iPhone or vice versa? That's the big problem regarding these keychains/password managers. Some of them didn't even allow you to export your Passkeys until a few months ago, meaning you were literally locked into their platform.
Remember that your average user has no idea what a passkey is, doesn't remember half of their passwords and has no idea what a password manager is.
If you want to change it maybe tough. It doesn't have to be. Bitwarden has an open source self hosted option(you can also use their service), that can be set as provider in Android and Windows 11. KeepassXC is an option everything is in your kdbx file. Passkeys are so much more convenient and secure. If you do get stuck having to migrate, you can use your password (I would actually prefer just using multiple passkeys.) You don't need to do them all at once. Your average user is probably using whatever their device offers or nothing at all. I'd argue anyone that is tech savvy shouldn't be using either Google or Apple. If your account is disabled, you probably just lost anyway to retrieve your account unless you use a separate email address. I recently discovered cross device auth when a device I had a passkey was able to open my account on my pc that didn't have a passkey. TLDR ther are simple solutions that solve the 'lock in' issue.
So the use of Passkeys is contingent on allowing a major tech firm to spy on you?
I actually do have a Google account, but do not link my (Android) phone to it. I don't have WhatsApp or any other spyware on the device. I do use Telegram, Ankidroid, and a few other apps that I trust. I'm not a fanatic, but I won't enable and abet anybody to follow me around and report all that I do. How my position is considered an extreme position today eludes me, and frightens me as well.
How easy is it to switch off keepass? And how easy is it to export off whatever you imported to? Passwords are simple, just remember the text. Passkeys have alot of uncertainty around this
To switch off, just stop using Keepass. If you want want delete the entry on the site. You don't need to, since your Keepass file should be secure and passkeys are designed allow multiple for a site. Passwords are not equal to passkeys and not difficult to add. Everyone seems to think you need to create new passkeys for all your websites. You don't, add them as you go. The hassle of adding it should be less than using a password to login.
You aren't considering all the advantages of passkeys.
Passkeys only work on the domain they were created for. Password managers usually default to providing the password of the current website, but nothing stops you from pasting that in at any site.
There is no danger to the credential db being stolen. The website only has your public key.
A website using passkeys can support cross device authentication which allows you to login to on a computer without it ever seeing your credentials.
I'm sure that isn't a complete list. My last point, despite all the comments here, there is no vendor lock in. Bitwarden provides an open source self hostable option. On both Android and Windows 11, you can change your passkey provider to Bitwarden. A proper passkey implementation, should allow multiple passkeys to provide access. My bank does exactly that.
> Passkeys only work on the domain they were created for. Password managers usually default to providing the password of the current website, but nothing stops you from pasting that in at any site.
Considering how my bank has changed the sign-in domain three times (as well as some other sites), I consider this a feature, not a shortcoming.
Unfortunately probably implementation specific, but you don't always need to have multiple passkeys. There is cross device passkey login. I had this occur in the last couple weeks. Evidently I had created a passkey on my phone. Logging into that site on my PC, it identified that I had a passkey and allowed me to authenticate using my phone.
There is security value. A passkey will not work anywhere except the actual website. Fake look a like sites can't get the credentials. Evidently they can trick you into authorizing their device.
That's also how any good password manager works. You'd have to manually copy-paste the password to get around the same-site fill restriction (whether it's autofill or manual fill).
This is one of the key security features of passkeys. I did a little searching and the work around is to do a standard fake website that prompts for your standard credentials. That should be a fairly simple fix. Require access from a new device to be authorized from another source with an explanation that they will never request this info.
If you were the FBI, much higher than you are assuming. Read up on https://en.wikipedia.org/wiki/Bojinka_plot . The FBI had the plans for the foiled first attempt for 9/11.
The US isn't being single handedly dismantled. The damage is being done by thousands. You are fooling yourself if you think it can't happen in the EU. People have been working on this for decades. Obviously if it were to happen it's not going to be one rogue, but multiple right leaning countries. As long as you believe it can't happen, the easier it becomes to do it.
There sure are thousands involved, but I’m confident a lot of the destruction we see wouldn’t be possible without the savage in chief and the lowering of standards he brought. This man is a political black swan. Things that used to be unthinkable are suddenly happening all the time.
Things can of course turn sideways in the EU too, but it’s massively more difficult to do so without a broad coalition across multiple independent nations.