Post BAH4Qthi4ygElXqVd2 by madalex@fosstodon.org
 (DIR) More posts by madalex@fosstodon.org
 (DIR) Post #BAGhTHDlJhnhKt0Hpo by bitwarden@fosstodon.org
       0 likes, 0 repeats
       
       🫆 Are your passkeys portable? #Bitwarden #Passkeys #Phishing
       
 (DIR) Post #BAGhUZ0keuvanhX1f6 by bitwarden@fosstodon.org
       0 likes, 0 repeats
       
       Bitwarden supports the Credential Exchange Protocol (CXP), so passkeys can move directly between supported apps.Available on iOS 26+ and Android 10+.
       
 (DIR) Post #BAGjJ1H7wofQtSoY8u by bitwarden@fosstodon.org
       0 likes, 0 repeats
       
       @breizh Feel free to share more detail. Passkeys are phishing resistant, and you can also log into your Bitwarden account with a passkey stored on a hardware key.
       
 (DIR) Post #BAGkh1hk6S8d84H5tY by bitwarden@fosstodon.org
       0 likes, 0 repeats
       
       @breizh Thanks for sharing!Looks like there might be a few inaccuracies in the articles, biometrics is a local/client side process, Bitwarden passkeys are built with the credential exchange protocol (so can be imported/exported), and if you're using a hardware key, someone would need to have both the physical key and your pin (which wipes after X number of failed attempts).
       
 (DIR) Post #BAGoA7YdigsHXia8Cu by mmu_man@m.g3l.org
       0 likes, 0 repeats
       
       @bitwarden decline to tell?
       
 (DIR) Post #BAGoGr7pDJnGbbFcRc by amdg2@diaspodon.fr
       0 likes, 0 repeats
       
       @bitwarden do you have more info on that protocol? So far I didn't use passkeys as it seems very easy to get locked out of accounts when you use many different devices (I use at least 6 devices routinely).
       
 (DIR) Post #BAGoHT4y6O5UJkCsGe by bitwarden@fosstodon.org
       0 likes, 0 repeats
       
       @mmu_man Valid!
       
 (DIR) Post #BAGoJfauXeRniCCIwC by bitwarden@fosstodon.org
       0 likes, 0 repeats
       
       @amdg2 Sure thing, this is a great starting place: https://fidoalliance.org/specifications-credential-exchange-specifications
       
 (DIR) Post #BAGphKndbjKa7dzxcu by stelb@mastodon.social
       0 likes, 0 repeats
       
       @bitwarden most are on hardware keys.
       
 (DIR) Post #BAH4Qthi4ygElXqVd2 by madalex@fosstodon.org
       0 likes, 0 repeats
       
       @bitwarden I have no passkeys nor will I ever get any. So not sure if that counts as a yes or no.
       
 (DIR) Post #BAH5uM8hXJHlJC57tQ by bitwarden@fosstodon.org
       0 likes, 0 repeats
       
       @madalex Everyone has a different approach, feel free to share more detail.
       
 (DIR) Post #BAH6WV9WTQBUGbeg1A by madalex@fosstodon.org
       0 likes, 0 repeats
       
       @bitwarden My understanding is that passkeys "solve" three problems. Passwords get reused, are forgotten or can get phished. I use a password manager to not reuse passwords, not to have to keep them in an unsafe location and and to go the website the password is for via the entry in said password manager.
       
 (DIR) Post #BAH7ixqhhrTIhFMLBY by bitwarden@fosstodon.org
       0 likes, 0 repeats
       
       @madalex Yes, passkeys by nature are unique/complex, and only work on the originating website. Many phishing attempts are users typing URLs in manually, mistyping, and landing on a phishing site, so we always recommend to use your saved bookmarks, or launch directly from your password manager.
       
 (DIR) Post #BAIfqGCRj3pQRVleU4 by bitwarden@fosstodon.org
       0 likes, 0 repeats
       
       @RaBenedictus Hey there, can you double check to see if Bitwarden is set as your passkey provider?Bitwarden > Settings > Autofill > Passkey Management > Choose Bitwarden as your preferred service.
       
 (DIR) Post #BAVa0DNRfGrMdgVhVA by madargon@is-a.cat
       0 likes, 0 repeats
       
       @bitwarden now I wonder... Passkeys on hardware keys aren't portable, just platform-independent, right? Didn't try to do anything with them after creation so I don't even know.