







Passkeys are the future of authentication, but using them for data encryption is a disaster waiting to happen. Overloading these credentials creates a dangerous blast radius that can lead to the irreversible loss of a user's most sacred memories and documents.
Enpass: Secure Passkey & Password Manager That Keeps Your Data On Your Cloud Storage
With Enpass, choose where your passwords and passkeys are secured and synced – on your personal or business clouds (or even offline). Not on our servers
Keeping credentials safe in Jupyter Notebooks | Towards Data Science
Jupyter Notebooks are widely used in Data Science. But how should we store credentials safely and practically when using them?

Replace SecurityKey with Passkey #240
EDIT: switched to a different approach, keeping SecurityKey but dropping the browser hint. This still triggers 1P for me, if the yubikey behavior is unaffected then we should be good? This replaces the existing SecurityKey-based implementation with the newer Passkey one. This is a drop in replacement that means that we properly hook into external password managers like 1P, while still supporting the built in OSX support. SecurityKey is literally meant for "hardware as a token" auth, while Passkey is the newer password-replacement standard. Browsers interpret SecurityKey as "time to show the insert your hardware key dialog", and would ignore passkeys in password managers. No migrations required, this is fully backwards compatible. There are no tests related to this in the codebase, but if you want I can add some! I have verified this works E2E running the app locally with `just run-dev` ([screenshot](https://johanna.wisp.place/tranquil-pds-passkey.png)) Closes https://tangled.org/tranquil.farm/tranquil-pds/issues/100
Passkeys.directory
A community-driven index of websites, apps, and services that offer signing in with passkeys.

AChep/keyguard-app
A password manager that supports Bitwarden platform and KeePass (KDBX) files. It autofills your logins, supports passkeys, works offline, and runs a Watchtower that finds leaked and reused passwords and other issues.
Coming to Apple OSes: A seamless, secure way to import and export passkeys
Apple OSes will soon transfer passkeys seamlessly and securely across platforms.

Keycloak
Keycloak - the open source identity and access management solution. Add single-sign-on and authentication to applications and secure services with minimum effort.

Import from 1Password | Enpass Help
Moving from 1Password to Enpass is easy Passkeys (for signing into accounts with fingerprints or face recognition) are not transferrable by design, and cannot …

Data-at-Rest Encryption in DuckDB
DuckDB v1.4 ships database encryption capabilities. In this blog post, we dive into the implementation details of the encryption, show how to use it and demonstrate its performance implications.
Open Source Password Manager for Teams | Passbolt
Manage and share passwords securely with Passbolt. Open source, audited and built for teams that need collaboration, compliance and control.

mrtc0/aws-sso-go
A utility tool that allows credentials to be saved in 1Password even in an AWS SSO environment
Making end-to-end encrypted AI chat feel like logging in
We want private AI chat to be simple. Yet today, many end-to-end encrypted experiences still have a level of friction that make them feel like they’re from another era: it usually either involves a long seed phrase users are asked to “store securely,” insecure password based encryption, or apps that aren’t cross-device and lose your data periodically (on reinstall, browser cache clear, etc).

Best Password Manager for Business, Enterprise & Personal | Bitwarden
Bitwarden is the most trusted password manager for passwords and passkeys at home or at work, on any browser or device. Start with a free trial.

Secret Manager
Securely store API keys, passwords, certificates, and other sensitive data with Google Cloud’s Secret Manager.
I've been saying for nearly a year that getting the UX right for bsky's OAuth deployment is a major inflection point for reinforcing users mental models If we phrase things right, people will learn that this password UX controls access to my identity + slices of my atmosphere data (via my PDS)
Paul Rohr
Claude is inheriting a centralized app-centric bias here (which existing OAuth profiles may share) To wind up in a decentralized world where all "my data" lives on "my PDS" -- regardless of how many atproto apps I authorize to store stuff there for me (see 🧵) -- we should invert that paradigm