• Sign in
  • Sign up
Elektrine
EN
  • EN English
  • 中 中文
Log in Register
Modes
Overview Search Chat Timeline Communities Gallery Lists Friends Email Vault VPN
Back to Timeline
  • Open on hachyderm.io

Ricky Mondello

@rmondello@hachyderm.io
mastodon 4.5.7

💚 Friend
🏳️‍⚧ Trans, nonbinary, they/them
😷 Caring, careful
🔑 Passkeys & passwords
🧛🏻‍♀️ It’s not a phase
🦔 Speedrunner

0 Followers
0 Following
Joined November 21, 2022
Pronouns:
they/them
Website:
https://rmondello.com
Twitch (amateur retro streamer):
https://twitch.tv/rmondello

Posts

rmondello
Ricky Mondello
@rmondello@hachyderm.io

💚 Friend 🏳️‍⚧ Trans, nonbinary, they/them 😷 Caring, careful 🔑 Passkeys & passwords 🧛🏻‍♀️ It’s not a phase 🦔 Speedrunner

hachyderm.io
Ricky Mondello
Ricky Mondello
@rmondello@hachyderm.io

💚 Friend 🏳️‍⚧ Trans, nonbinary, they/them 😷 Caring, careful 🔑 Passkeys & passwords 🧛🏻‍♀️ It’s not a phase 🦔 Speedrunner

hachyderm.io
@rmondello@hachyderm.io · 4d ago

This is a beautiful post that I recommend reading. https://samhenri.gold/blog/20260312-this-is-not-the-computer-for-you/

View on hachyderm.io
181
0
112
0
rmondello
Ricky Mondello
@rmondello@hachyderm.io

💚 Friend 🏳️‍⚧ Trans, nonbinary, they/them 😷 Caring, careful 🔑 Passkeys & passwords 🧛🏻‍♀️ It’s not a phase 🦔 Speedrunner

hachyderm.io
Ricky Mondello
Ricky Mondello
@rmondello@hachyderm.io

💚 Friend 🏳️‍⚧ Trans, nonbinary, they/them 😷 Caring, careful 🔑 Passkeys & passwords 🧛🏻‍♀️ It’s not a phase 🦔 Speedrunner

hachyderm.io
@rmondello@hachyderm.io · Feb 28, 2026
An incredibly American experience: handing my drivers license over to rent a car in New Zealand and having the employee confirm which digits of my birthday are my birth month and which are my birth day.
View on hachyderm.io
70
0
16
0
rmondello
Ricky Mondello
@rmondello@hachyderm.io

💚 Friend 🏳️‍⚧ Trans, nonbinary, they/them 😷 Caring, careful 🔑 Passkeys & passwords 🧛🏻‍♀️ It’s not a phase 🦔 Speedrunner

hachyderm.io
Ricky Mondello
Ricky Mondello
@rmondello@hachyderm.io

💚 Friend 🏳️‍⚧ Trans, nonbinary, they/them 😷 Caring, careful 🔑 Passkeys & passwords 🧛🏻‍♀️ It’s not a phase 🦔 Speedrunner

hachyderm.io
@rmondello@hachyderm.io · Feb 27, 2026
Just this week I’ve heard people on two different podcasts talking about how in macOS Tahoe, AutoFill of verification codes received in Messages or Mail work in more Mac apps than before, including popular web browsers. The people seemed very happy about it. I just wanna say that people talking about this brings me joy, because I worked hard and did unspeakable things to get that to work.
View on hachyderm.io
129
0
32
0
rmondello
Ricky Mondello
@rmondello@hachyderm.io

💚 Friend 🏳️‍⚧ Trans, nonbinary, they/them 😷 Caring, careful 🔑 Passkeys & passwords 🧛🏻‍♀️ It’s not a phase 🦔 Speedrunner

hachyderm.io
Ricky Mondello
Ricky Mondello
@rmondello@hachyderm.io

💚 Friend 🏳️‍⚧ Trans, nonbinary, they/them 😷 Caring, careful 🔑 Passkeys & passwords 🧛🏻‍♀️ It’s not a phase 🦔 Speedrunner

hachyderm.io
@rmondello@hachyderm.io · Jul 12, 2025

iOS 26 (and OSes 26 in general) add an OS-facilitated way to securely migrate your passkeys, passwords, and other data saved in one password manager app to another. The details here are super interesting and are covered in the WWDC25 video “What's new in passkeys” (https://developer.apple.com/videos/play/wwdc2025/279). The rest of this post includes a summary of part of that video and other publicly-available information. (I am not breaking any kind of news here.)

- Data is sent from one app to the other without exporting any kind of file to a filesystem. This means it can’t accidentally be accidentally uploaded to an attacker attempting to compromise one or all of your accounts.
- There’s an OS API that password manager apps call to export their data. Then, securely and out-of-process, users select which app to send the data to. They are reminded of the scope of the data, and authentication with local biometrics or their passcode to confirm sending the data.
- The destination app is not revealed to the source app.
- Remember that crappy unstandardized CSV format for migrating passwords between password managers? It’s going to be a thing of the past, because…
- The data sendable via the API is explicitly based on the “Credential Exchange Format” (https://fidoalliance.org/specifications-credential-exchange-specifications/) standard. This standard is being developed in the FIDO Alliance, the standards body working on passkeys, but the spec covers far more than passwords and passkeys. In fact, it was co-developed by 1Password, Dashlane, and others. There’s a collection of Swift structs in the SDK implementing the standard, with as few modifications as possible.
- The data format part of the API is versioned so it can evolve as the Credential Exchange Format does.

I know it’s taken some time for this to come to fruition, but I hope that delivering a phishing-resistant credential migration process based on open standards (with a credential format standardized for the first time!) makes up for the delay. As I have said since day 1, your passkey data is yours. Passkeys are not a form of “vendor lock-in”.

View on hachyderm.io
373
0
171
0
313k7r1n3

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • VPN Policy

Email Settings

IMAP: imap.elektrine.com:993

POP3: pop.elektrine.com:995

SMTP: smtp.elektrine.com:465

SSL/TLS required

Support

  • support@elektrine.com
  • Report Security Issue

Connect

Tor Hidden Service

khav7sdajxu6om3arvglevskg2vwuy7luyjcwfwg6xnkd7qtskr2vhad.onion
© 2026 Elektrine. All rights reserved. • Server: 13:26:07 UTC