logoalt Hacker News

timmyc123yesterday at 12:29 AM1 replyview on HN

A passkey is a discoverable credential (aka resident key) in spec terminology. But the type of credential has no relationship to attestation (which is not used in the consumer passkey ecosystem).


Replies

spencerflemyesterday at 9:47 AM

Ah my bad, I thought the distinction was resident = stored on a YubiKey/Secure Enclave/TPM and that was what made them resident.

To my credit I think yubikey uses the term that way and webauthn has a different definition but in the context of passkeys you’re right.

show 2 replies