logoalt Hacker News

nerdsniperyesterday at 7:48 PM1 replyview on HN

Those don't prove that a human is present. A FIDO2 key can be automated by electronic relay. The only way to do this involves device attestation - locking devices down and utilizing hardcoded TPM/Secure Enclave esque chips. The best we can hope for would be an open standard for those chips so that people can use them with their own X.509 certificates that lets them choose their own CA.


Replies

nitwit005yesterday at 7:56 PM

Real hardware doesn't mean a human is present either, unfortunately. It just means that you have to spend on real devices to bypass these defences.

show 2 replies