logoalt Hacker News

throwawayk7htoday at 5:21 AM2 repliesview on HN

that's not true. Passkeys have an optional remote attestation capability, which second parties can use to completely enforce aspects of your keys, such as them being non-transferrable or not usable without a screen touch etc.


Replies

cyberaxtoday at 8:12 AM

Passkeys (as defined in the spec) by definition don't.

Non-passkey WebAuthn keys can have additional attestations.

show 1 reply
vel0citytoday at 5:38 AM

This doesn't change the fact it can still be your physical device that remains in your personal control.

I can stash them on a yubikey or similar device and still meet those requirements. It's still only my device, it doesn't rely on other services, etc.

show 1 reply