|
|
|
|
|
by nickray
1954 days ago
|
|
No, they cannot. This is an explicit design goal of FIDO (https://fidoalliance.org/specs/fido-security-requirements/fi...). The actual public key used for logging in to a specific site is completely random. Optionally, the website can ask for "attestation", which is intended to prove that the public key is from a specific vendor/model. To make this also unlinkable, devices are supposed to share attestation keys in batches of 100k units. |
|