|
|
|
|
|
by md_
1576 days ago
|
|
> The point is that it takes that choice out of the users' hands. Unclear to me why you think the user--and not the IdP--should have the final say here. > You shouldn't. That's like expecting to be able to use your work laptop for personal stuff. Except FIDO identities are unlinkable even if using the same hardware. |
|
I understand for a corporate setup employees are threat vectors. But that depressing outlook isn't how most people view the consumer space. We want: consumer x signed this auth challenge. We do not want: authority Y said consumer X signed this auth challenge. That’s just CA SSO style oligarchy repeated.
Why wouldn't you trust the consumer and their preferred authentication agent to participate in an authentication challenge? Consumer apps don’t need to ensure that consumers are using a hardware token device they just need to arrange an authentication dance that doesn't involve a shared secret.