Hacker News new | ask | show | jobs
by mariusmarais 1500 days ago
It was also deliberate in the sense that they specifically wanted to make it impossible to link different identities on the same key in order to protect privacy. So you can be user1 and user2@ without the site being able to tell from the authentication process alone. (Obviously cookies, IPs and other side-channels exist, but if you protect against that, FIDO won't give you away.)