Hacker News new | ask | show | jobs
by briHass 1082 days ago
OAuth/OIDC flow through Facebook (or whoever) doesn't really have the same tight integration into the browser/OS that WebAuthn proposes, however. There's also no compelling reason for 'Website X' to support OIDC with Facebook/Google/Yahoo/other, because there's too many choices and if the provider of choice is down, your site is inaccessible to those users.

The major browsers and OSes already support WebAuthn, so it may be compelling for all 'Website Xs' to implement it, though the linked article presents a (dated) concern that they won't.

That's not the part I'm worried about: WebAuthn as a standard may work almost everywhere, but as a user, your ability to bounce around between browsers/OSes with your secrets coming with you may be restricted.