Hacker News new | ask | show | jobs
by Bu9818 987 days ago
If I'm allowed to use a software implementation (like with TOTP) so that my private keys can be stored in for e.g. a KeePassXC database so that I can back it up by having multiple copies, then I'm okay with it. Is it possible for sites to deny certain webauthn providers (ignoring scenarios like attestation forcing you to use a locked down system where you can't run keepassxc)?

Hopefully Tor Browser can turn on security.webauth.webauthn in a safe way before sites force it to be used, too.