|
|
|
|
|
by yencabulator
920 days ago
|
|
Passkeys are the opposite of "private key in a mini-HSM" in that they're synced to a cloud provider. The goals of this whole thing have shifted, and it's hard to keep track of what was aiming at what goal. It started out as "actually secure 2FA" and now we're at "cloud-synced unphishable password replacements for non-technical users". |
|
If it's the hardware token, then the "certificate" (which can either contain your username or not aka discoverable vs non-discoverable credentials) that private key required for authentication will be stored and cannot be extracted in the secure element (until an exploit is found).