|
|
|
|
|
by hedora
741 days ago
|
|
Here's a great github discussion about passkey plaintext exports. Apparently, the FIDO alliance is considering adding an attestation feature that would allow websites to block various passkey implementations: https://github.com/keepassxreboot/keepassxc/issues/10407#iss... e.g., they could block ones that allow exports, or they could block ones that are FOSS. To their credit, it looks like Apple's throwing their weight around to prevent such blocking from being technically possible. The more I hear about this standard, the more concerned I become. |
|
I use AAGUID attestation for Yubikeys at work, but that addresses an actual security need to enforce known authenticator types and prevent enrollment of non-hardware tokens.