|
|
|
|
|
by TheNewsIsHere
740 days ago
|
|
I see device attestation is a different issue. Passkeys don't have to have device attestation. FIDO2 has long-supported this already in the form of AAGUIDs [1] which do address a valid use case of wanting to restrict the kinds of authenticators that can be used. For example if you have FIPS requirements. I do agree that passkeys, implemented in software, should categorically prohibit attestation. I think the cost of needing attestation should be that you have to require/invest in the actual hardware tokens. [1] https://support.yubico.com/hc/en-us/articles/360016648959-Yu... |
|