Hacker News new | ask | show | jobs
by gre345t34 614 days ago
To be fair, the webauthn spec expressly forbids facilitating the extraction of credentials from the authenticator (though arguably even syncing between devices violates the spec).
1 comments

If the vast majority of implementers (by users) are not compliant with a spec, that arguably says something about the spec as well.