Hacker News new | ask | show | jobs
by TheNewsIsHere 545 days ago
The key itself, but the standard explicitly supports platforms, browsers, or password managers handling authentication to permit key use.

For example you can have a passkey where the private key is on a security token protected with a PIN or biometry.

You can have a private key live in a secure element on an endpoint too.

You could make a browser plugin that requires no auth whatsoever if you wished.