|
|
|
|
|
by parliament32
406 days ago
|
|
Excellent writeup. This is the true kicker: > Passkeys do not provide an attestation statement, as the attestation model currently defined in WebAuthn wasn't designed with syncing credentials in mind. On any platform, attestation and "syncing" are effectively opposites. Either you're getting attestation that the auth comes from a secure application and on secure hardware (read: non-exportable in-TPM crypto material), or not. As usual, it's a tug-of-war between security and convenience. |
|