Hacker News new | ask | show | jobs
by immibis 405 days ago
Attestation is probably the worst feature of passkeys.

From a freedom perspective, I need to ensure that Google has no idea whether my device is an Android phone bought from an officially licensed manufacturer, or Waydroid or android-x86. Compliance is not an issue because I am, ya know, some random guy. The only way I can ensure this happens is by ensuring attestation is not possible.