|
|
|
|
|
by crote
317 days ago
|
|
Having a single certificate makes it trivial to implement cross-website tracking. FIDO2 (and by extension Passkeys) prevent this by having a unique key for every (origin, username) combination. Also, having a single cert shared across multiple hardware tokens is a security risk, as it becomes impossible to distinguish the tokens or revoke only a single one of them. |
|
Users who truly need that ability can create multiple certificates, and synchronise them as appropriate.