| > they are treated like a virtually secret value by the platform "virtually" is the problem for webauthn the public key isn't revealed to everyone for privacy reasons, not cryptographic reasons the webauthn API is also only part of the cryptosystem the platform authenticator (yubikey, windows hello, password manager, whatever) may have an API to list stored public keys without any authentication at all because they were never intended to be protected |