|
|
|
|
|
by digiown
129 days ago
|
|
> Approximately nobody thinks users shouldn't be able to access their keys in the general case Citation needed. To me it seems to be the quiet part that they aren't saying out loud. If it's just a consequence of the spec being unfinished, then they shouldn't threaten to ban KeepassXC for this. The purpose of a system is what it does, and commercial passkey implementations lock users out of their credentials and uses it to strengthen vendor lock-in. > Is it a super useful feature? No It's security theater and a way for websites to annoy users unnecessarily. > KeePassXC is not "being threatened with being banned via attestation". https://github.com/keepassxreboot/keepassxc/issues/10406#iss... It's a thinly veiled threat. Making a certification process and refusing to certify KeepassXC is exactly the same as banning it. |
|
Brother, there's no conspiracy here. Attestation requires a trusted third party, same as TLS. You know how you can generate self-signed certificates, but your browser and other tools don't trust them? Attestation is like that. What you keep calling a "ban" is a trivial operational consequence of this. Individual services still get to decide whether attestation is even required, and in the consumer space you aren't going to see it much.