Hacker News new | ask | show | jobs
XSS Is Deadly for Passkeys: The Hidden Risk of Attestation None (scotthelme.co.uk)
8 points by moebrowne 28 days ago
2 comments

Passkeys: as if we didn't have enough ways Big Tech could deprive you of your digital life. Just say "hell no!"
What's the concern with using passkeys?
Not the OP, but I'd assume they are talking about 'direct' attestation mode creating vendor lock-in
I can kind of see it, but you can also just use an authenticator from any manufacturer, or have multiple types that you use? I'm just curious what I'm overlooking.
> I've encountered multiple sites that now use authenticatorAttachment options to force you to use a platform bound Passkey. In other words, they force you into Microsoft, Google or Apple. No password manager, no security key, no choices.

https://fy.blackhats.net.au/blog/2025-12-17-yep-passkeys-sti...

and more discussion here: https://news.ycombinator.com/item?id=46301585

Interesting, could you link me to some of those sites so I can investigate?
The hidden risk of attestation none: the user might (gasp) use a libre authenticator!

This same ordeal is why lots of Android software is intentionally broken on non-Google operating systems, and it would be a terrible blow for the web if it worked like that for every website with a login. Passkeys are that future, and it's very hard to take anyone who encourages their use seriously. Encouraging attestation, like here, is even worse.