top | item 36007432

(no title)

roundandround | 2 years ago

If a passkey is something you know then you are using a failed implementation. A fido/authn device is supposed to be able to attest to never having let the private key out, even with a relaxation to passkeys it should at least be sending it to another device that can attest.

discuss

order

JohnFen|2 years ago

True, but I'm hoping that "failed implementation" is accepted, because the correct implementation is too burdensome for my taste.