top | item 42517874

(no title)

Scion9066 | 1 year ago

A passkey is a synced, discoverable WebAuthn credential. While many implementations protect the private keys with additional security measures like secure enclaves or TPMs, it's not required. If you want to use an implementation that doesn't use those types of lock-ins, even when they're there to protect your credentials, you can. Multiple software-only implementations exist.

discuss

order

eikenberry|1 year ago

Until they start trying to enforce attestation. Then your only choice will be giving a large corporation control over your online access.