(no title)
lxgr | 13 hours ago
Yes, because hardware authenticators (like Yubikeys) still commonly support it, and it makes sense there.
I guess they could add an explicit remark like "synchronized credentials must not support attestation", and given the amount of FUD this regularly seems to generate I'd appreciate that. But attestation semantics seem to be governed more by FIDO than the W3C, so putting that in the WebAuthN spec would be a bit awkward, I think.
valenterry|12 hours ago
lxgr|11 hours ago
In other words, you have a principal-agent problem: Users doing custom software passkey acrobatics and the banks liable for any funds lost.
Preferably, use of attestation should be limited to these (and enterprise) scenarios, and I do share the concern of others starting to use them as weak proofs of humanity etc.