• hummingbird@lemmy.world
    link
    fedilink
    English
    arrow-up
    89
    ·
    2 days ago

    Sadly did not dig into the whole “the other side decides which device you are allowed to use” topic, a feature inherently build into passkeys.

    • Schal330@lemmy.world
      link
      fedilink
      English
      arrow-up
      16
      ·
      2 days ago

      I think that is only an issue based on what Passkey attestation is configured by the relying party? From what I have read a lot of public facing companies implementing it will have passkey attestation statements configured as None, which typically means there isn’t an authenticator certificate verification.

      • Natanael@infosec.pub
        link
        fedilink
        English
        arrow-up
        5
        ·
        1 day ago

        Only companies issuing their own passkeys on company hardware has a reason to enable attestation (forcing use of company approved devices throughout). Any public facing service has no reason to use attestation.