• Schal330@lemmy.world
    link
    fedilink
    English
    arrow-up
    16
    ·
    2 days ago

    I think that is only an issue based on what Passkey attestation is configured by the relying party? From what I have read a lot of public facing companies implementing it will have passkey attestation statements configured as None, which typically means there isn’t an authenticator certificate verification.

    • Natanael@infosec.pub
      link
      fedilink
      English
      arrow-up
      5
      ·
      1 day ago

      Only companies issuing their own passkeys on company hardware has a reason to enable attestation (forcing use of company approved devices throughout). Any public facing service has no reason to use attestation.