5 ms·
"providers allow you to register multiple keys" Why isn't my identity just a Merkle root? I don't understand the need to register individual keys.
by Zamicol 4y ago
"providers allow you to register multiple keys"
Why isn't my identity just a Merkle root? I don't understand the need to register individual keys.
- giaour 4y agoYou'd also need some way to revoke keys signed by the root if a valid hardware key were lost, stolen, or confiscated. I think Yubico will actually do something like this for large enough customers, though revocation is left as an exercise for the customer. When I worked for AWS, I was issued a couple company YubiKeys, and there was a web portal where I could revoke a token's association with my account.
- lxgr 4y agoHow would you add a new key at a later point in time (i.e. after your initial registration of e.g. a main and a backup key, after having lost the main key and wanting to add a new backup/main key)? The FIDO/WebAuthN model does by design not include a stateful/centralized authority that could maintain the required state for any such solution.