3 ms·
Yet Google, one of the key participants in the FIDO alliance, has published an open source firmware! I agree the potential exists, in a hypothetical sense. But
by md_ 4y ago
Yet Google, one of the key participants in the FIDO alliance, has published an open source firmware!
I agree the potential exists, in a hypothetical sense. But the dynamics are very different than you describe (with your analogy to the CA ecosystem, which, ironically, gives big platform owners far more power—yet has no evidence of such abuse!).
Right now, there is just not that much use of WebAuthn and FIDO. You’re the guy saying, “if we find a way to lower global temperatures, we should fear an ice age.” It’s premature to say the least.
- dane-pgp 4y agoI'm glad Google has published an open source firmware, and I hope that people will be able to independently verify that the hardware they use is genuinely running that firmware. Then I hope that hardware with such guarantees is not discriminated against by RPs. The important difference with the CA ecosystem is that (in the worst case) the big platform owners can put pressure on small websites to obtain a certificate from one of a large number of competing issuers. Significantly, these issuers are not the same as the big OS providers themselves, and there are issuers who issue certificates for free. That is completely the reverse of 3 big platforms forcing end users to buy hardware, and those platforms being hardware vendors themselves. > You’re the guy saying, “if we find a way to lower global temperatures, we should fear an ice age.” No, I'm the frog saying "Hey, isn't this water getting a bit warm? Don't you think we should jump out before it's too late?"
- md_ 4y agoBut the big three can't do that, with FIDO. All they can do is influence the FIDO Alliance to add other SK manufacturers to the pseudo-CRL, which: - is transparent - is mediated by the FIDO Alliance; the platform makers cannot do it unilaterally, as they can with CAs in browsers - is mediated by the RPs; even if the FIDO Alliance did do this for some reason, RPs could just ignore it with no ill effects, unlike with CA trust in browsers - wouldn't have any effect today for the vast majority of RPs, since the vast majority do not even use attestation today - honestly, isn't something they have any incentive to do; hardware security keys are not a meaningful source of revenue for someone like Apple, Microsoft, or Google I'm guessing you've never worked in a big tech company before if you think they have an incentive to do that. :)