3 ms·
Cloudflare is one example, using a security key not found in the FIDO Metadata Service, will not work on their site. This precludes the use of any hacker-friend
by e2le 4y ago
Cloudflare is one example, using a security key not found in the FIDO Metadata Service, will not work on their site. This precludes the use of any hacker-friendly solution (making your own).
> Supported: All security keys found in the FIDO Metadata Service 3.0, unless they have been revoked for security reasons.
https://support.cloudflare.com/hc/en-us/articles/4406889048077-FAQs-for-Cryptographic-Attestation-of-Personhood#h_16OGl1pu5javVk3m408rPU https://support.cloudflare.com/hc/en-us/articles/44068890480...
Attestation keys, aren't very "privacy friendly" either and it's much worse for those who wish to create their own key.
> Usually, the attestation private key is shared between a batch of at least 100,000 security keys of the same model. If you build your own OpenSK, your private key is unique to you. This makes you identifiable across registrations: Two websites could collaborate to track if registrations were attested with the same key material. If you use OpenSK beyond experimentation, please consider carefully if you want to take this privacy risk.
https://github.com/google/OpenSK/blob/f2496a8e6d71a4e838884996a1c9b62121f87df2/docs/customization.md https://github.com/google/OpenSK/blob/f2496a8e6d71a4e8388849...
- zozbot234 4y agoThat's used for Cryptographic Attestation of Personhood, so the restriction to genuine devices has some rationale behind it. It's not quite about checking an identity for login purposes, so much as checking that an actual human being is operating the device, via e.g. biometrics or physically poking in a PIN. (As a CAPTCHA replacement.) The precise key you use ought not to matter for that purpose, it could even be "enrolled" on the spot.