2 ms·
I don't disagree that it will be hard, but I think that ultimately all that is needed for this to be possible is a standard TPM API that lets you export key mat
by sebk 4y ago
I don't disagree that it will be hard, but I think that ultimately all that is needed for this to be possible is a standard TPM API that lets you export key material wrapped in a public key (corresponding to another TPM, presumably) only if it's signed by the TPM itself. This would let implementers build something equivalent to Apple's circle of trust (https://support.apple.com/guide/security/secure-keychain-syncing-sec0a319b35f/web https://support.apple.com/guide/security/secure-keychain-syn...), and use the new API to share 'Passkeys' between devices.
Whether having an open syncing fabric is enough for vendors to want to interoperate with it I don't know, but if they ship TPM comformant hardware, you as a consumer would have the option to use either fabric.
I glossed over a lot of details and the implementation might not end up looking like that, but I believe something similar would be sufficient to kickstart the effort.