17 ms·
Current Yubikeys do allow you to store login information (Resident Keys in webauthn), and because Apple refuses to provide attestation for Passkeys, it's going
by warp 3y ago
Current Yubikeys do allow you to store login information (Resident Keys in webauthn), and because Apple refuses to provide attestation for Passkeys, it's going to be very difficult for a website to force you to use a security key from any particular vendor.
Obviously Yubikeys (and most/all other hardware keys) do provide attestation, so in theory a website could refuse to let you register those -- but if that becomes common it would be easy for any company to create hardware keys which refuse attestation.
- kps 3y agoHigher Yubikeys do, but other FIDO2 keys, including Yubico's ‘Security Key’ series, don't. Apple's current policy on attestation is good (for consumers; I don't deny there are closed conditions where you'd legitimately use it), but their refusal to allow 3P integration is not.