4 ms·
It's all about the FIDO2 hardware attestation. I'd rather use a FIDO2 authenticator with attestation. Call it a passkey or not, I don't want the to use the sync
by Melown 3y ago
It's all about the FIDO2 hardware attestation. I'd rather use a FIDO2 authenticator with attestation. Call it a passkey or not, I don't want the to use the syncable passkeys without hardware attestation.
- wkat4242 3y agoApple doesn't do attestation so if you require that you're already leaving out the biggest platform. But it's a bad thing for self hosters anyway. Because parties will make exclusive deals or only wish to deal with authenticators they trust (eg that pay them for 'certification')
- 0x4e53 3y agoAt least for the enterprise - this decision should be up to the company. (i.e, flip a switch on your identity provider to enable or disable support for "no attestation") Some companies are comfortable with the idea of a two-factor method that can be airdropped to friends. Major organizations (AWS, among others) are not huge fans of passkeys for enterprise use. When passkeys released, our initial response at AWS was to give organization admins the ability to disallow passkeys. Overall, I think there are fixes coming across the board from Apple and the FIDO Alliance to address some of the early shortfalls of passkeys.
- wkat4242 3y agoWell for the enterprise yes, but they shouldn't force these decisions on their customers. They can provide the total hardware package for their employees to sign in with anyway.