5 ms·
Some of the takes about why attestation is bad seem purposely false because the author dislikes the feature. If attestation isn't triggered then prior behaviour
by meandmycode 3y ago
Some of the takes about why attestation is bad seem purposely false because the author dislikes the feature. If attestation isn't triggered then prior behaviour will happen (captcha etc).. this is a progressive feature.. and the point of the attestation isn't to prove you're using an approved device, it's to prove a human is actually present, of which, a verified software stack is needed, otherwise the feature is useless..
- dahwolf 3y agoIt doesn't prove that a human is present at all.
- meandmycode 3y agoIt actually does, that's entirely it's purpose.. I know it takes a little effort to actually go and research yourself, but here you go https://developer.apple.com/videos/play/wwdc2022/10077/ https://developer.apple.com/videos/play/wwdc2022/10077/
- dahwolf 3y agoYou must have never heard of test automation with real devices? No human there, still passes this check.
- meandmycode 3y agoEven if that's true (apple is a bit ambiguous here because they say passcode login is enough), this is still connected to a need to login physically, it sets a much higher cost of acquisition for most.. plus this isn't relevant.. the tech is still aimed at proving real human interaction, even if it's not perfect at that today..
- deleted 3y ago[deleted]
- Zinu 3y ago> If attestation isn't triggered then prior behaviour will happen That’s up to the web server to decide, it could just block you instead, and there is incentive to do exactly that. > attestation isn't to prove you're using an approved device That’s what it is doing though, so it can and will be used for that.
- meandmycode 3y agoWhere's the incentive to block your potential customers?
- hellojesus 3y agoDoes this progressive feature allow every visitor to a site to be uniquely identified with 100% certainty? Because that doesn't sound very progressive.
- meandmycode 3y agoAgain, you need only research and find they are designed independently not to allow this https://developer.apple.com/videos/play/wwdc2022/10077/ https://developer.apple.com/videos/play/wwdc2022/10077/
- hellojesus 3y agoIf that is the case, what stops people from setting up bot farms to gathering millions of valid keys per origin, and then passing them off to requesting users to use with unapproved devices? Seems like the same choke point still exists, in that captchas may be required to prove the token requestor is human. And since you also could do it maliciously in the sense that you could fire and forget requests if you didn't care about the token, you could spoof your ip across the range of all residential ips to try and force captcha rate limiting on everyone that requests an attlestation.
- fruitreunion1 3y agoThe captcha and fingerprinting methods are higher effort compared to attestation, so I think there is an incentive for most sites to get rid of it in favor of attestation.