4 ms·
XSS Is Deadly for Passkeys: The Hidden Risk of Attestation None
- PaulHoule 5mo agoPasskeys: as if we didn't have enough ways Big Tech could deprive you of your digital life. Just say "hell no!"
- Scott_Helme_ 5mo agoWhat's the concern with using passkeys?
- moebrowne 5mo agoNot the OP, but I'd assume they are talking about 'direct' attestation mode creating vendor lock-in
- Scott_Helme_ 5mo agoI can kind of see it, but you can also just use an authenticator from any manufacturer, or have multiple types that you use? I'm just curious what I'm overlooking.
- moebrowne 5mo ago> I've encountered multiple sites that now use authenticatorAttachment options to force you to use a platform bound Passkey. In other words, they force you into Microsoft, Google or Apple. No password manager, no security key, no choices. https://fy.blackhats.net.au/blog/2025-12-17-yep-passkeys-still-have-problems/ https://fy.blackhats.net.au/blog/2025-12-17-yep-passkeys-sti... and more discussion here: https://news.ycombinator.com/item?id=46301585 https://news.ycombinator.com/item?id=46301585
- Scott_Helme_ 5mo agoInteresting, could you link me to some of those sites so I can investigate?
- mzajc 5mo agoThe hidden risk of attestation none: the user might (gasp) use a libre authenticator! This same ordeal is why lots of Android software is intentionally broken on non-Google operating systems, and it would be a terrible blow for the web if it worked like that for every website with a login. Passkeys are that future, and it's very hard to take anyone who encourages their use seriously. Encouraging attestation, like here, is even worse.