Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Apple doesn't do attestation so if you require that you're already leaving out the biggest platform.

But it's a bad thing for self hosters anyway. Because parties will make exclusive deals or only wish to deal with authenticators they trust (eg that pay them for 'certification')



At least for the enterprise - this decision should be up to the company. (i.e, flip a switch on your identity provider to enable or disable support for "no attestation")

Some companies are comfortable with the idea of a two-factor method that can be airdropped to friends. Major organizations (AWS, among others) are not huge fans of passkeys for enterprise use. When passkeys released, our initial response at AWS was to give organization admins the ability to disallow passkeys.

Overall, I think there are fixes coming across the board from Apple and the FIDO Alliance to address some of the early shortfalls of passkeys.


Well for the enterprise yes, but they shouldn't force these decisions on their customers.

They can provide the total hardware package for their employees to sign in with anyway.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: