Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

None of the common passkey implementations support attestation.

Apple doesn't support it at all anymore; Google only supports it for non-synchronized credentials (which are arguably not passkeys). Bitwarden obviously doesn't either (it can't, as a pure software implementation).

> One of the developers already threatened to use it against keepass when they built an export feature he didn't agree with.

Developer of what? There's no competing software solution that supports attestation, and hardware authenticators complement software ones, rather than compete with them.



https://github.com/timcappalli, "passkeys, FIDO2/WebAuthn, and digital credentials @ okta"

Not directly threatening but within that frame of mind:

https://github.com/keepassxreboot/keepassxc/issues/10407#iss...

https://github.com/keepassxreboot/keepassxc/issues/10407#iss...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: