Nerd confession. I haven't looked into passkeys and have no idea what they are and why some companies want me to adapt them.

Follow

@tante I have tried looking into them and found it very difficult to find any *clear* information.

I grew suspicious and a deeper look into it confirmed my suspicions - while it *is* a form of keypair auth, and nominally an open standard, the general design choices and implementation recommendations are quite problematic and primarily seem chosen to entrench large players like Google as authentication providers (via eg. Android).

(Like how there are specific provisions and recommendations for allowlisting "attestation providers", which people are only ever going to do for major providers)

· · Web · 0 · 0 · 1
Sign in to participate in the conversation
Pixietown

Small server part of the pixie.town infrastructure. Registration is closed.