Remix.run Logo
eadmund 9 days ago

> Passkeys is the way to go.

No, please, not as long as attestation is in the spec. I firmly believe that passkeys are intended to facilitate vendor lock-in and reduce the autonomy of end users.

Frankly, I do not trust any passkey implementation as much as I trust a GPG-encrypted text file.

timmyc123 9 days ago | parent | next [-]

There is no credential manager attestation in the consumer synced passkey ecosystem. Period.

palata 9 days ago | parent | prev [-]

I use a FIDO2 security key, I fail to see how I am locked in. Can you elaborate?