▲ | ori_b 9 days ago | ||||||||||||||||||||||||||||||||||||||||||||||
Yeah, so if you want me to trust them, the harmful parts need to get removed from specs used in public contexts. I would love to use public key cryptography to authenticate with websites, but enabling remote attestation is unacceptable. And pinky swears that attestation won't be used aren't good enough. I've seen enough promises broken. It needs to be systematic, by spec. Passwords suck. It's depressing that otherwise good alternatives carry poisonous baggage. If you make something possible, it will be used. | |||||||||||||||||||||||||||||||||||||||||||||||
▲ | growse 9 days ago | parent [-] | ||||||||||||||||||||||||||||||||||||||||||||||
> If you make something possible, it will be used. Sure, but that's not without tradeoffs. I come back to: > Any service requiring attestation for passkeys will effectively lock out every iPhone user - not going to happen. | |||||||||||||||||||||||||||||||||||||||||||||||
|