| ▲ | ivlad 2 days ago | |
> The important part is it's up to the service to decide on whether they want to require hardware resident keys (which cannot be synced via the cloud). From what I know, Apple ignores `platform` and `ResidentKeyRequirement` claims and always creates cloud-synced key pairs. Moreover, the strongest claim value allowed for the `ResidentKeyRequirement` is “discouraged”, which per spec is treated as SHOULD in RFC 2119 since. In other words, browsers are free to ignore it when “they know better”, which Apple always does. | ||
| ▲ | atanasi a day ago | parent | next [-] | |
The service may require attestation and verify the actual authenticator metadata. If the passkey is not accepted by the service, it can use the signaling API to indicate that the passkey was not registered validly. | ||
| ▲ | packetlost a day ago | parent | prev [-] | |
Sure, but you can still use a Titan T3 or recent Yubikey model on an iPhone. If I had the threat model to justify it, I would not set up the passkey in Apple's infrastructure. It is too bad they ignore that though. That's really disappointing. | ||