| ▲ | littlecranky67 3 hours ago | |
I try to boycott passkeys due to built-in attestation feature in the standard. Not active now, but given how Google+Apple already use the passkey feature to lock you into their ecosystems, it is just a matter of time until their service will require that the passkey is attested from a non-rooted Google or Apple device. I think this will especially be true for Google to prevent AI scraping bots. Turning this on does not require anything, once passkeys are widely used, Apple, Google and Co. simply can flip a switch. | ||
| ▲ | EvanAnderson 37 minutes ago | parent [-] | |
> Not active now, but given how Google+Apple already use the passkey feature to lock you into their ecosystems, it is just a matter of time until their service will require that the passkey is attested from a non-rooted Google or Apple device. I'm with you 100%. There will be evil and stupid uses. The brain-damaged people who think disabling paste on password fields is a security feature will be all over forcing device-attested passkeys as soon as they learn about it. Evil people will see it as a proxy attestation of humanity. Either way it will be rammed down our throats if passkeys are widely adopted. | ||