Comment on Passkeys Explained: The End of Passwords

<- View Parent
Septimaeus@infosec.pub ⁨2⁩ ⁨weeks⁩ ago

Yeah the counter-interoperability of the proprietary expansions on the FIDO standards sounds very much like embrace extend extinguish to me. I know engineering standards generally require field revisions but these big corps have a track record of this behavior.

I can see how the FIDO standard’s dID requirement might be an issue at the org level, but even in the case of a fully custom/unknown rooted device they have provisions for using traditional security keys attached to one or more associated devices via USB/BT/NFC. Megacorp platforms might be first to facilitate adoption but the spec absolutely accommodates open provider integration.

I need to experiment with personal security passkey registration and authentication workflows to know how difficult it actually is in practice, but it looks like the equivalent of self-signed certificates are possible anywhere the user controls the stack like self-hosted intranetwork suites that are popular around here.

Thanks again for the write up!

source
Sort:hotnewtop