I think that is only an issue based on what Passkey attestation is configured by the relying party? From what I have read a lot of public facing companies implementing it will have passkey attestation statements configured as None, which typically means there isn't an authenticator certificate verification.
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
replies: