you are viewing a single comment's thread
view the rest of the comments
[–] 17 points 1 week ago (1 child)

I think that is only an issue based on what Passkey attestation is configured by the relying party? From what I have read a lot of public facing companies implementing it will have passkey attestation statements configured as None, which typically means there isn't an authenticator certificate verification.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 7 points 1 week ago

    Only companies issuing their own passkeys on company hardware has a reason to enable attestation (forcing use of company approved devices throughout). Any public facing service has no reason to use attestation.

  • source
  • parent