Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> If you don't like Google or Apple, use your favorite password manager.

Unless the service you are trying to use requires that you use a particular model of authenticator, which the service provider can enforce via attestation.



> Unless the service you are trying to use requires that you use a particular model of authenticator, which the service provider can enforce via attestation.

Android's implementation of passkeys currently does not support attestation. https://groups.google.com/a/fidoalliance.org/g/fido-dev/c/nh...

Neither does Apple's, I believe.


Good to know! Hopefully this kills off unnecessary use of attestation.


Isn't it even worse? Browser vendors don't even offer any way to not use their baked-in authenticator? With WebAuthn they offered at least the options of using a security key via Bluetooth/NFC/Bluetooth as alternatives to the device authenticator. I don't see that option with passkeys.

So, there seems no way to use a password manager with passkeys.


They can do this with SSO provided by third parties now.


Sure, but passkeys are meant to replace passwords, not SSO (although I won't complain if they do replace SSO).

Most services probably would not restrict you to just one model of authenticator, but it wouldn't surprise me at all to see a service require that the authenticator be backed by a secure element, in which case you could use a security key, a passkey, a TPM, et cetera, but not a password manager. I'd still take that over passwords, but I don't think everyone would.


I recently got hardware TOTP keys and I wanted to use them with my financial accounts but all the banks have their own propritary authenticators :(




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: