I try to boycott passkeys due to built-in attestation feature in the standard. Not active now, but given how Google+Apple already use the passkey feature to lock you into their ecosystems, it is just a matter of time until their service will require that the passkey is attested from a non-rooted Google or Apple device. I think this will especially be true for Google to prevent AI scraping bots. Turning this on does not require anything, once passkeys are widely used, Apple, Google and Co. simply can flip a switch.

> Not active now, but given how Google+Apple already use the passkey feature to lock you into their ecosystems, it is just a matter of time until their service will require that the passkey is attested from a non-rooted Google or Apple device.

I'm with you 100%.

There will be evil and stupid uses.

The brain-damaged people who think disabling paste on password fields is a security feature will be all over forcing device-attested passkeys as soon as they learn about it.

Evil people will see it as a proxy attestation of humanity.

Either way it will be rammed down our throats if passkeys are widely adopted.

I imagine that's why they're pushing them so hard, especially given Google's recent anti-user lockdowns. I have a hard time imagining they'd expend so many resources to protect a tiny percentage of users from having their accounts hacked...there's no way they actually give a shit about that. Their bread and butter is instead protecting the value of their product, which is their captive userbase.

Apple and Google don't need the passkey spec to mandate that you only use their services from non rooted Google/ Apple devices. They could do it before passkeys existed, and they can do that right now if they wanted to.

What's any of that got to do with passkeys and attestation?

User convenience.

TIL about the attestation. Ohhhh, why can't we just have nice things?