Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

By using the built in device attestation feature to blackball any passkey providers that allow that, apparently:

https://github.com/keepassxreboot/keepassxc/issues/10407#iss...

Now imagine a whitelist of acceptable providers. Suddenly, you don't even own your credentials anymore.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: