logoalt Hacker News

vel0cityyesterday at 3:26 PM1 replyview on HN

> Passkeys basically MITM the 2FA process so that they can track and deplatform you with a single click across all your accounts.

I use passkeys with a physical authenticator. How do "they" track and deplatform me with a single click? Can you explain?


Replies

deltoidmaximusyesterday at 6:06 PM

The service can use the use the attestation feature to block passkey providers that are deemed undesirable for whatever reason. Hard not to see eventually only major providers being accepted, even things like Microsoft services requiring Microsoft Passkeys using the Microsoft Passkey App which you're now required to have on your phone. Or worse you now need Symantec Passkeys to login to Symantec services (using that example since I believe Symantec had a ToTP App you needed to reverse engineer to extract the ToTP seed from if you wanted to use a different Authenticator)

show 1 reply