logoalt Hacker News

SrslyJoshyesterday at 10:04 PM1 replyview on HN

This is hard to understand without any references. Can you please share a relevant link or two?


Replies

OkayPhysicistyesterday at 10:26 PM

Here's KeePassXC being threatened with blacklisting over granting users control over their own data:

https://github.com/keepassxreboot/keepassxc/issues/10407#iss...

Here's the most readable reference to playing favorites on passkey vaults I could find from the FIDO Alliance (the previously mentioned 'cabal of evil').

See Section 2.2: "Validating FIDO UAF authenticator attestations against the configured authenticator metadata to ensure only trusted authenticators are registered for use. "

And Section 2.3: "Verify attestation assertions made by the FIDO UAF Authenticators to ensure the authenticator is authentic and trusted. Verification occurs using the attestation public key certificates distributed via authenticator metadata. "

https://fidoalliance.org/specs/fido-uaf-v1.2-ps-20201020/fid...

Basically, Relying Parties (the sites you are logging in to) are expected to allow/disallow certain passkey authenticators (the devices or software that hold your passkeys), based on registration and trusted lists. The FIDO Alliance can use entry into those trusted lists as a cudgel to force compliance with the standard. Effectively, the standard is that users must be locked into to proprietary ecosystems, unable to escape.