zlacker

[return to "A Tour of WebAuthn"]
1. Zamico+uR[view] [source] 2024-12-27 05:14:56
>>caust1+(OP)
WebAuthn and passkeys are a disaster.

Much of the specs were created behind closed doors and never done in a way where we could have had outside input. They're completely corporate driven and designed to control users not empower them.

◧◩
2. pas+sj1[view] [source] 2024-12-27 13:21:31
>>Zamico+uR
Ah yes the closed doors of the world wide web consortium.

https://lists.w3.org/Archives/Public/public-webauthn/

(nb. I'm not saying the folks were easy to work with or super open to discussion, but it was not some clandestine black kitchen where it was cooked up.)

◧◩◪
3. Zamico+FJ1[view] [source] 2024-12-27 16:26:22
>>pas+sj1
You're right that WebAuthn was much more public, but passkey was not.

I personally tried to stay apprised of passkey's development. After asking several developers and poking around the best I could, I was told several times that it was being primarily developed behind closed doors for corporate interests, invite-only, and wasn't ready for release. The only information available was the WebAuthn forums.

Even now the documentation is still poor, and there's essentially no rationale to understand design and architectural decisions. We're just given a spec and expected to adhere to it.

◧◩◪◨
4. growse+Fv2[view] [source] 2024-12-27 21:58:33
>>Zamico+FJ1
Passkey is just a fancy brand/marketing name for a specific mode of webauthn (resident).

Saying that "WebAuthn was much more public, but passkey was not." shows that you don't really have a clear and accurate mental model of what passkeys are. Maybe TFA might help?

[go to top]