However, I don't know whether it's possible to delete only a single resident key you no longer need.
https://github.com/w3c/webauthn/issues/2038
They apparently came up with a fix for this using something called Signals API but I don't think any browser implemented that yet.
Just wanted to highlight that this part of the UX is hairy and hard to get right
https://lists.w3.org/Archives/Public/public-webauthn/
(nb. I'm not saying the folks were easy to work with or super open to discussion, but it was not some clandestine black kitchen where it was cooked up.)
But I agree that one thing you can't accuse them of is not operating in the open. While I don't agree with some of their decisions, discussing feedback in Github issues as well as on public mailing lists is probably as transparent as it gets.
I haven't really looked into it myself, but it seems to be using the same database format as KeePass, and it hooks into macOS's "FIDO provider" API, which makes it accessible to not only Safari but all browsers that use it (which includes Firefox and Chrome on macOS, and probably everything on iOS), without requiring any browser-side extension.
You keep repeating that, but that's not possible anymore, since both Apple and Google removed attestation from their respective passkey/WebAuthN implementations.
For details, see >>42522490 .
Once the technology is there to support it, hopefully the user experience part can be improved with time.
Ref in the standard - https://fidoalliance.org/specs/fido-v2.1-ps-20210615/fido-cl...
It would be great if you’re correct, but these references sure seem to indicate that attestation is still a thing.
Microsoft, November 2024: https://learn.microsoft.com/en-us/entra/identity/authenticat...
Yubico: https://developers.yubico.com/Passkeys/Passkey_relying_party...
Apple: https://developer.apple.com/documentation/devicemanagement/s...
Apple: https://support.apple.com/guide/deployment/managed-device-at...
Google, September 2024: https://android-developers.googleblog.com/2024/09/attestatio...
A Tour of WebAuthn, December 2024 (aka the fine article): https://www.imperialviolet.org/tourofwebauthn/tourofwebauthn...
edit: Indeed, that's the firmware revision credential management was added, per this blog post: https://www.yubico.com/blog/whats-new-in-yubikey-firmware-5-...
I'm honestly very annoyed with Yubico that they just froze their product line-up circa 2018 and pretend the major changes in firmware (5.2, 5.7) don't matter at all and don't warrant a separate SKU.