Earlier quoted context omitted.
Passkeys will be the way to go if we get them to remove the "attestation object" field from the protocol. Until then there's no way for Jimbob to tell the difference between: > Website: is this Jimbob' phone > Hardware: yes And > Website: I'll give you a dollar if you tell me something juicy about this user > Hardware: Give this token to Microsoft and ask them > Microsoft: Jimbob is most likely to click ads involving…
> Passkeys will be the way to go if we get them to remove the "attestation object" field from the protocol. I don't think you understand the protocol. The attestation object does not mean there is an authenticator attestation. There is no authenticator / credential manager attestation in the consumer synced passkey ecosystem. Period.
It seems pretty clear that "where possible" parties besides the user are provided with information about the user (ostensibly about their device, but who knows what implementers will use this channel for)... so they can make a trust decision.
It's going to end up being a root-of-trust play, and those create high value targets which don't hold up against corruption, so you're going to end up with a cabal of auth-providers who use their privileged position to mistreat users (which they already do, but what'll be different is that this time around nobody will trust that you're a real human unless you belong at least one member of this cabal).