XSS Is Deadly for Passkeys: The Hidden Risk of Attestation None
scotthelme.co.uk
XSS Is Deadly for Passkeys: The Hidden Risk of Attestation None
1–8 of 8 posts
Re: XSS Is Deadly for Passkeys: The Hidden Risk of Attestation None
#2Re: XSS Is Deadly for Passkeys: The Hidden Risk of Attestation None
#3Passkeys: as if we didn't have enough ways Big Tech could deprive you of your digital life. Just say "hell no!"
Re: XSS Is Deadly for Passkeys: The Hidden Risk of Attestation None
#4Re: XSS Is Deadly for Passkeys: The Hidden Risk of Attestation None
#5Earlier quoted context omitted.
What's the concern with using passkeys?
Not the OP, but I'd assume they are talking about 'direct' attestation mode creating vendor lock-in
Re: XSS Is Deadly for Passkeys: The Hidden Risk of Attestation None
#6Earlier quoted context omitted.
Not the OP, but I'd assume they are talking about 'direct' attestation mode creating vendor lock-in
I can kind of see it, but you can also just use an authenticator from any manufacturer, or have multiple types that you use? I'm just curious what I'm overlooking.
https://fy.blackhats.net.au/blog/2025-12-17-yep-passkeys-sti...
and more discussion here: https://news.ycombinator.com/item?id=46301585
Re: XSS Is Deadly for Passkeys: The Hidden Risk of Attestation None
#7Earlier quoted context omitted.
I can kind of see it, but you can also just use an authenticator from any manufacturer, or have multiple types that you use? I'm just curious what I'm overlooking.
> I've encountered multiple sites that now use authenticatorAttachment options to force you to use a platform bound Passkey. In other words, they force you into Microsoft, Google or Apple. No password manager, no security key, no choices. https://fy.blackhats.net.au/blog/2025-12-17-yep-passkeys-sti... and more discussion here: https://news.ycombinator.com/item?id=46301585
Re: XSS Is Deadly for Passkeys: The Hidden Risk of Attestation None
#8This same ordeal is why lots of Android software is intentionally broken on non-Google operating systems, and it would be a terrible blow for the web if it worked like that for every website with a login. Passkeys are that future, and it's very hard to take anyone who encourages their use seriously. Encouraging attestation, like here, is even worse.