Home | Notifications | New Note | Local | Federated | Search | Logout
Filippo Valsorda@filippo@abyssdomain.expert
@FiloSottile elsewhere / Cryptogopher / Go crypto maintainer / Professional Open Source maintainer / RC F'13, F2'17
https://mkcert.dev / https://age-encryption.org / https://filippo.io/newsletter
🕳️ “Gaze not into the abyss, lest you become recognized as an abyss domain expert, and they expect you keep gazing into the damn thing.” —@nickm
Location: Rome 🇮🇹
Pronouns: he/him
Website: https://filippo.io
Twitter: https://twitter.com/FiloSottile
Joined: 2026-07-22 12:03:10
3 notes, 0 following, 0 followers
Reply to @ori@hj.9fs.net
Filippo Valsorda@filippo@abyssdomain.expert (2026-07-22 18:34:43)
@ori @shaoyu There are no popular software authenticator that support attestation and no major websites that constrain AAGUID (because they wouldn't work with major software authenticators). The attestation concern is purely hypothetical and has so far proven unfounded. The human cost od phishing, on the other hand, is very real.
Reply to @shaoyu@mastodon.social
Filippo Valsorda@filippo@abyssdomain.expert (2026-07-22 11:36:06)
@shaoyu passkeys can't be phished.
Filippo Valsorda@filippo@abyssdomain.expert (2026-07-21 08:25:04)
Passkeys can be stored just like password hashes!
I'm proposing an interoperable $webauthn$v=1$… format, and a Go API that uses these passkey records for authentication.
I'm looking for feedback before proposing this as crypto/passkey for Go 1.28!
https://words.filippo.io/passkey-record/