Home | Notifications | New Note | Local | Federated | Search | Logout

Note Detail


Reply to @ori@hj.9fs.net
Filippo Valsorda@filippo@abyssdomain.expert (2026-07-22 18:34:43)
@ori @shaoyu There are no popular software authenticator that support attestation and no major websites that constrain AAGUID (because they wouldn't work with major software authenticators). The attestation concern is purely hypothetical and has so far proven unfounded. The human cost od phishing, on the other hand, is very real.

---Reply--- ori@ori@hj.9fs.net (2026-07-24 05:40:36) I would still be much more comfortable if the spec was updated to remove support. Hypothetical bad behavior by companies has an unpleasant tendency to become actual, especially if there's a way to use it for additional lock-in.

I don't think it's worth prioritizing holding on to a dead feature over removing things that make adopters uncomfortable.

CC: @shaoyu@mastodon.social @filippo@abyssdomain.expert
Reply