1. Is there anything in the standard about proving to the server that you have a genuine FIDO device that meets certain standards, and not say a piece of software that is merely pretending to be a hardware security module? If so, I presume the Solo will come with whatever certification / digital signature is required?
2. My understanding of FIDO (v1) is that the only function a device has to offer is authentication through digital signature, so a FIDO v1 device is no use as an extra authentication factor to unlock a password manager without "cloud" support (such as pwsafe) as it doesn't provide you with anything that a hacker couldn't work around - as opposed to a token that stores a cryptographic key and releases it when you press the button (which you can set up a yubikey to do). Is this correct, and does FIDO2 change this situation?