>FIDO requires an attestation private key, which must be shared between a batch of at least 100,000 security keys. Using a DIY or cli app solution (application running on the host) will likely mean you'll be generating that private key yourself, this makes you identifiable across registrations.
>Some sites (Cloudflare) may reject the use of attestation keys which are not found on the Fido Alliance Metadata Service. This precludes the use of any DIY solution.
>https://fidoalliance.org/metadata/
>https://support.cloudflare.com/hc/en-us/articles/44068890480...
Taken from a previous Hacker News discussion: https://news.ycombinator.com/item?id=31294316#31295128