Passkeys
imperialviolet.org
imperialviolet.org
IMO, the best part of Apple adding Passkeys support over WebAuthn is that we are finally able to use Secure Keys as well across all devices. If this takes off, I wonder if it would somehow end up replacing FIDO2 for Secure Keys scenarios as wel.
This document describes a mechanism to transfer digital credentials
securely between two devices. Secure credentials may represent a
digital key to a hotel room, a digital key to a door lock in a house
or a digital key to a car. Devices that share credentials may belong
to the same or two different platforms (e.g. iOS and Android).
Secure transfer may include one or more write and read operations.
Credential transfer needs to be performed securely due to the
sensitive nature of the information.
* https://datatracker.ietf.org/doc/html/draft-secure-credentia...https://securitycryptographywhatever.buzzsprout.com/1822302/...
https://fidoalliance.org/apple-google-and-microsoft-commit-t...
https://github.com/w3c/webauthn/pull/1703
Github maintains a Ponyfill for browsers that don't support this standardised serialisation format yet: https://github.com/github/webauthn-json
https://github.com/w3c/webauthn/issues/1616 https://github.com/w3c/webauthn/issues/1255