Clearing up some misconceptions about Passkeys
stavros.io
stavros.io
Many services already do fingerprint my machine and I heavily dislike it since I often do use different machines and I am tired of these cookie banners bugging me. This is not part of my security model and it is forced upon me. I am aware of the potential benefits, but I am also aware of the often far more specific costs.
It might be that every site restricts their allowed authenticators to one from Google or Apple, but there isn't much point in intentionally breaking your users' devices. I don't think attestation will be widely deployed outside of some niche corporate cases (e.g. you can only use a Yubikey to log in to the company VPN).