XSS Is Deadly for Passkeys: The Hidden Risk of Attestation None
scotthelme.co.uk
scotthelme.co.uk
https://fy.blackhats.net.au/blog/2025-12-17-yep-passkeys-sti...
and more discussion here: https://news.ycombinator.com/item?id=46301585
This same ordeal is why lots of Android software is intentionally broken on non-Google operating systems, and it would be a terrible blow for the web if it worked like that for every website with a login. Passkeys are that future, and it's very hard to take anyone who encourages their use seriously. Encouraging attestation, like here, is even worse.