Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

i'm pretty sure you're wrong. or at least, you're directly contradicted by the apple docs, which say "The other key is private, and is what is needed to actually sign in. The server never learns what the private key is." https://support.apple.com/en-ca/HT213305

the basic claim about being able to store "infinite" passkeys on a USB is also directly contradicted by the yubikey docs, which say they can store 25: https://www.yubico.com/blog/a-yubico-faq-about-passkeys/



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: