Tell me this, can a user still use an external password manager with WebAuth or maintain the password themselves, or does it require the user to have their OS generate and store the key? From what I can tell, this looks more like an industry effort to have users integrate their passwords into various major-players sync services which is far from ideal for many users who actually want some control over where their passwords are stored and how they are generated.
It doesn't integrate with password managers. You can use your YubiKey or similar that is enrolled with one device on another device (even with another protocol; USB on your computer, NFC on your phone).
As far as I can tell, it doesn't integrate with any sort of platform-level sync, either. My tablet doesn't get my phone's credentials; it has to be independently enrolled.
Comments
Tell me this, can a user still use an external password manager with WebAuth or maintain the password themselves, or does it require the user to have their OS generate and store the key? From what I can tell, this looks more like an industry effort to have users integrate their passwords into various major-players sync services which is far from ideal for many users who actually want some control over where their passwords are stored and how they are generated.
It doesn't integrate with password managers. You can use your YubiKey or similar that is enrolled with one device on another device (even with another protocol; USB on your computer, NFC on your phone).
As far as I can tell, it doesn't integrate with any sort of platform-level sync, either. My tablet doesn't get my phone's credentials; it has to be independently enrolled.