Skip to content

Comment on Pass the Passkey: A Novel Attack Surface in Passwordless Authenticationparent

Comments

They want you dependent on them and locked into their ecosystem.

This is a strange conclusion to come to when clearly a lot of effort was put into developing an open standard (Credential Exchange Format) to make it easy and secure to move credentials between vendors/ecosystems, without opening end-users up to phishing attacks on credential export.

If big tech wanted to lock people in, it seems like it would have been a lot easier to just... not create an open standard.

Bug tech isn't a single entity. But I strongly believe a different group would have finished this obvious gap by now.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.